Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2023ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 200,000 by the AEPD for issuing a duplicate SIM card to a third party without the complainant's consent. The incident enabled unauthorized access to personal and banking data, indicating a serious data protection failure.ESAEPDGDPR€200,000
01 Jan 2023QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined 20,000 EUR by the AEPD for unlawfully obtaining personal data from a website. The data was then used for promotional purposes without the consent of the data subjects.ESAEPDGDPR€20,000
01 Jan 2023CLUB VOLEIBOL ***CLUB.1The club was fined by the AEPD in the amount of EUR 500 for publishing minors' images without proper consent. The authority also found that the club failed to provide access to personal data requested by a parent.ESAEPDGDPR€500
01 Jan 2023LOCAL VERTICALS, S.L.The company was fined by the AEPD in the amount of 10,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€10,000
01 Jan 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 100,000 EUR for allowing a third party to impersonate a customer. This led to a mobile line portability request and the purchase of a mobile device without the customer’s consent.ESAEPDGDPR€100,000
01 Jan 2023NATURGY IBERIA, S.A.Naturgy Iberia was fined for changing a customer's gas and electricity supplier without authorization. The authority found that this breached Article 6(1) of the GDPR because there was no lawful basis for the processing.ESAEPDGDPR€100,000
01 Jan 2023GENERAL LOGISTICS SYSTEMS SPAIN, S.A.GENERAL LOGISTICS SYSTEMS SPAIN, S.A. was fined by the AEPD 140,000 EUR for processing the personal data of two complainants without proper authorization. The breach resulted in identity theft and misuse of personal data.ESAEPDGDPR€140,000
01 Jan 2023GLOVOGLOVO was fined EUR 15,000 by the AEPD for failing to properly handle a data access request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€15,000
02 Jan 2023Dulnevnd fyritøka (Dátueftirlitið)DATFO referred a company to the police for suspected breaches of data protection law. The company collected and stored personal data without a valid legal basis and without providing adequate information to the data subjects. Its website contact mechanism also caused data intended for a specific provider to be collected and retained by the company.FODATFOGDPR€13,446
03 Jan 2023QUALITY-PROVIDER, S.A.QUALITY-PROVIDER, S.A. was fined by the AEPD in the amount of 30,000 EUR for processing personal data without consent. The data were then shared with third parties, who used them to contact the complainant via a personal social network.ESAEPDGDPR€30,000
03 Jan 2023Asociație de proprietari din IașiA homeowners' association in Iași was fined 500 EUR by ANSPDCP for GDPR violations. The case concerned failure to comply with personal data protection requirements as a controller.ROANSPDCPGDPR€500
04 Jan 2023Apă Canal Ilfov SAThe company was fined EUR 3,000 by ANSPDCP for a data security breach. User information was exposed because email addresses were entered in the “To” field instead of “BCC”.ROANSPDCPGDPR€3,000
09 Jan 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR after a SIM swapping incident enabled unauthorized bank transactions. The authority found a breach of Article 6(1) of the GDPR.ESAEPDGDPR€200,000
09 Jan 2023NANDIVALE, S.L.NANDIVALE, S.L. was fined by the AEPD EUR 10,000 for publishing images of minors on Instagram without parental consent. The authority found this conduct to be in breach of GDPR Article 6(1).ESAEPDGDPR€10,000
10 Jan 2023POSADA DE LLERENA, S.L.POSADA DE LLERENA, S.L. was fined 2,000 EUR by the AEPD for requesting excessive personal data from customers, including copies of ID documents, as a condition for accommodation. The authority found this practice breached the GDPR data minimization principle.ESAEPDGDPR€2,000
11 Jan 2023Azienda Sanitaria Locale di BrindisiAzienda Sanitaria Locale di Brindisi was fined by the Garante 2,500 EUR for failing to respond to a data access request. The authority found a breach of GDPR Article 15.ITGaranteGDPR€2,500
11 Jan 2023Associazione Nazionale MagistratiAssociazione Nazionale Magistrati was fined by the Garante for improper handling of personal data. An official email address was used instead of a personal one to notify a disciplinary proceeding, which breached confidentiality requirements.ITGaranteGDPR€5,000
11 Jan 2023Commify Italia S.r.l.Commify Italia S.r.l. was fined by the Garante 80,000 EUR for violations related to the processing of personal data through its Skebby platform. The case involved inadequate data protection measures and unauthorized access that led to phishing attacks.ITGaranteGDPR€80,000
11 Jan 2023AXEL SPRINGER ESPAÑA S.AAXEL SPRINGER ESPAÑA S.A was fined 5,000 EUR by the AEPD for non-compliance with data protection rules in its cookie policy. The website required users to disable providers individually and did not offer an option to disable all cookies at once.ESAEPDePrivacy€5,000
11 Jan 2023BBVABBVA was fined by the AEPD EUR 1,640,000 for multiple data protection violations. The case involved unauthorized payment operations and improper handling of personal data in credit information systems.ESAEPDGDPR€1,640,000