Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Jan 2026MEDIOS DE PREVENCIÓN EXTERNOS SUR, S.L.The company suffered a ransomware attack that caused a breach of the confidentiality and availability of personal data. AEPD found a violation of Article 5(1)(f) GDPR.ESAEPDGDPR€60,000
25 Jul 2019VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined EUR 60,000 by the AEPD for a security breach in its customer portal. The incident allowed unauthorized access to a third party's personal data, indicating insufficient access controls.ESAEPDGDPR€60,000
21 Oct 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 60,000 for processing personal data without proper consent. The case involved a customer receiving a notification of a purchase they had not made, indicating improper use of personal data.ESAEPDGDPR€60,000
01 Mar 2018Yahoo! Italia s.r.l.Yahoo! Italia s.r.l. was fined by the Garante in the amount of 60,000 EUR. The company failed to comply with a request to remove certain URLs containing personal information from its search engine and did not provide information on the implementation of that request.ITGaranteGDPR€60,000
07 Jul 2022Głównego Geodetę Kraju z siedzibą w Warszawie, przy ul.UODO imposed a PLN 60,000 administrative fine on the Chief Geodesist of Poland. The authority found that the personal data breach was not reported to the supervisory authority without undue delay and that affected individuals were not notified.PLUODOGDPR€12,573
05 Oct 2023DPP Law LtdThe Information Commissioner's Office issued a monetary penalty notice against DPP Law Ltd. The firm was fined GBP 60,000 for failing to implement appropriate technical and organisational measures to secure personal data.GBInformation Commissioner's OfficeGDPR€69,282
10 Feb 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD for processing personal data without valid consent. The case concerned a debt claim made against an individual for a contract they had not entered into.ESAEPDGDPR€60,000
09 Jul 2025REAL SOCIEDAD DE FUTBOL S.A.D.REAL SOCIEDAD DE FUTBOL S.A.D. suffered a ransomware attack that led to a data breach affecting 60,000 individuals, including biometric, identification, financial, and health data. The AEPD fined the company for failing to implement adequate technical and organizational measures to protect data security.ESAEPDGDPR€60,000
06 Mar 2020BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for inaccurate processing of personal data. The bank demanded payment for a debt the complainant did not owe and shared the complainant’s personal data with a debt collection agency.ESAEPDGDPR€60,000
12 Jun 2014Istituto Poligrafico e Zecca dello Stato S.p.AIstituto Poligrafico e Zecca dello Stato S.p.A was fined EUR 60,000 by the Garante. The authority found that the company did not fully implement required security measures, in particular the logging of system administrator access to electronic archives.ITGaranteGDPR€60,000
05 Nov 2015Enterprise Service s.r.l.Enterprise Service s.r.l. was fined EUR 62,000 by the Garante. The sanction concerned sending unsolicited promotional faxes without prior consent, in breach of privacy rules.ITGaranteGDPR€62,000
22 Jun 2017Bookingshow s.p.a.Bookingshow s.p.a. was fined EUR 62,000 by the Garante for unlawfully processing personal data. The company required mandatory consent for promotional purposes during online ticket purchases, which breached data processing rules.ITGaranteGDPR€62,000
28 May 2015Xpedite Systems s.r.l.Xpedite Systems s.r.l. was fined 64,000 EUR by the Garante for sending unsolicited promotional faxes without the required notice and consent. The authority found this to be a breach of privacy rules.ITGaranteGDPR€64,000
13 Jun 2013BBJ s.r.l.BBJ s.r.l. was fined by the Garante EUR 64,000 for running SMS and email marketing campaigns without providing the required information to data subjects and without obtaining their consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€64,000
20 Jul 2017Crea Futuro s.r.l.Crea Futuro s.r.l. was fined by the Garante 64,000 EUR for processing personal data without providing adequate information and obtaining consent. The breach affected about 2 million people, indicating a broad compliance impact.ITGaranteGDPR€64,000
12 Mar 2015Giuseppe PernaGiuseppe Perna was fined 64,000 EUR by the Garante for collecting and selling users’ email and IP addresses without proper consent and notice. The authority found this conduct to be in breach of data protection rules.ITGaranteGDPR€64,000
20 Sept 2012Policlinico Sassarese s.p.a.Policlinico Sassarese s.p.a. was fined EUR 64,000 by the Garante for inadequate data protection measures. The authority cited insufficient video surveillance notices and missing consent documentation for the processing of sensitive data.ITGaranteGDPR€64,000
26 Oct 2023Argentum Data Solutions LtdBetween 1 January 2021 and 31 January 2022, a total of 2,330,423 SMS messages were sent without consent. Argentum Data Solutions Ltd sent 24,309 messages directly and allowed its lines to be used by third parties to send the remaining 2,306,114. The conduct breached regulation 22 of PECR and came to the ICO’s attention through complaints reported via the 7726 spam tool.GBICOePrivacy€74,568
25 Sept 2025JacksonsThe ODPA fined Jacksons £65,000 after finding that the company unlawfully changed customer marketing preferences. The investigation identified anomalies in customer records and direct marketing communications made against customers’ wishes.GGODPAGDPR€74,302
18 Aug 2020HSEThe Irish DPC fined HSE EUR 65,000 in inquiry IN-19-9-1. The fine was collected.IEDPCGDPR€65,000