BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Feb 2022 | VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined EUR 70,000 by the AEPD for issuing a duplicate SIM card to a third party without the customer's consent. This enabled unauthorized access to the customer's bank account. | ES | AEPD | GDPR | €70,000 | ↗ |
| 02 Nov 2010 | VODAFONE ESPAÑA, S.A.Vodafone España, S.A. was fined 600 EUR by the AEPD for sending commercial communications to a complainant who had previously opted out. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 14 Mar 2011 | VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD in the amount of 1,800 EUR for sending unsolicited commercial communications via SMS. The conduct breached Article 21.1 of the LSSI, which prohibits such messages without prior consent. | ES | AEPD | ePrivacy | €1,800 | ↗ |
| 06 Apr 2011 | VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD 30,001 EUR for continuing to send commercial emails and SMS messages to a complainant. The conduct continued despite requests to stop and objections to the processing of personal data for advertising purposes. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 02 Nov 2010 | VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial communications in breach of Article 21 of the LSSI. The infringement was classified as serious because a technical error resulted in 18 such messages being sent. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 16 Sept 2010 | VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD 30,001 EUR for sending advertising messages to a customer who had previously opted out. The authority found this breached Article 21 of the LSSI on marketing communications without the recipient’s consent. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 04 Aug 2017 | VodafoneVodafone was fined 5,000 EUR by the HDPA for failing to satisfy the complainant’s request to access their personal data. The case concerns a breach of the data subject’s access rights under the controller’s obligations. | GR | HDPA | GDPR | €5,000 | ↗ |
| 03 Jun 2025 | VodafoneVodafone was fined EUR 45 million by Germany’s federal data protection authority for GDPR-related privacy violations. The case involved weaknesses in authentication and partner oversight that could allow unauthorized access to customer data and eSIM profiles. | DE | Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) | GDPR | €45,000,000 | ↗ |
| 04 Aug 2017 | VodafoneThe HDPA imposed a €10,000 fine on Vodafone for unlawfully processing the complainant's credit card data without consent. The case concerns a breach of the legal basis requirements for personal data processing. | GR | HDPA | GDPR | €10,000 | ↗ |
| 20 Feb 2026 | VodafoneThe Greek Data Protection Authority fined Vodafone EUR 30,000 for GDPR breaches related to a subscriber’s request to access recorded phone conversations. The authority found violations of transparency obligations under Article 12 and of the rights of access and restriction of processing under Articles 15 and 18 GDPR. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €30,000 | ↗ |
| 04 Feb 2025 | V&M Contab&Management SRLANSPDCP imposed a fine of EUR 2,000 on V&M Contab&Management SRL for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 04 Feb 2025 | V&M Contab&Management SRLANSPDCP imposed a fine of EUR 8,000 on V&M Contab&Management SRL for GDPR violations. The case concerns non-compliance with personal data protection requirements, creating regulatory risk for the controller. | RO | ANSPDCP | GDPR | €8,000 | ↗ |
| 21 Jul 2025 | VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 3,000 EUR for failing to implement appropriate technical and organizational measures to secure personal data. The deficiency resulted in unauthorized disclosure of personal data. | GR | HDPA | GDPR | €3,000 | ↗ |
| 21 Jul 2025 | VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 4,000 EUR for failing to notify the data breach to the supervisory authority and the affected data subjects in a timely manner. The case indicates non-compliance with the statutory notification deadlines following a security incident. | GR | HDPA | GDPR | €4,000 | ↗ |
| 21 Jul 2025 | VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA in the amount of €2,000 for failing to build data protection into the design of its processing and for not applying privacy by default. The authority treated this as a breach of GDPR requirements on privacy by design and by default. | GR | HDPA | GDPR | €2,000 | ↗ |
| 11 Feb 2016 | Vito Roma s.r.l.Vito Roma s.r.l. was fined by the Garante for operating a video surveillance system without providing the required data protection notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 13 Jun 2013 | Vito GiacoiaVito Giacoia was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned the failure to provide the required privacy notice for a video surveillance system at the “Fratelli Venaria” club, in breach of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Feb 2015 | Visini FabioVisini Fabio was fined EUR 12,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection requirements. | IT | Garante | GDPR | €12,000 | ↗ |
| 20 Dec 2022 | Virtue Integrated Elder Care LtdThe Irish DPC imposed a fine of EUR 100,000 on Virtue Integrated Elder Care Ltd in inquiry IN-21-2-5. The penalty has been collected. | IE | DPC | GDPR | €100,000 | ↗ |
| 10 Apr 2013 | VIRTUALIZZA S.L.VIRTUALIZZA S.L. was fined EUR 600 by the AEPD for sending unsolicited commercial emails without proper consent. The authority also found that the company failed to provide an effective opt-out mechanism, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |