BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2023 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 200,000 by the AEPD for issuing a duplicate SIM card to a third party without the complainant's consent. The incident enabled unauthorized access to personal and banking data, indicating a serious data protection failure. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2023 | QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined 20,000 EUR by the AEPD for unlawfully obtaining personal data from a website. The data was then used for promotional purposes without the consent of the data subjects. | ES | AEPD | GDPR | €20,000 | ↗ |
| 01 Jan 2023 | CLUB VOLEIBOL ***CLUB.1The club was fined by the AEPD in the amount of EUR 500 for publishing minors' images without proper consent. The authority also found that the club failed to provide access to personal data requested by a parent. | ES | AEPD | GDPR | €500 | ↗ |
| 01 Jan 2023 | LOCAL VERTICALS, S.L.The company was fined by the AEPD in the amount of 10,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2023 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 100,000 EUR for allowing a third party to impersonate a customer. This led to a mobile line portability request and the purchase of a mobile device without the customer’s consent. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Jan 2023 | NATURGY IBERIA, S.A.Naturgy Iberia was fined for changing a customer's gas and electricity supplier without authorization. The authority found that this breached Article 6(1) of the GDPR because there was no lawful basis for the processing. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Jan 2023 | GENERAL LOGISTICS SYSTEMS SPAIN, S.A.GENERAL LOGISTICS SYSTEMS SPAIN, S.A. was fined by the AEPD 140,000 EUR for processing the personal data of two complainants without proper authorization. The breach resulted in identity theft and misuse of personal data. | ES | AEPD | GDPR | €140,000 | ↗ |
| 01 Jan 2023 | GLOVOGLOVO was fined EUR 15,000 by the AEPD for failing to properly handle a data access request. The authority found a breach of Article 15 of the GDPR. | ES | AEPD | GDPR | €15,000 | ↗ |
| 02 Jan 2023 | Dulnevnd fyritøka (Dátueftirlitið)DATFO referred a company to the police for suspected breaches of data protection law. The company collected and stored personal data without a valid legal basis and without providing adequate information to the data subjects. Its website contact mechanism also caused data intended for a specific provider to be collected and retained by the company. | FO | DATFO | GDPR | €13,446 | ↗ |
| 03 Jan 2023 | QUALITY-PROVIDER, S.A.QUALITY-PROVIDER, S.A. was fined by the AEPD in the amount of 30,000 EUR for processing personal data without consent. The data were then shared with third parties, who used them to contact the complainant via a personal social network. | ES | AEPD | GDPR | €30,000 | ↗ |
| 03 Jan 2023 | Asociație de proprietari din IașiA homeowners' association in Iași was fined 500 EUR by ANSPDCP for GDPR violations. The case concerned failure to comply with personal data protection requirements as a controller. | RO | ANSPDCP | GDPR | €500 | ↗ |
| 04 Jan 2023 | Apă Canal Ilfov SAThe company was fined EUR 3,000 by ANSPDCP for a data security breach. User information was exposed because email addresses were entered in the “To” field instead of “BCC”. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 09 Jan 2023 | TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR after a SIM swapping incident enabled unauthorized bank transactions. The authority found a breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 09 Jan 2023 | NANDIVALE, S.L.NANDIVALE, S.L. was fined by the AEPD EUR 10,000 for publishing images of minors on Instagram without parental consent. The authority found this conduct to be in breach of GDPR Article 6(1). | ES | AEPD | GDPR | €10,000 | ↗ |
| 10 Jan 2023 | POSADA DE LLERENA, S.L.POSADA DE LLERENA, S.L. was fined 2,000 EUR by the AEPD for requesting excessive personal data from customers, including copies of ID documents, as a condition for accommodation. The authority found this practice breached the GDPR data minimization principle. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Jan 2023 | Azienda Sanitaria Locale di BrindisiAzienda Sanitaria Locale di Brindisi was fined by the Garante 2,500 EUR for failing to respond to a data access request. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €2,500 | ↗ |
| 11 Jan 2023 | Associazione Nazionale MagistratiAssociazione Nazionale Magistrati was fined by the Garante for improper handling of personal data. An official email address was used instead of a personal one to notify a disciplinary proceeding, which breached confidentiality requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 Jan 2023 | Commify Italia S.r.l.Commify Italia S.r.l. was fined by the Garante 80,000 EUR for violations related to the processing of personal data through its Skebby platform. The case involved inadequate data protection measures and unauthorized access that led to phishing attacks. | IT | Garante | GDPR | €80,000 | ↗ |
| 11 Jan 2023 | AXEL SPRINGER ESPAÑA S.AAXEL SPRINGER ESPAÑA S.A was fined 5,000 EUR by the AEPD for non-compliance with data protection rules in its cookie policy. The website required users to disable providers individually and did not offer an option to disable all cookies at once. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 11 Jan 2023 | BBVABBVA was fined by the AEPD EUR 1,640,000 for multiple data protection violations. The case involved unauthorized payment operations and improper handling of personal data in credit information systems. | ES | AEPD | GDPR | €1,640,000 | ↗ |