Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Jan 2023NANDIVALE, S.L.NANDIVALE, S.L. was fined by the AEPD EUR 10,000 for publishing images of minors on Instagram without parental consent. The authority found this conduct to be in breach of GDPR Article 6(1).ESAEPDGDPR€10,000
04 Jan 2023Apă Canal Ilfov SAThe company was fined EUR 3,000 by ANSPDCP for a data security breach. User information was exposed because email addresses were entered in the “To” field instead of “BCC”.ROANSPDCPGDPR€3,000
03 Jan 2023QUALITY-PROVIDER, S.A.QUALITY-PROVIDER, S.A. was fined by the AEPD in the amount of 30,000 EUR for processing personal data without consent. The data were then shared with third parties, who used them to contact the complainant via a personal social network.ESAEPDGDPR€30,000
03 Jan 2023Asociație de proprietari din IașiA homeowners' association in Iași was fined 500 EUR by ANSPDCP for GDPR violations. The case concerned failure to comply with personal data protection requirements as a controller.ROANSPDCPGDPR€500
02 Jan 2023Dulnevnd fyritøka (Dátueftirlitið)DATFO referred a company to the police for suspected breaches of data protection law. The company collected and stored personal data without a valid legal basis and without providing adequate information to the data subjects. Its website contact mechanism also caused data intended for a specific provider to be collected and retained by the company.FODATFOGDPR€13,446
01 Jan 2023THE RED KIWI, S.L.THE RED KIWI, S.L. was fined 30,000 EUR by the AEPD. The breach involved adding clients’ phone numbers to a WhatsApp group without consent, which enabled unauthorized access to personal data.ESAEPDGDPR€30,000
01 Jan 2023PHONE HOUSEPHONE HOUSE was fined by the AEPD for failing to ensure data integrity and confidentiality. The breach resulted in a data incident caused by a cyberattack.ESAEPDGDPR€6,500,000
01 Jan 2023Vodafone España, S.A.U.The AEPD fined Vodafone España EUR 70,000 for providing a SIM card duplicate to a third party without the data subject's consent. This enabled unauthorized access to personal and banking information.ESAEPDGDPR€70,000
01 Jan 2023MAKING SOLUTIONS, S.L. (MY PERFECT WEDDING)MY PERFECT WEDDING was fined by the AEPD EUR 1,000 for failing to properly provide personal data in response to the complainant’s request. The authority found a breach of Article 15 GDPR, which governs the right of access.ESAEPDGDPR€1,000
01 Jan 2023INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L.INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L. was fined by the AEPD EUR 7,000 for unlawfully disclosing personal data, including health information, in response to a Google review. The authority found a breach of confidentiality and of the security obligations under the GDPR.ESAEPDGDPR€7,000
01 Jan 2023PUNTO ROJO LIBROS, S.L.PUNTO ROJO LIBROS, S.L. was fined by the AEPD 1,000 EUR for failing to adequately respond to a data subject’s request for information about the origin of their personal data. The authority treated this as a breach of GDPR obligations.ESAEPDGDPR€1,000
01 Jan 2023EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.EL ESPAÑOL was fined 10,000 EUR by the AEPD for publishing a private video without the consent of the data subject. The case concerns a breach of data protection rules.ESAEPDGDPR€10,000
01 Jan 2023SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L. was fined by the AEPD 50,000 EUR for processing personal data without consent. The case involved formalizing an electricity supply contract and charging the complainant's bank account without authorization.ESAEPDGDPR€50,000
01 Jan 2023ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD in the amount of 50,000 EUR for publishing excessive personal data. The case concerned an audio recording of a victim's court statement, which was not necessary for the journalistic purpose.ESAEPDGDPR€50,000
01 Jan 2023Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without a proper legal basis. The breach enabled unauthorized SIM card duplication and subsequent fraudulent bank transactions.ESAEPDGDPR€70,000
01 Jan 2023CARSO TRADING, S.L.CARSO TRADING, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails. The company also failed to respond to a data access request, which constitutes a breach of Article 15 GDPR.ESAEPDGDPR€1,000
01 Jan 2023ISA MADRID SERVICIOS, S.L.ISA MADRID SERVICIOS, S.L. was fined EUR 900 by the AEPD for improperly positioning a surveillance camera that captured public areas. The authority also found that adequate signage informing individuals about the surveillance was not provided, in breach of data protection rules.ESAEPDGDPR€900
01 Jan 2023BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for a data breach after an employee accessed a customer's banking information and shared it without consent. The authority found that data security measures were violated.ESAEPDGDPR€70,000
01 Jan 2023MASLUZ ENERGY POWER, S.L.MASLUZ ENERGY POWER, S.L. was fined EUR 90,000 by the AEPD for changing a customer's energy provider without authorization. The authority also found a failure to provide the required information, constituting breaches of GDPR Articles 13 and 6(1).ESAEPDGDPR€90,000
01 Jan 2023B.B.B.The entity installed a video surveillance system in a garage without the required authorization and without informing the affected individuals. This constituted a breach of data protection rules and resulted in a EUR 600 fine imposed by the AEPD.ESAEPDGDPR€600