BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Apr 2025 | Energia Pulita S.r.l.Energia Pulita S.r.l. was fined by the Garante for improper handling of personal data in telemarketing activities. The authority also noted failure to cooperate with the supervisory authority and incorrect identification of roles in data processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Feb 2023 | ENERGÍA COLECTIVA, S.L.ENERGÍA COLECTIVA, S.L. was fined by the AEPD 70,000 EUR for changing an individual's electricity provider without consent. The authority found a breach of Article 6 GDPR, which requires a lawful basis for processing personal data. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2023 | ENERGÍA COLECTIVA, S.L.ENERGÍA COLECTIVA, S.L. was fined by the AEPD for inaccurately processing personal data. The issue led to incorrect billing and an intrusion into individuals’ privacy. | ES | AEPD | GDPR | €70,000 | ↗ |
| 04 Mar 2010 | Enel s.p.a.Enel s.p.a. was fined EUR 24,000 by the Garante for failing to respond to a request for information concerning data protection. The breach concerned Articles 157 and 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €24,000 | ↗ |
| 22 Aug 2022 | Enel Energie Muntenia S.A.The company was fined by ANSPDCP for failing to implement sufficient security measures. The breach concerned inadequate safeguards required to protect data. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 12 Mar 2026 | Enel Energia S.p.A.Enel Energia S.p.A. was fined by the Italian data protection authority, Garante, for making unwanted telemarketing calls without a proper legal basis. The authority found that the company’s conduct breached data protection principles. | IT | Garante | GDPR | €563,000 | ↗ |
| — | Enel Energia SpAEnel Energia SpA was fined EUR 79.1 million by the Italian data protection authority, Garante. The case concerned misuse of personal data and was a major GDPR enforcement action. | IT | Garante per la protezione dei dati personali | GDPR | €79,100,000 | ↗ |
| 16 Dec 2021 | Enel Energia S.p.a.Enel Energia S.p.a. was investigated for improper promotional contacts, including contacts to individuals with reserved numbers or registered in the ROP. The authority also challenged making access to online services conditional on consent to marketing and profiling. | IT | Garante | GDPR | €26,513,000 | ↗ |
| 12 Feb 2015 | Enel Energia S.p.a.Enel Energia S.p.a. was fined by the Garante 200,000 EUR for failing to provide information and obtain consent for processing personal data for promotional purposes. The breach affected a large database of approximately 43.1 million contacts. | IT | Garante | GDPR | €200,000 | ↗ |
| 19 Mar 2019 | Enel Energia s.p.a.Enel Energia s.p.a. was fined by the Garante EUR 80,000 for failing to implement adequate security measures. This allowed unauthorized access and massive data downloads by a third-party company using credentials of former employees. | IT | Garante | GDPR | €80,000 | ↗ |
| 29 Jul 2013 | ENDESA, S.A.ENDESA, S.A. was fined EUR 600 by the AEPD for sending commercial emails to a former customer despite requests to delete personal data. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 01 Dec 2023 | ENDESA, S.A.The Spanish data protection authority imposed a EUR 6.1 million fine on ENDESA in December 2023. The case involved a security breach that led to the sale of customer personal data through Facebook ads. | ES | Agencia Española de Protección de Datos | GDPR | €6,100,000 | ↗ |
| 06 May 2019 | ENDESA ENERGÍA XXI, S.L.U.ENDESA ENERGÍA XXI, S.L.U. was fined by the AEPD 100,000 EUR for a data protection breach. An agent mistakenly altered a contract, replacing the complainant’s data with that of a third party. | ES | AEPD | GDPR | €100,000 | ↗ |
| 17 Jan 2023 | ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without valid consent. The case concerned a contract entered into in the name of a deceased person without authorization. | ES | AEPD | GDPR | €70,000 | ↗ |
| 04 Oct 2021 | ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 50,000 EUR for breaching GDPR data accuracy principles. The case involved identity theft and false documentation in a request to transfer an electricity contract. | ES | AEPD | GDPR | €50,000 | ↗ |
| 04 Mar 2022 | ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined EUR 50,000 by the AEPD for a personal data protection violation. The case involved unauthorized changes to a contract holder's information, resulting in a security breach under Article 32 of the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 18 May 2015 | ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 5,000 EUR for sending commercial emails to a recipient who had requested to unsubscribe. The case concerns a breach of Article 21.1 of the LSSI and shows failure to respect an opt-out request. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jan 2024 | ENDESA ENERGIA, S.A.U.ENDESA ENERGIA, S.A.U. was fined €200,000 by the AEPD for changing the contract holder and bank account without consent. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2015 | ENDESA ENERGÍA S.A.ENDESA ENERGÍA S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial SMS messages to a complainant who had previously opted out of such communications. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 02 Sept 2010 | ENDESA ENERGIA, S.A.ENDESA ENERGIA, S.A. was fined by the AEPD for sending unsolicited commercial emails despite the recipient’s request to stop receiving such messages. The conduct breached Article 21.1 of the LSSI on marketing communications without consent. | ES | AEPD | ePrivacy | €600 | ↗ |