Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2019XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 60,000 by the AEPD for processing personal data without a legal basis. The authority found a breach of Article 6 GDPR, meaning the processing lacked a lawful basis.ESAEPDGDPR€60,000
14 Jun 2018Anonymizováno (ÚOOÚ UOOU-00051/18-14)The entity was fined for processing the personal data of apartment building residents through a camera system without their consent. The authority found this to be a breach of Czech data protection law.CZUOOUGDPR€2,339
25 Jul 2019VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined by the AEPD 60,000 EUR for failing to ensure adequate security of personal data. The breach resulted in unauthorized or unlawful processing, indicating deficiencies in security controls.ESAEPDGDPR€60,000
17 Oct 2024Serfin 97 S.r.l.Serfin 97 S.r.l. was fined EUR 60,000 by the Garante for unlawful processing of personal data. The company used a third party’s email address to contact a debtor for debt recovery purposes, which breached data protection rules.ITGaranteGDPR€60,000
24 Jan 2013Casa di cura Abano TermeCasa di cura Abano Terme was fined EUR 60,000 by the Garante for processing personal data without complying with the legal requirements and limits. The authority found a breach of Article 26 of the Italian Privacy Code.ITGaranteGDPR€60,000
04 Nov 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD after a contract was entered into using another person's identity. The case concerns a breach of data protection rules and insufficient identity verification.ESAEPDGDPR€60,000
17 May 2023Anonymizováno (ÚOOÚ UOOU-03562/22-14)The entity was fined for repeatedly sending commercial communications without prior consent from recipients. The messages were not clearly marked as advertising, did not identify the sender, and did not provide a valid address for opting out.CZUOOUePrivacy€2,539
17 Sept 2020Scanshare s.r.l.Scanshare s.r.l. was fined by the Garante 60,000 EUR for inadequate technical and organizational measures in handling candidate data during a hospital recruitment process. The authority also found a breach of GDPR Article 13 because the required information was not provided to candidates.ITGaranteGDPR€60,000
28 Jun 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 60,000 EUR by the AEPD for a data protection breach. Personal data of a third party was accessible through its mobile application, and the issue was not resolved promptly after it was reported.ESAEPDGDPR€60,000
21 Feb 2013American Express Services Europe LimitedAmerican Express Services Europe Limited was fined EUR 60,000 by the Garante. The authority found that the security program document was not updated in line with the technical rules on minimum security measures.ITGaranteGDPR€60,000
01 Jan 2019XFERA MÓVILES S.A.XFERA MÓVILES S.A. was fined 60,000 EUR by the AEPD for processing personal data without consent. As a result, unauthorized contracts were sent to a customer, indicating improper use of personal data.ESAEPDGDPR€60,000
11 Feb 2021Roma Servizi per La Mobilita S.r.l.Roma Servizi per La Mobilita S.r.l. was fined EUR 60,000 by the Garante for inadequate security measures. The weakness led to unauthorized access to personal data related to ZTL permits.ITGaranteGDPR€60,000
30 Nov 2023Limit Call S.r.l.s.Limit Call S.r.l.s. was fined by the Italian supervisory authority, Garante, in the amount of €60,000. The case concerned a failure to respond to an information request linked to unsolicited phone calls made without consent, which breached data protection rules.ITGaranteGDPR€60,000
12 Apr 2024DATACENTRICDATACENTRIC was fined by the AEPD 60,000 EUR for processing personal data of self-employed individuals without a valid legal basis. The data was also exposed online and used for marketing purposes, breaching GDPR Articles 6(1) and 14.ESAEPDGDPR€60,000
01 Jan 2019GESTIÓN DE COBROS, YO COBRO SLThe company was fined EUR 60,000 by the AEPD for unlawfully processing personal data. The breach involved sending debt collection emails to an institutional email address without consent, in violation of data protection rules.ESAEPDGDPR€60,000
01 Apr 2019VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD EUR 60,000 for sending a marketing email that exposed the email addresses and names of more than eighty recipients. The authority found this breached the principles of data integrity and confidentiality.ESAEPDGDPR€60,000
16 Feb 2017Momax s.r.l.Momax s.r.l. was fined by the Garante for improper handling of telephone traffic data. The authority found failures to implement appropriate safeguards, including strong authentication and biometric recognition measures, and retention of data beyond the permitted period for billing and crime prevention purposes.ITGaranteGDPR€60,000
04 Jun 2020PRA IBERIA, S.L.PRA IBERIA, S.L. was fined by the AEPD 60,000 EUR for unlawful processing of personal data and for failing to provide access to personal data information. The breaches concerned Articles 6(1) and 15 of the GDPR.ESAEPDGDPR€60,000
04 Feb 2020VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 60,000 EUR for a data protection violation. The case involved unauthorized data processing and signature forgery by an employee, which led to a fraudulent service transfer.ESAEPDGDPR€60,000
08 Jun 2020G.L.P. Instalaciones 86, S.L.G.L.P. Instalaciones 86, S.L. was fined by the AEPD EUR 60,000 for processing personal data without a legal basis. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€60,000