BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Sept 2020 | Geanonimiseerd (APD 53/2020)A politician was fined for sending an election propaganda email without consent. The authority found unlawful processing of personal data and a failure to implement appropriate technical and organizational measures. | BE | APD | GDPR | €2,000 | ↗ |
| 01 Sept 2020 | Iweb Internet Learning, S.L.Iweb Internet Learning, S.L. was fined by the AEPD EUR 13,000 for failing to inform data subjects about the processing of their personal data. The authority also found the use of storage and retrieval devices without the required notice or consent. | ES | AEPD | ePrivacy | €13,000 | ↗ |
| 01 Sept 2020 | B.B.B.The entity was fined by the AEPD €5,000 for using a webcam to record video and audio without justification. The conduct infringed privacy by monitoring private conversations and activities inside a rented residence. | ES | AEPD | GDPR | €5,000 | ↗ |
| 03 Sept 2020 | Comune di CasaloldoComune di Casaloldo was fined by the Garante for publishing personal data on its institutional website without an appropriate legal basis. The conduct breached the principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |
| 03 Sept 2020 | Deichmann Cipőkereskedelmi Korlátolt Felelősségű TársaságThe company failed to respond properly to data subject requests for access and restriction of processing. The authority also found inadequate technical and organizational measures for the processing of CCTV data. | HU | NAIH | GDPR | €55,800 | ↗ |
| 08 Sept 2020 | Sanatatea Press Group S.R.L.Sanatatea Press Group S.R.L. was fined EUR 2,000 by ANSPDCP for a data security breach during an online event. Login details were mistakenly sent to incorrect email addresses, resulting in disclosure of information to unauthorized recipients. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 08 Sept 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD €40,000 for processing personal data without a legal basis. The case involved fraudulent contracts created in individuals’ names without their consent, breaching the principle of lawful processing. | ES | AEPD | GDPR | €40,000 | ↗ |
| 11 Sept 2020 | BODEGAS DINASTIA, S.L.BODEGAS DINASTIA, S.L. was fined by the AEPD EUR 2,000 for non-compliance with data protection rules on its websites. The issues concerned the privacy policy and the way cookie consent was obtained. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 17 Sept 2020 | Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The Garante imposed an EUR 80,000 fine on Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli” for a data breach involving sensitive health data. The incident occurred during a platform maintenance period, indicating insufficient safeguards around processing. | IT | Garante | GDPR | €80,000 | ↗ |
| 17 Sept 2020 | Scanshare s.r.l.Scanshare s.r.l. was fined by the Garante 60,000 EUR for inadequate technical and organizational measures in handling candidate data during a hospital recruitment process. The authority also found a breach of GDPR Article 13 because the required information was not provided to candidates. | IT | Garante | GDPR | €60,000 | ↗ |
| 21 Sept 2020 | CONSEGURIDAD S.L.CONSEGURIDAD S.L. was fined 50,000 EUR by the AEPD for failing to appoint a Data Protection Officer. The authority found a breach of Article 37(1)(b) of the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 21 Sept 2020 | AVATA HISPANIA, S.L.AVATA HISPANIA, S.L. was fined by the AEPD 5,000 EUR for using personal data after the contract had ended. The company acted as a data processor, and continued use of the data was inconsistent with its obligations in that role. | ES | AEPD | GDPR | €5,000 | ↗ |
| 22 Sept 2020 | VENU SANZ CHEF, S.L.VENU SANZ CHEF, S.L. used a client's personal data, including full name, profile photo, and health information, for advertising purposes without consent. The AEPD found this conduct to be a breach of data protection rules. | ES | AEPD | GDPR | €3,000 | ↗ |
| 24 Sept 2020 | BRONSON BAR, S.L.BRONSON BAR, S.L. was fined 2,000 EUR by the AEPD. The company used the reverse side of a contract to create an inventory, which was then publicly displayed, breaching data integrity and confidentiality principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 25 Sept 2020 | SINDICATO DE TRABAJADORES DE LA ADMINISTRACIÓN PÚBLICA (STAP-CGT)The labor union STAP-CGT was fined EUR 3,000 by the AEPD for unlawful processing of personal data. The case concerned publishing a video of a court hearing on YouTube without proper consent, in breach of GDPR Article 6(1)(a). | ES | AEPD | GDPR | €3,000 | ↗ |
| 25 Sept 2020 | THE WASHPOINT S.L.THE WASHPOINT S.L. was fined by the AEPD 2,000 EUR for lacking a privacy policy and for having an improper cookie policy on its website. The breach concerned Article 13 of the GDPR and Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 29 Sept 2020 | PLAY ORENES, S.L.PLAY ORENES, S.L. was fined by the AEPD €20,000 for improperly positioning surveillance cameras. The cameras captured public areas, which breached data protection rules. | ES | AEPD | GDPR | €20,000 | ↗ |
| 29 Sept 2020 | GABINETE PARAPSICOLÓGICO MYSTIC S.L.The entity was fined for sending unsolicited advertising SMS messages without the recipient's consent. This conduct breached Article 21 of the LSSI and constituted unlawful marketing communication. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 29 Sept 2020 | Geanonimiseerd (APD 64/2020)The Litigation Chamber fined the data controller for failing to close email accounts after employees left the company. The authority found breaches of GDPR principles of purpose limitation, data minimization, and storage limitation. | BE | APD | GDPR | €5,000 | ↗ |
| 29 Sept 2020 | Vodafone Magyarország Távközlési Zártkörűen Működő RészvénytársaságThe NAIH imposed a 60,000,000 HUF fine on Vodafone Magyarország for unlawful voice recording practices at customer service offices. The authority found GDPR breaches relating to legal basis, transparency, purpose limitation, and data minimization. | HU | NAIH | GDPR | €163,000 | ↗ |