Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Jun 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined EUR 70,000 by the AEPD for a SIM card duplication incident. The incident enabled unauthorized attempts to access the complainant's bank accounts and was treated as a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
10 Mar 2023DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the customer's consent. The action enabled unauthorized bank transactions, indicating a serious breach of data protection and authentication security.ESAEPDGDPR€200,000
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 130,000 EUR for unauthorized SIM card duplication. The incident led to identity theft and fraudulent charges, and the authority found the data protection measures insufficient.ESAEPDGDPR€130,000
01 Jan 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for unlawfully duplicating a customer's SIM card without consent. The incident led to unauthorized access to the customer's personal and banking data.ESAEPDGDPR€70,000
09 Jan 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card without proper authorization. The incident enabled unauthorized access to a customer's bank account.ESAEPDGDPR€70,000
13 Feb 2024DIGIMAN ALICANTE, S.L.DIGIMAN ALICANTE, S.L. was fined by the AEPD 1,000 EUR for operating a video surveillance system without the required signage. The authority found that the lack of notice breached the information obligations under GDPR Article 13.ESAEPDGDPR€1,000
14 Mar 2023DIGIMAN ALICANTE, S.L.DIGIMAN ALICANTE, S.L. was fined 2,000 EUR by the AEPD for failing to remove an ex-employee’s image from its YouTube channel despite repeated requests. The authority found a breach of GDPR Article 6(1) regarding the lawful basis for processing personal data.ESAEPDGDPR€2,000
21 Feb 2024DIBEA ESTETIC, S.L.DIBEA ESTETIC, S.L. was fined EUR 7,000 by the AEPD for transferring personal data without the data subject’s consent. The authority found this conduct to be contrary to Article 6(1) of the GDPR.ESAEPDGDPR€7,000
04 Dec 2025DIARIO DE PRENSA DIGITAL, S.L.DIARIO DE PRENSA DIGITAL, S.L. was fined by the AEPD 5,000 EUR for placing tracking and advertising cookies on its website without prior user consent. The authority found this to be a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
27 Apr 2022DIARIO ABC, S.L.DIARIO ABC, S.L. was fined 50,000 EUR by the AEPD for publishing audio of a victim's testimony in a high-profile court case. The authority found that the publication could identify the victim and therefore breached data protection rules.ESAEPDGDPR€50,000
04 Oct 2024DIAMOND FERVA, S.L.DIAMOND FERVA, S.L. was fined by the AEPD 1,000 EUR for installing a surveillance camera without properly informing data subjects and without the required authorization. The authority treated this as a breach of the information obligations under GDPR Article 13.ESAEPDGDPR€1,000
19 Feb 2024DHL PARCEL IBERIA, S.L.U.DHL Parcel Iberia, S.L.U. was fined by the AEPD 5,000 EUR for failing to implement appropriate technical and organizational measures to ensure security appropriate to the risk, as required by Article 32 GDPR. As a result, personal data, including phone numbers, were exposed on shipping labels.ESAEPDGDPR€5,000
16 Aug 2024D*** Handels Ges.m.b.H.D*** Handels Ges.m.b.H. was fined by the DSB for unlawfully processing personal data through a video surveillance system without a legal basis. The authority also found a breach of the data minimization principle.ATDSBGDPR€1,500,000
16 Oct 2024D**** GmbHThe company appointed its managing director as the data protection officer, creating a conflict of interest. The DSB found this breached Article 38(6) GDPR and imposed a fine of EUR 5,000.ATDSBGDPR€5,000
12 Dec 2024DEUX SOCIETES EXERCANT DES ACTIVITES D'AGENCES DE PRESSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on DEUX SOCIETES EXERCANT DES ACTIVITES D'AGENCES DE PRESSE. Available information indicates a simplified procedure and two fines of EUR 5,000 each.FRCNILGDPR€5,000
16 Jun 2022Deutsche Bank S.p.A.Deutsche Bank S.p.A. was fined EUR 20,000 by the Garante for unlawfully processing personal data. The bank reported an individual's name to CRIF S.p.A. without prior notice, which breached data protection rules.ITGaranteGDPR€20,000
09 Jan 2024Det Kongelige TeaterThe Danish DPA reported Det Kongelige Teater to the police and recommended a fine of 250,000 DKK. The case concerned the absence of deletion rules for customer data used for marketing, affecting about 520,000 individuals.DKDatatilsynetGDPR€33,523
30 Jan 2026deținătorul site-ului evita-teparii.roANSPDCP imposed total fines of 51,000 lei, about 10,000 euro, on the operator, a natural person who runs the site evita-teparii.ro. The case involved multiple GDPR breaches, including the unlawful publication of identity, contact, sensitive, and alleged criminal data without a legal basis.ROANSPDCPGDPR€10,007
11 Jan 2024DESPACHO TORRENTE, S.L.P.DESPACHO TORRENTE, S.L.P. was fined by the AEPD 10,000 EUR for improperly disclosing personal data, including sensitive information, in a letter concerning damage at public facilities. The authority found a breach of data protection principles.ESAEPDGDPR€10,000
18 Jun 2021DESPACHO TEJEDOR INFANTES CONSULTORES ASESORES, S.L.The entity unlawfully disclosed personal data to a third party, breaching the confidentiality principle under GDPR. The AEPD imposed a fine of 2,000 EUR.ESAEPDGDPR€2,000