Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Jan 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card without proper authorization. The incident enabled unauthorized access to a customer's bank account.ESAEPDGDPR€70,000
07 Jan 2022Elektro & Automasjon Systemer ASElektro & Automasjon Systemer AS was fined NOK 200,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The company checked a co-owner of another company despite having no business relationship or justification for the credit check.NODatatilsynetGDPR€19,942
07 Jan 2022CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD EUR 70,000 for including personal data in credit information systems without a proper legal basis. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
06 Jan 2022B.B.B.A fine was imposed for the mass dissemination of a video recorded without the victim’s consent on social media and via WhatsApp. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€10,000
05 Jan 2022Egnatia Odos S.A.Egnatia Odos S.A. was fined by the HDPA EUR 1,000 for failing to provide the complainant with access to personal data related to a toll violation. The authority found a breach of the right of access under the GDPR.GRHDPAGDPR€1,000
05 Jan 2022CONTIMAG INVEST, S.L.CONTIMAG INVEST, S.L. was fined by the AEPD 1,200 EUR for operating a video surveillance system without the required informational signage. The authority found a breach of Article 13 GDPR on transparency and information duties.ESAEPDGDPR€1,200
05 Jan 2022B.B.B.A camera was installed in a vehicle parked in a community garage and recorded communal areas. The community was not informed and no required signage was displayed, resulting in a breach of data protection rules.ESAEPDGDPR€1,500
05 Jan 2022CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined by the AEPD in the amount of EUR 5,000 for sending commercial SMS messages without the recipient’s consent. The conduct breached Article 21 of the LSSI, which governs unsolicited electronic marketing.ESAEPDePrivacy€5,000
04 Jan 2022BEAUTY & AESTHETIC BALEARIC, SL.BEAUTY & AESTHETIC BALEARIC, SL. was fined by the AEPD €1,000 for sending marketing emails without an opt-out mechanism. The authority found this to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,000
01 Jan 2022B.B.B.B.B.B. was fined 1,000 EUR by the AEPD. The authority found that the company shared individuals’ personal data in a WhatsApp group without consent, in breach of data protection rules.ESAEPDGDPR€1,000
01 Jan 2022ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company impersonated another energy provider and used personal data without consent.ESAEPDGDPR€10,000
01 Jan 2022BOOKSY INTERNATIONAL SPOLKA, S.L.BOOKSY INTERNATIONAL SPOLKA, S.L. was fined by the AEPD €500 for sending unsolicited commercial SMS messages. The recipient was registered on the Robinson List, which constituted a breach of Article 21 of the LSSI.ESAEPDePrivacy€500
01 Jan 2022CAIXABANK S.A.CaixaBank was fined EUR 25,000 by the AEPD for failing to update a customer's address despite repeated requests. The authority found this to be a breach of the GDPR right to rectification.ESAEPDGDPR€25,000
01 Jan 2022HOSPITAL POVISA, S.A.HOSPITAL POVISA, S.A. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned the improper inclusion of private health test results in a public health system, which violated the complainant’s privacy.ESAEPDGDPR€30,000
01 Jan 2022FEDERACIÓN DE SERVICIOS A LA CIUDADANÍA DE CCOOThe entity was fined by the AEPD €3,000 for breaching data protection principles. The case involved the improper disclosure of personal data related to a COVID-19 case among employees.ESAEPDGDPR€3,000
01 Jan 2022UNION SINDICAL OBRERAThe labor union UNION SINDICAL OBRERA was fined by the AEPD for failing to comply with a prior decision on the complainant’s right to data deletion. Despite being notified of the obligation to stop, it continued sending emails.ESAEPDGDPR€3,000
01 Jan 2022Unión de Oficiales Guardia Civil ProfesionalThe entity was fined for sending a letter containing personal data without prior consent, in breach of Article 6(1) GDPR. The case concerned unauthorized processing of personal data through the dispatch of correspondence to the data subject.ESAEPDGDPR€6,000
01 Jan 2022ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without consent. The conduct led to unauthorized contracts and credit reporting issues.ESAEPDGDPR€70,000
01 Jan 2022FUNDACIÓN CIPRI GÓMESFUNDACIÓN CIPRI GÓMES was fined EUR 4,000 by the AEPD for failing to provide information on personal data processing to athletes or their guardians. The authority also found unlawful processing of a minor's personal data after the parents had withdrawn him from the gym.ESAEPDGDPR€4,000
01 Jan 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 70,000 by the AEPD for disclosing one client's personal address to another client. The authority found a breach of personal data confidentiality obligations under the GDPR.ESAEPDGDPR€70,000