Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 May 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a SIM card duplicate without verifying the requester’s identity. The failure enabled unauthorized access to a bank account and caused financial loss to the complainant.ESAEPDGDPR€70,000
04 May 2022Concordia Capital IFN S.A.The company was fined for installing audio-video cameras in employee offices. The authority found that this monitoring violated data protection rules.ROANSPDCPGDPR€4,000
05 May 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD EUR 70,000 for a data protection breach involving unauthorized SIM card duplication. The incident led to unauthorized bank transfers from the complainant's account.ESAEPDGDPR€70,000
05 May 2022SOCIEDAD ESPAÑOLA DE RADIODIFUSIÓN, S.L.The Spanish Data Protection Agency (AEPD) fined SOCIEDAD ESPAÑOLA DE RADIODIFUSIÓN, S.L. EUR 50,000 for publishing audio of a victim’s court testimony without adequate data protection safeguards. The authority found a breach of GDPR Article 5(1)(c) on data minimization.ESAEPDGDPR€50,000
05 May 2022ABUNTIA SERVICES, S.L.ABUNTIA SERVICES, S.L. was fined by the AEPD EUR 1,500 for sending commercial SMS messages without prior consent from recipients. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€1,500
05 May 2022THOMAS INTERNATIONAL SYSTEMS, S.A.THOMAS INTERNATIONAL SYSTEMS, S.A. was fined by the AEPD 50,000 EUR for processing special categories of personal data without proper legal justification. The company requested sensitive information, including disability and ethnicity, in psychometric questionnaires.ESAEPDGDPR€50,000
05 May 2022LYCAMOBILE S.L.U.LYCAMOBILE S.L.U. was fined by the AEPD 56,000 EUR for processing personal data without consent. The case involved unauthorized phone number portability, which could create a risk of identity theft.ESAEPDGDPR€56,000
05 May 2022РТК ЕООДThe company processed personal data without a lawful basis by including an individual's data in a public register without a valid contract or consent. The authority found this to be a breach of data protection principles and imposed a fine.BGCPDPGDPR€5,113
05 May 2022JOYPAZAR, S.A.JOYPAZAR, S.A. was fined by the AEPD for reinstalling a surveillance camera that captured images of a public children's park. The authority found this to be a breach of data protection rules.ESAEPDGDPR€2,000
09 May 2022FARMACIA MERCADO CENTRAL DE SAN FERNANDO C.BThe pharmacy was fined by the AEPD for operating a video surveillance system that recorded public areas and conversations between employees and customers. The authority found that this processing breached data protection rules.ESAEPDGDPR€1,000
10 May 2022B.B.B.The entity was fined by the AEPD EUR 300 for installing surveillance cameras that recorded a neighbor’s property and a public street. The authority found this to be a breach of data protection rules.ESAEPDGDPR€300
10 May 2022CONECTA5 TELECINCO, S.A.U.CONECTA5 TELECINCO, S.A.U. was fined by the AEPD 50,000 EUR for publishing audio of a victim’s court testimony without voice distortion. The authority found a breach of data protection principles.ESAEPDGDPR€50,000
11 May 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 70,000 by the AEPD for issuing a duplicate SIM card without the customer's consent. This enabled unauthorized access to the customer's bank account, indicating a serious failure in security and data protection controls.ESAEPDGDPR€70,000
11 May 2022LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD 50,000 EUR for publishing audio of a victim's court statement in a high-profile case. The authority found excessive processing of personal data and a breach of data protection rules.ESAEPDGDPR€50,000
12 May 2022Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante €7,000 for violations related to the processing of health data. The authority also found insufficient data security measures.ITGaranteGDPR€7,000
12 May 2022Minimarket di Alam SaifulThe Garante fined Minimarket di Alam Saiful 1,000 EUR for operating a video surveillance system without the required notice to individuals being recorded. The case concerned a breach of data protection information obligations.ITGaranteGDPR€1,000
12 May 2022Zito Auto di Gianfranco ZitoThe company was fined for operating a video surveillance system that did not meet the information requirements under GDPR Article 13 and Article 114 of the Italian Privacy Code. The authority found that the required notices for monitored individuals were not properly provided.ITGaranteGDPR€3,000
12 May 2022Hu XiaoyanThe Garante fined Hu Xiaoyan EUR 20,000 for operating a video surveillance system without proper informational signage and required safeguards. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
12 May 2022Singh Market S.r.l.The Garante fined Singh Market S.r.l. 2,000 EUR for operating a video surveillance system without the required informational signage. The authority found a breach of Article 13 GDPR.ITGaranteGDPR€2,000
12 May 2022LORIS FUEL SHOP SRLLORIS FUEL SHOP SRL was fined EUR 1,000 by ANSPDCP for breaches of GDPR rules on data processing and security measures. The case indicates compliance gaps in personal data protection controls.ROANSPDCPGDPR€1,000