Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Feb 2022VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined EUR 70,000 by the AEPD for issuing a duplicate SIM card to a third party without the customer's consent. This enabled unauthorized access to the customer's bank account.ESAEPDGDPR€70,000
02 Nov 2010VODAFONE ESPAÑA, S.A.Vodafone España, S.A. was fined 600 EUR by the AEPD for sending commercial communications to a complainant who had previously opted out. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€600
14 Mar 2011VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD in the amount of 1,800 EUR for sending unsolicited commercial communications via SMS. The conduct breached Article 21.1 of the LSSI, which prohibits such messages without prior consent.ESAEPDePrivacy€1,800
06 Apr 2011VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD 30,001 EUR for continuing to send commercial emails and SMS messages to a complainant. The conduct continued despite requests to stop and objections to the processing of personal data for advertising purposes.ESAEPDePrivacy€30,001
02 Nov 2010VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial communications in breach of Article 21 of the LSSI. The infringement was classified as serious because a technical error resulted in 18 such messages being sent.ESAEPDePrivacy€30,001
16 Sept 2010VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD 30,001 EUR for sending advertising messages to a customer who had previously opted out. The authority found this breached Article 21 of the LSSI on marketing communications without the recipient’s consent.ESAEPDePrivacy€30,001
04 Aug 2017VodafoneVodafone was fined 5,000 EUR by the HDPA for failing to satisfy the complainant’s request to access their personal data. The case concerns a breach of the data subject’s access rights under the controller’s obligations.GRHDPAGDPR€5,000
03 Jun 2025VodafoneVodafone was fined EUR 45 million by Germany’s federal data protection authority for GDPR-related privacy violations. The case involved weaknesses in authentication and partner oversight that could allow unauthorized access to customer data and eSIM profiles.DEBundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)GDPR€45,000,000
04 Aug 2017VodafoneThe HDPA imposed a €10,000 fine on Vodafone for unlawfully processing the complainant's credit card data without consent. The case concerns a breach of the legal basis requirements for personal data processing.GRHDPAGDPR€10,000
20 Feb 2026VodafoneThe Greek Data Protection Authority fined Vodafone EUR 30,000 for GDPR breaches related to a subscriber’s request to access recorded phone conversations. The authority found violations of transparency obligations under Article 12 and of the rights of access and restriction of processing under Articles 15 and 18 GDPR.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€30,000
04 Feb 2025V&M Contab&Management SRLANSPDCP imposed a fine of EUR 2,000 on V&M Contab&Management SRL for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
04 Feb 2025V&M Contab&Management SRLANSPDCP imposed a fine of EUR 8,000 on V&M Contab&Management SRL for GDPR violations. The case concerns non-compliance with personal data protection requirements, creating regulatory risk for the controller.ROANSPDCPGDPR€8,000
21 Jul 2025VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 3,000 EUR for failing to implement appropriate technical and organizational measures to secure personal data. The deficiency resulted in unauthorized disclosure of personal data.GRHDPAGDPR€3,000
21 Jul 2025VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 4,000 EUR for failing to notify the data breach to the supervisory authority and the affected data subjects in a timely manner. The case indicates non-compliance with the statutory notification deadlines following a security incident.GRHDPAGDPR€4,000
21 Jul 2025VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA in the amount of €2,000 for failing to build data protection into the design of its processing and for not applying privacy by default. The authority treated this as a breach of GDPR requirements on privacy by design and by default.GRHDPAGDPR€2,000
11 Feb 2016Vito Roma s.r.l.Vito Roma s.r.l. was fined by the Garante for operating a video surveillance system without providing the required data protection notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
13 Jun 2013Vito GiacoiaVito Giacoia was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned the failure to provide the required privacy notice for a video surveillance system at the “Fratelli Venaria” club, in breach of the Italian Privacy Code.ITGaranteGDPR€2,400
12 Feb 2015Visini FabioVisini Fabio was fined EUR 12,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection requirements.ITGaranteGDPR€12,000
20 Dec 2022Virtue Integrated Elder Care LtdThe Irish DPC imposed a fine of EUR 100,000 on Virtue Integrated Elder Care Ltd in inquiry IN-21-2-5. The penalty has been collected.IEDPCGDPR€100,000
10 Apr 2013VIRTUALIZZA S.L.VIRTUALIZZA S.L. was fined EUR 600 by the AEPD for sending unsolicited commercial emails without proper consent. The authority also found that the company failed to provide an effective opt-out mechanism, in breach of Article 21 of the LSSI.ESAEPDePrivacy€600