BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Jan 2026 | MEDIOS DE PREVENCIÓN EXTERNOS SUR, S.L.The company suffered a ransomware attack that caused a breach of the confidentiality and availability of personal data. AEPD found a violation of Article 5(1)(f) GDPR. | ES | AEPD | GDPR | €60,000 | ↗ |
| 25 Jul 2019 | VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined EUR 60,000 by the AEPD for a security breach in its customer portal. The incident allowed unauthorized access to a third party's personal data, indicating insufficient access controls. | ES | AEPD | GDPR | €60,000 | ↗ |
| 21 Oct 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 60,000 for processing personal data without proper consent. The case involved a customer receiving a notification of a purchase they had not made, indicating improper use of personal data. | ES | AEPD | GDPR | €60,000 | ↗ |
| 01 Mar 2018 | Yahoo! Italia s.r.l.Yahoo! Italia s.r.l. was fined by the Garante in the amount of 60,000 EUR. The company failed to comply with a request to remove certain URLs containing personal information from its search engine and did not provide information on the implementation of that request. | IT | Garante | GDPR | €60,000 | ↗ |
| 07 Jul 2022 | Głównego Geodetę Kraju z siedzibą w Warszawie, przy ul.UODO imposed a PLN 60,000 administrative fine on the Chief Geodesist of Poland. The authority found that the personal data breach was not reported to the supervisory authority without undue delay and that affected individuals were not notified. | PL | UODO | GDPR | €12,573 | ↗ |
| 05 Oct 2023 | DPP Law LtdThe Information Commissioner's Office issued a monetary penalty notice against DPP Law Ltd. The firm was fined GBP 60,000 for failing to implement appropriate technical and organisational measures to secure personal data. | GB | Information Commissioner's Office | GDPR | €69,282 | ↗ |
| 10 Feb 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD for processing personal data without valid consent. The case concerned a debt claim made against an individual for a contract they had not entered into. | ES | AEPD | GDPR | €60,000 | ↗ |
| 09 Jul 2025 | REAL SOCIEDAD DE FUTBOL S.A.D.REAL SOCIEDAD DE FUTBOL S.A.D. suffered a ransomware attack that led to a data breach affecting 60,000 individuals, including biometric, identification, financial, and health data. The AEPD fined the company for failing to implement adequate technical and organizational measures to protect data security. | ES | AEPD | GDPR | €60,000 | ↗ |
| 06 Mar 2020 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for inaccurate processing of personal data. The bank demanded payment for a debt the complainant did not owe and shared the complainant’s personal data with a debt collection agency. | ES | AEPD | GDPR | €60,000 | ↗ |
| 12 Jun 2014 | Istituto Poligrafico e Zecca dello Stato S.p.AIstituto Poligrafico e Zecca dello Stato S.p.A was fined EUR 60,000 by the Garante. The authority found that the company did not fully implement required security measures, in particular the logging of system administrator access to electronic archives. | IT | Garante | GDPR | €60,000 | ↗ |
| 05 Nov 2015 | Enterprise Service s.r.l.Enterprise Service s.r.l. was fined EUR 62,000 by the Garante. The sanction concerned sending unsolicited promotional faxes without prior consent, in breach of privacy rules. | IT | Garante | GDPR | €62,000 | ↗ |
| 22 Jun 2017 | Bookingshow s.p.a.Bookingshow s.p.a. was fined EUR 62,000 by the Garante for unlawfully processing personal data. The company required mandatory consent for promotional purposes during online ticket purchases, which breached data processing rules. | IT | Garante | GDPR | €62,000 | ↗ |
| 28 May 2015 | Xpedite Systems s.r.l.Xpedite Systems s.r.l. was fined 64,000 EUR by the Garante for sending unsolicited promotional faxes without the required notice and consent. The authority found this to be a breach of privacy rules. | IT | Garante | GDPR | €64,000 | ↗ |
| 13 Jun 2013 | BBJ s.r.l.BBJ s.r.l. was fined by the Garante EUR 64,000 for running SMS and email marketing campaigns without providing the required information to data subjects and without obtaining their consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €64,000 | ↗ |
| 20 Jul 2017 | Crea Futuro s.r.l.Crea Futuro s.r.l. was fined by the Garante 64,000 EUR for processing personal data without providing adequate information and obtaining consent. The breach affected about 2 million people, indicating a broad compliance impact. | IT | Garante | GDPR | €64,000 | ↗ |
| 12 Mar 2015 | Giuseppe PernaGiuseppe Perna was fined 64,000 EUR by the Garante for collecting and selling users’ email and IP addresses without proper consent and notice. The authority found this conduct to be in breach of data protection rules. | IT | Garante | GDPR | €64,000 | ↗ |
| 20 Sept 2012 | Policlinico Sassarese s.p.a.Policlinico Sassarese s.p.a. was fined EUR 64,000 by the Garante for inadequate data protection measures. The authority cited insufficient video surveillance notices and missing consent documentation for the processing of sensitive data. | IT | Garante | GDPR | €64,000 | ↗ |
| 26 Oct 2023 | Argentum Data Solutions LtdBetween 1 January 2021 and 31 January 2022, a total of 2,330,423 SMS messages were sent without consent. Argentum Data Solutions Ltd sent 24,309 messages directly and allowed its lines to be used by third parties to send the remaining 2,306,114. The conduct breached regulation 22 of PECR and came to the ICO’s attention through complaints reported via the 7726 spam tool. | GB | ICO | ePrivacy | €74,568 | ↗ |
| 25 Sept 2025 | JacksonsThe ODPA fined Jacksons £65,000 after finding that the company unlawfully changed customer marketing preferences. The investigation identified anomalies in customer records and direct marketing communications made against customers’ wishes. | GG | ODPA | GDPR | €74,302 | ↗ |
| 18 Aug 2020 | HSEThe Irish DPC fined HSE EUR 65,000 in inquiry IN-19-9-1. The fine was collected. | IE | DPC | GDPR | €65,000 | ↗ |