Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Apr 2025Energia Pulita S.r.l.Energia Pulita S.r.l. was fined by the Garante for improper handling of personal data in telemarketing activities. The authority also noted failure to cooperate with the supervisory authority and incorrect identification of roles in data processing.ITGaranteGDPR€10,000
22 Feb 2023ENERGÍA COLECTIVA, S.L.ENERGÍA COLECTIVA, S.L. was fined by the AEPD 70,000 EUR for changing an individual's electricity provider without consent. The authority found a breach of Article 6 GDPR, which requires a lawful basis for processing personal data.ESAEPDGDPR€70,000
01 Jan 2023ENERGÍA COLECTIVA, S.L.ENERGÍA COLECTIVA, S.L. was fined by the AEPD for inaccurately processing personal data. The issue led to incorrect billing and an intrusion into individuals’ privacy.ESAEPDGDPR€70,000
04 Mar 2010Enel s.p.a.Enel s.p.a. was fined EUR 24,000 by the Garante for failing to respond to a request for information concerning data protection. The breach concerned Articles 157 and 164 of the Italian Data Protection Code.ITGaranteGDPR€24,000
22 Aug 2022Enel Energie Muntenia S.A.The company was fined by ANSPDCP for failing to implement sufficient security measures. The breach concerned inadequate safeguards required to protect data.ROANSPDCPGDPR€10,000
12 Mar 2026Enel Energia S.p.A.Enel Energia S.p.A. was fined by the Italian data protection authority, Garante, for making unwanted telemarketing calls without a proper legal basis. The authority found that the company’s conduct breached data protection principles.ITGaranteGDPR€563,000
Enel Energia SpAEnel Energia SpA was fined EUR 79.1 million by the Italian data protection authority, Garante. The case concerned misuse of personal data and was a major GDPR enforcement action.ITGarante per la protezione dei dati personaliGDPR€79,100,000
16 Dec 2021Enel Energia S.p.a.Enel Energia S.p.a. was investigated for improper promotional contacts, including contacts to individuals with reserved numbers or registered in the ROP. The authority also challenged making access to online services conditional on consent to marketing and profiling.ITGaranteGDPR€26,513,000
12 Feb 2015Enel Energia S.p.a.Enel Energia S.p.a. was fined by the Garante 200,000 EUR for failing to provide information and obtain consent for processing personal data for promotional purposes. The breach affected a large database of approximately 43.1 million contacts.ITGaranteGDPR€200,000
19 Mar 2019Enel Energia s.p.a.Enel Energia s.p.a. was fined by the Garante EUR 80,000 for failing to implement adequate security measures. This allowed unauthorized access and massive data downloads by a third-party company using credentials of former employees.ITGaranteGDPR€80,000
29 Jul 2013ENDESA, S.A.ENDESA, S.A. was fined EUR 600 by the AEPD for sending commercial emails to a former customer despite requests to delete personal data. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
01 Dec 2023ENDESA, S.A.The Spanish data protection authority imposed a EUR 6.1 million fine on ENDESA in December 2023. The case involved a security breach that led to the sale of customer personal data through Facebook ads.ESAgencia Española de Protección de DatosGDPR€6,100,000
06 May 2019ENDESA ENERGÍA XXI, S.L.U.ENDESA ENERGÍA XXI, S.L.U. was fined by the AEPD 100,000 EUR for a data protection breach. An agent mistakenly altered a contract, replacing the complainant’s data with that of a third party.ESAEPDGDPR€100,000
17 Jan 2023ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without valid consent. The case concerned a contract entered into in the name of a deceased person without authorization.ESAEPDGDPR€70,000
04 Oct 2021ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 50,000 EUR for breaching GDPR data accuracy principles. The case involved identity theft and false documentation in a request to transfer an electricity contract.ESAEPDGDPR€50,000
04 Mar 2022ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined EUR 50,000 by the AEPD for a personal data protection violation. The case involved unauthorized changes to a contract holder's information, resulting in a security breach under Article 32 of the GDPR.ESAEPDGDPR€50,000
18 May 2015ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 5,000 EUR for sending commercial emails to a recipient who had requested to unsubscribe. The case concerns a breach of Article 21.1 of the LSSI and shows failure to respect an opt-out request.ESAEPDePrivacy€5,000
01 Jan 2024ENDESA ENERGIA, S.A.U.ENDESA ENERGIA, S.A.U. was fined €200,000 by the AEPD for changing the contract holder and bank account without consent. The authority found a breach of data protection principles.ESAEPDGDPR€200,000
01 Jan 2015ENDESA ENERGÍA S.A.ENDESA ENERGÍA S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial SMS messages to a complainant who had previously opted out of such communications. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€5,000
02 Sept 2010ENDESA ENERGIA, S.A.ENDESA ENERGIA, S.A. was fined by the AEPD for sending unsolicited commercial emails despite the recipient’s request to stop receiving such messages. The conduct breached Article 21.1 of the LSSI on marketing communications without consent.ESAEPDePrivacy€600