Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2022HOSPITAL POVISA, S.A.HOSPITAL POVISA, S.A. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned the improper inclusion of private health test results in a public health system, which violated the complainant’s privacy.ESAEPDGDPR€30,000
01 Jan 2022FEDERACIÓN DE SERVICIOS A LA CIUDADANÍA DE CCOOThe entity was fined by the AEPD €3,000 for breaching data protection principles. The case involved the improper disclosure of personal data related to a COVID-19 case among employees.ESAEPDGDPR€3,000
01 Jan 2022UNION SINDICAL OBRERAThe labor union UNION SINDICAL OBRERA was fined by the AEPD for failing to comply with a prior decision on the complainant’s right to data deletion. Despite being notified of the obligation to stop, it continued sending emails.ESAEPDGDPR€3,000
01 Jan 2022Unión de Oficiales Guardia Civil ProfesionalThe entity was fined for sending a letter containing personal data without prior consent, in breach of Article 6(1) GDPR. The case concerned unauthorized processing of personal data through the dispatch of correspondence to the data subject.ESAEPDGDPR€6,000
01 Jan 2022ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without consent. The conduct led to unauthorized contracts and credit reporting issues.ESAEPDGDPR€70,000
01 Jan 2022FUNDACIÓN CIPRI GÓMESFUNDACIÓN CIPRI GÓMES was fined EUR 4,000 by the AEPD for failing to provide information on personal data processing to athletes or their guardians. The authority also found unlawful processing of a minor's personal data after the parents had withdrawn him from the gym.ESAEPDGDPR€4,000
01 Jan 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 70,000 by the AEPD for disclosing one client's personal address to another client. The authority found a breach of personal data confidentiality obligations under the GDPR.ESAEPDGDPR€70,000
01 Jan 2022Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD EUR 15,000 for processing personal data without a legal basis. The case involved a contract fraudulently created in the complainant's name without consent.ESAEPDGDPR€15,000
01 Jan 2022ANIVERSALIA NETWORKS, S.L.ANIVERSALIA NETWORKS, S.L. was fined €2,000 by the AEPD. The authority found that the website did not provide adequate contact information for individuals to exercise their data protection rights.ESAEPDGDPR€2,000
01 Jan 2022ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP.The company was fined by the AEPD EUR 10,000 for processing personal data without consent. The authority also found that its website privacy information was insufficient, including missing contact details and information on data subject rights.ESAEPDGDPR€10,000
01 Jan 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for processing personal data without consent. The breach led to unauthorized access to personal data and fraudulent financial transactions.ESAEPDGDPR€70,000
01 Jan 2022GESTERPOOL, S.L.U.The AEPD imposed a 15,000 EUR fine on GESTERPOOL, S.L.U. for unauthorized use of personal data in a commercial call and for contract processing without consent. The case concerns breaches of GDPR rules, including Articles 28 and 58(1).ESAEPDGDPR€15,000
01 Jan 2022JEG'S LIFE STYLE, S.L.JEG'S LIFE STYLE, S.L. was fined by the AEPD 20,000 EUR for breaching data protection rules. The company disclosed private information about a former employee to third parties by email without consent.ESAEPDGDPR€20,000
01 Jan 2022UNIQUEDESIGN & DECOR, S.L.UNIQUEDESIGN & DECOR, S.L. was fined by the AEPD 5,000 EUR for not having an accessible privacy policy on its website. The authority found a breach of Article 13 GDPR because users were not properly provided with the required information.ESAEPDGDPR€5,000
01 Jan 2022CosmoteThe Greek data protection authority imposed a €6 million fine on Cosmote under decision 4/2022. The sanction concerned inadequate security measures and retaining more data than permitted after a 2020 cyberattack.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€6,000,000
01 Jan 2022VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD 70,000 EUR for unlawfully accessing a creditworthiness file. The company used an individual's tax ID without legitimate grounds, breaching data protection rules.ESAEPDGDPR€70,000
01 Jan 2022ADADE BURGOS, S.L.ADADE BURGOS, S.L. was fined by the AEPD EUR 5,000 for improper use of personal data. The company informed clients about an employee's disciplinary dismissal, which breached data protection rules.ESAEPDGDPR€5,000
01 Jan 2022GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the AEPD for processing a broad range of delivery riders’ personal data without adequate data protection measures. The authority found breaches of GDPR Articles 25 and 32, relating to privacy by design and processing security.ESAEPDGDPR€550,000
01 Jan 2022BANQUETES SANTA ANA, S.L.BANQUETES SANTA ANA, S.L. was fined EUR 5,000 by the AEPD for collecting personal data, including DNI numbers, from wedding guests without providing information about data processing. The authority found a breach of data minimization and transparency obligations.ESAEPDGDPR€5,000
01 Jan 2022B.B.B.B.B.B. was fined 2,000 EUR by the AEPD. The authority found that the company forwarded emails containing personal data without proper authorization, in breach of Article 6 of the GDPR.ESAEPDGDPR€2,000