BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Feb 2023 | COMMUNE (procédure simplifiée)CNIL imposed a EUR 5,000 fine on COMMUNE under a simplified procedure and issued an injunction. The case concerned a confirmed breach requiring corrective action. | FR | CNIL | GDPR | €5,000 | ↗ |
| 08 Feb 2023 | DKN.5131.50.2021StatusprawomocnaTytuUODO imposed a PLN 33,012 fine on the controller and the processor for failing to implement appropriate technical and organizational measures to secure personal data. The authority also found that the controller did not verify whether the processor provided sufficient guarantees of GDPR compliance and protection of data subjects' rights. | PL | UODO | GDPR | €6,967 | ↗ |
| 08 Feb 2023 | SOCIETE EXERCANT UNE ACTIVITE DE DETAIL D'HABILLEMENT EN MAGASIN SPECIALISE (procédure simplifiée)CNIL imposed a fine of 10,000 EUR on SOCIETE EXERCANT UNE ACTIVITE DE DETAIL D'HABILLEMENT EN MAGASIN SPECIALISE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 08 Feb 2023 | VODAFONE SERVICIOS, S.L.U.VODAFONE SERVICIOS, S.L.U. was fined by the AEPD 70,000 EUR for a SIM card duplication incident. The incident resulted in identity theft and unauthorized access to a bank account, indicating a breach of data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 08 Feb 2023 | MEDECIN GENERALISTE (procédure simplifiée)The CNIL imposed a EUR 3,000 fine on MEDECIN GENERALISTE under a simplified procedure. The authority also issued an injunction to remedy the identified deficiencies. | FR | CNIL | GDPR | €3,000 | ↗ |
| 07 Feb 2023 | Dane anonimowe (Wspólnotę Mieszkaniową „)UODO imposed an administrative fine on a housing community for entrusting personal data processing to an external provider without a written agreement and without verifying adequate technical and organizational safeguards. The authority also cited the failure to notify affected individuals without undue delay about the personal data breach. | PL | UODO | GDPR | €327 | ↗ |
| 06 Feb 2023 | VODAFONE ESPAÑA, S.A.U.The AEPD imposed a 200,000 EUR fine on VODAFONE ESPAÑA, S.A.U. for breaching Article 6(1) GDPR. The case involved unauthorized SIM card duplication that enabled fraudulent bank charges. | ES | AEPD | GDPR | €200,000 | ↗ |
| 06 Feb 2023 | ONEY SERVICIOS FINANCIEROS E.F.C., S.A.ONEY SERVICIOS FINANCIEROS E.F.C., S.A. was fined by the AEPD 50,000 EUR for inaccurately processing personal data. The company included incorrect debt information in credit information systems, breaching data protection principles. | ES | AEPD | GDPR | €50,000 | ↗ |
| 06 Feb 2023 | I&S Limited Kft.I&S Limited Kft. was fined by NAIH for continuous recording of work activities and monitoring guests, as well as for misleading information about data processing. The authority also found unauthorized processing of health data for marketing purposes. | HU | NAIH | GDPR | €76,800 | ↗ |
| 06 Feb 2023 | ROMBOC COMUNICACIONESROMBOC COMUNICACIONES was fined by the AEPD in the amount of 2,000 EUR for making misleading advertising calls without explicit consent from recipients. The case indicates a breach of data protection and direct marketing rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 03 Feb 2023 | Epic LtdEpic Ltd was fined by the CyDPC in the amount of 3,250 EUR for making unsolicited calls to former customers without a legal basis. The authority also found insufficient technical and organizational measures to ensure compliant data processing and inadequate data security controls. | CY | CyDPC | GDPR | €3,250 | ↗ |
| 02 Feb 2023 | LEADDESK, S.L.LEADDESK, S.L. was fined 500 EUR by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information to the authority, which constitutes a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 02 Feb 2023 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card without the complainant's consent. The incident led to attempts to gain unauthorized access to the complainant's bank accounts. | ES | AEPD | GDPR | €70,000 | ↗ |
| 02 Feb 2023 | TRACTAMENT D'AIGUES TEIA, S.L.TRACTAMENT D'AIGUES TEIA, S.L. was fined by the AEPD EUR 1,000 for failing to comply with a data subject's request to delete personal data. The case indicates non-compliance with GDPR obligations regarding the exercise of individual rights. | ES | AEPD | GDPR | €1,000 | ↗ |
| 02 Feb 2023 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for changing a customer's contract ownership and activating services without consent. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Feb 2023 | Tensa Art Design SAANSPDCP completed an investigation in January 2023 at Tensa Art Design SA and found violations of GDPR provisions. As a result, the company was fined EUR 1,000. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 31 Jan 2023 | Dent Estet Clinic SADent Estet Clinic SA was fined by ANSPDCP EUR 1,000 for breaches of the transparency obligations under GDPR Articles 12–14. The case concerned inadequate compliance with information duties toward data subjects. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 31 Jan 2023 | Dent Estet Clinic SADent Estet Clinic SA was fined EUR 1,000 by ANSPDCP for failing to notify the supervisory authority within 72 hours of becoming aware of a personal data breach. The incident involved unauthorized disclosure of health data, which required prompt reporting under GDPR rules. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 31 Jan 2023 | PRESTAMER, S.L.PRESTAMER, S.L. sent an email to 472 recipients without using BCC, which exposed recipients’ personal data. The AEPD imposed a 3,000 EUR fine for breaching data protection rules. | ES | AEPD | GDPR | €3,000 | ↗ |
| 30 Jan 2023 | COMUNIDAD DE PROPIETARIOS RÍO CANARIOThe entity did not provide the requested information to the Spanish Data Protection Agency (AEPD). The conduct breached Article 58(1) of the GDPR and resulted in a 500 EUR fine. | ES | AEPD | GDPR | €500 | ↗ |