Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 May 2022DIGITECNIA SOLUTIONS, S.L.DIGITECNIA SOLUTIONS, S.L. was fined by the AEPD 2,000 EUR for publishing an image on its website without authorization. The authority found this to be a breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
22 Jun 2023Digi Távközlési és Szolgáltató Kft.Digi Távközlési és Szolgáltató Kft. was fined by the NAIH for failing to delete a test database containing personal data after the tests were completed. The authority found a breach of storage limitation and data security obligations.HUNAIHGDPR€216,000
18 May 2020Digi Távközlési és Szolgáltató Kft.Digi Távközlési és Szolgáltató Kft. was fined by the NAIH 100,000,000 HUF for failing to delete a test database containing personal data after its intended use. The authority also found inadequate security measures, which led to unauthorized access to personal data.HUNAIHGDPR€283,000
26 Sept 2012DIGITARAN, S.L.U.DIGITARAN, S.L.U. was fined by the AEPD 3,000 EUR for sending unsolicited advertising SMS messages to a user registered on the Robinson List. The conduct breached Article 21 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€3,000
13 Sept 2024DIGITAL PHOTO IMAGE, S.A.DIGITAL PHOTO IMAGE, S.A. was fined EUR 20,000 by the AEPD for breaching the LSSI. The company sent emails without providing recipients with a valid means to exercise their right to stop receiving such communications.ESAEPDePrivacy€20,000
11 Jun 2024DIGITAL FLOW, S.L.DIGITAL FLOW, S.L. was fined EUR 2,000 by the AEPD for sending emails without an unsubscribe option. The authority also found that the company failed to provide a valid contact for exercising data deletion rights.ESAEPDePrivacy€2,000
18 Apr 2013Digital Design di Patron AndreaDigital Design di Patron Andrea was fined 2,400 EUR by the Garante. The authority found that the website's contact form lacked the required data protection information, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
25 Feb 2022DIGITAL CONTENT DISTRIBUTION LTD.DIGITAL CONTENT DISTRIBUTION LTD. was fined by the AEPD EUR 100 for sending marketing emails without the recipient's consent. The conduct breached Article 21 of the LSSI on electronic commercial communications.ESAEPDePrivacy€100
29 Apr 2026DIGI SPAIN TELECOM, S.L.U.DIGI SPAIN TELECOM, S.L.U. was fined by the AEPD 140,000 EUR for processing personal data without a legal basis. The case concerned a SIM card duplication incident that resulted in unauthorized data processing.ESAEPDGDPR€140,000
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the original user's consent. The incident led to unauthorized access to personal and banking data.ESAEPDGDPR€200,000
19 Mar 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for failing to verify the identity of a person who obtained a SIM duplicate. This omission led to unauthorized transactions and was treated as a breach of Article 6(1) GDPR.ESAEPDGDPR€200,000
05 May 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD EUR 70,000 for a data protection breach involving unauthorized SIM card duplication. The incident led to unauthorized bank transfers from the complainant's account.ESAEPDGDPR€70,000
07 Mar 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for improperly handling a SIM card duplication request. The failure led to unauthorized transactions on a customer's bank account and was found to breach Article 6(1) GDPR.ESAEPDGDPR€70,000
03 Feb 2022DIGI SPAIN TELECOM, S.L.DIGI Spain Telecom, S.L. was fined by the AEPD in the amount of EUR 70,000 for a breach of Article 6(1) GDPR. The case concerned the unauthorized duplication of a SIM card in an identity theft incident, which resulted in financial losses for the complainant.ESAEPDGDPR€70,000
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 120,000 EUR for a data protection breach involving unauthorized SIM card duplication. The incident enabled fraudulent activity, and the authority found that the company had not implemented sufficient preventive measures.ESAEPDGDPR€120,000
01 Jan 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for processing personal data without consent. The breach led to unauthorized access to personal data and fraudulent financial transactions.ESAEPDGDPR€70,000
07 Mar 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card to a third party without proper identity verification. The incident enabled unauthorized access to a bank account and resulted in financial loss.ESAEPDGDPR€70,000
04 May 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a SIM card duplicate without verifying the requester’s identity. The failure enabled unauthorized access to a bank account and caused financial loss to the complainant.ESAEPDGDPR€70,000
11 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD EUR 150,000 for processing personal data without proper authorization. The case involved a fraudulent contract created using the complainant’s identity, and the authority found that the company did not adequately verify the identity of the person entering into the contract.ESAEPDGDPR€150,000
02 Feb 2023DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card without the complainant's consent. The incident led to attempts to gain unauthorized access to the complainant's bank accounts.ESAEPDGDPR€70,000