Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2024COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company was fined EUR 80,000 by the AEPD for processing a gas contract without the complainant's consent. It used personal data without authorization, which constitutes a breach of data protection law.ESAEPDGDPR€80,000
01 Jan 2024XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD for failing to ensure the security and confidentiality of personal data. The incident resulted in a data breach and created a risk of identity theft.ESAEPDGDPR€4,000,000
01 Jan 2024FLEXICAR IBÉRICA, S.L.FLEXICAR IBÉRICA, S.L. was fined €50,000 by the AEPD for a personal data breach. The incident occurred when information belonging to other clients was mistakenly shared via WhatsApp.ESAEPDGDPR€50,000
01 Jan 2024a small recruitment bureauA small recruitment bureau in the Netherlands was fined EUR 6,000 by the Autoriteit Persoonsgegevens for failing to respond on time to an ex-candidate’s request to delete personal data. The Raad van State upheld the fine in case ECLI:NL:RVS:2024:2221.NLAutoriteit PersoonsgegevensGDPR€6,000
01 Jan 2024FRUTAS CALISA, S.L.FRUTAS CALISA, S.L. was fined 300 EUR by the AEPD for contacting an individual via WhatsApp without prior consent. The authority found this conduct to be a breach of Article 6(1) GDPR.ESAEPDGDPR€300
01 Jan 2024EXCEL HOTELS & RESORTS, S.A.EXCEL HOTELS & RESORTS, S.A. was fined by the AEPD 40,000 EUR for leaving property owners’ personal data unattended, including ID and passport numbers. The authority found that this created unauthorized access to sensitive personal information and breached data protection principles.ESAEPDGDPR€40,000
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 130,000 EUR for unauthorized SIM card duplication. The incident led to identity theft and fraudulent charges, and the authority found the data protection measures insufficient.ESAEPDGDPR€130,000
01 Jan 2024EDP SOLAR ESPAÑA, S.A.EDP SOLAR ESPAÑA, S.A. was fined by the AEPD for failing to meet data protection obligations. The breach concerned Article 5(1)(c) of the GDPR, which requires data minimization.ESAEPDGDPR€70,000
01 Jan 2024EDA TV CONSULTING S.L.EDA TV CONSULTING S.L. was fined 5,000 EUR by the AEPD for publishing a minor’s image without consent. The case concerns a breach of data protection rules and the child’s privacy rights.ESAEPDGDPR€5,000
01 Jan 2024ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓNThe entity was fined €4,000 by the AEPD for processing personal data without a lawful basis and for failing to inform the data subject. The authority found breaches of Articles 6 and 14 of the GDPR.ESAEPDGDPR€4,000
01 Jan 2024Santander BankIn 2024, Santander Bank was fined 1,440,000 PLN by UODO. The sanction concerned the failure to report a personal data breach, which is a significant breach of GDPR obligations.PLUrząd Ochrony Danych OsobowychGDPR€331,000
01 Jan 2024REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS S.L.U.REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS S.L.U. was fined by the AEPD for processing personal data without consent, which led to unauthorized access to a customer's data. The authority also found inadequate security measures.ESAEPDGDPR€1,380,000
01 Jan 2024Unnamed data controllerNAIH imposed a HUF 50 million fine on an unnamed public body for failing to provide data to the Central Public Information Register. The case concerned non-publication of financial data required by law.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€130,000
02 Jan 2024FEDERACIÓN DE SERVICIOS PÚBLICOS DE LA UGT (FSP-UGT)The entity sent emails that disclosed personal data of multiple recipients. The AEPD found a breach of the confidentiality principle under Article 5(1)(f) GDPR.ESAEPDGDPR€5,000
04 Jan 2024N*** -FußballvereinigungThe football association failed to implement appropriate technical and organizational measures for handling data deletion requests. The authority found breaches of Articles 25 and 17 GDPR and imposed a fine of EUR 11,000.ATDSBGDPR€11,000
05 Jan 2024B.B.B.The entity was fined for publishing personal images and phone numbers on Telegram channels without the data subjects’ consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€10,000
08 Jan 2024VUKMAL TRADE, S.L.VUKMAL TRADE, S.L. was fined by the AEPD €2,000 for requiring an employee to use a personal mobile phone for work purposes without consent. The company also shared the employee’s personal number with other staff, breaching data protection principles.ESAEPDGDPR€2,000
08 Jan 2024GESTIÓN DE PATRIMONIOS ANFIPOLIS SL.The entity sent unsolicited commercial emails to an individual registered on the Robinson List. This breached Article 21 of the LSSI and led to a fine imposed by the AEPD.ESAEPDePrivacy€2,000
08 Jan 2024INVERTIA TENERIFE 2019, S.L.INVERTIA TENERIFE 2019, S.L. was fined 1,000 EUR by the AEPD for failing to meet its information obligations toward data subjects. The authority found that the required information under Article 13 GDPR was not provided.ESAEPDGDPR€1,000
09 Jan 2024EDITEUR DE SITE WEB - ANNUAIRE INVERSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 1,500 on EDITEUR DE SITE WEB - ANNUAIRE INVERSE under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision.FRCNILGDPR€1,500