BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Sept 2020 | Követeléskezelő cég által végzett adatkezelés jogszerűségeThe authority imposed a fine for violating the data subject’s right to erasure because outdated address data was not deleted. It also found that personal data was processed without a proper legal basis. | HU | NAIH | GDPR | €2,740 | ↗ |
| 01 Oct 2020 | Asociația de proprietari Militari R, comuna Chiajna, județul IlfovThe homeowners' association was fined by ANSPDCP €2,000 for failing to respond to a data subject's request. The authority treated this as a breach of GDPR rules on the exercise of individual rights. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 01 Oct 2020 | Università Campus Bio-medico di RomaThe Garante fined Università Campus Bio-medico di Roma 20,000 EUR for a data protection breach. Online medical reports were accessible to other patients, resulting in unauthorized disclosure of sensitive information. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Oct 2020 | Megareduceri TV S.R.L.Megareduceri TV S.R.L. was fined EUR 3,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with certain personal data protection obligations. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 02 Oct 2020 | INSTITUTO DEL DAÑO CEREBRAL Y PSÍQUICO, S.L.The entity did not provide timely access to clinical records, which constituted a breach of data protection obligations. Deficiencies were also identified in the website's cookie policy, leading the AEPD to impose a fine. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 02 Oct 2020 | GRUPO OCIO DESARROLLO Y SERVICIOS, S.L.The entity was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited commercial communications via WhatsApp. The authority found a breach of the complainant's rights to data protection and to object to data processing. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 05 Oct 2020 | Pontosság elvének megsértéseThe controller was fined for processing inaccurate personal data, in breach of the accuracy principle under GDPR Art. 5(1)(d). The authority also ordered correction of the complainant’s address data. | HU | NAIH | GDPR | €1,674 | ↗ |
| 06 Oct 2020 | PROSAD CONSULTORES, S.L.PROSAD CONSULTORES, S.L. was fined by the AEPD 12,000 EUR for sending unsolicited commercial emails without prior consent. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €12,000 | ↗ |
| 07 Oct 2020 | UST GLOBAL ESPAÑA, S.A.UST Global España, S.A. was fined by the AEPD EUR 5,000 for improperly sharing employees’ personal data in a group email. The disclosed data included names, email addresses, and DNI numbers, which breached data protection principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 08 Oct 2020 | Servicio de Alojamientos Responsables, S.L.The entity was fined by the AEPD 6,000 EUR for processing personal data without a legal basis. The breach involved signing a contract on behalf of an individual without authorization. | ES | AEPD | GDPR | €6,000 | ↗ |
| 08 Oct 2020 | Anonymizováno (ÚOOÚ UOOU-00179/19-38)The entity was fined for retaining personal data of financial service applicants longer than necessary, failing to inform them about potential data recipients, and lacking internal data protection measures. The authority found these practices inconsistent with data protection obligations. | CZ | UOOU | GDPR | €6,459 | ↗ |
| 14 Oct 2020 | Munkahelyi kamerás megfigyelés célhoz kötöttséggel, adattakarékossággal és az érintettek tájékoztatásával kapcsolatos hiányosságaiThe entity was fined by NAIH in the amount of HUF 700,000 for improperly implementing camera surveillance of employees. The authority also found that employees were not adequately informed about the scope and rules of the video monitoring. | HU | NAIH | GDPR | €1,925 | ↗ |
| 15 Oct 2020 | Comune di CollegnoComune di Collegno was fined by the Garante for failing to respond in time to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €2,000 | ↗ |
| 19 Oct 2020 | Anonymisiert (DSB 2020-0.550.322)An individual was fined for unlawfully processing image data by using a smartphone to record a person in a restroom. The authority found a breach of the principles of lawfulness, fairness, and transparency under Art. 5 GDPR and no legal basis under Art. 6 GDPR. | AT | DSB | GDPR | €150 | ↗ |
| 19 Oct 2020 | Anonymisiert (DSB 2020-0.111.488)A fine of EUR 600 was imposed for publishing excerpts from patient letters and medical records on a personal Facebook page. The authority found that personal data and health data were processed without consent or another legal basis. | AT | DSB | GDPR | €600 | ↗ |
| 19 Oct 2020 | PREDASE SERVICIOS INTEGRALES SOCIEDAD LIMITADAPREDASE SERVICIOS INTEGRALES S.L. was fined EUR 5,000 by the AEPD for failing to publish a privacy policy on its website and for misleadingly using the AEPD logo. The conduct could imply an association with the authority and influence user decisions. | ES | AEPD | GDPR | €5,000 | ↗ |
| 21 Oct 2020 | HEREDAD DE UREÑA, S.L.HEREDAD DE UREÑA, S.L. was fined by the AEPD EUR 4,000 for not having a privacy policy on its website, lacking a cookies policy, and sending unsolicited marketing emails without consent. The case indicates failures in basic transparency obligations and consent requirements for electronic communications. | ES | AEPD | GDPR | €4,000 | ↗ |
| 21 Oct 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 60,000 for processing personal data without proper consent. The case involved a customer receiving a notification of a purchase they had not made, indicating improper use of personal data. | ES | AEPD | GDPR | €60,000 | ↗ |
| 22 Oct 2020 | Jogalap nélküli adattovábbítás mobilparkolási szolgáltatás kapcsánThe controller transferred the complainant's personal data to the complainant's employer without a valid legal basis. This breached the purpose limitation principle and the complainant's right of access. | HU | NAIH | GDPR | €5,480 | ↗ |
| 26 Oct 2020 | ***EMPRESA.1.The company was fined by the AEPD 10,000 EUR for sending an email containing personal data of a former employee to a third party without authorization. The case involved a breach of data protection principles and unauthorized disclosure of information. | ES | AEPD | GDPR | €10,000 | ↗ |