Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Jun 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD €65,000 for improper handling of personal data. The company failed to notify the rectification or deletion of personal data, which led to unwarranted debt collection calls.ESAEPDGDPR€65,000
21 Sept 2023RHAP LtdRHAP Ltd made 15,288 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a £65,000 fine and issued an enforcement notice.GBICOePrivacy€74,958
14 Jan 2021SIA "Lursoft IT"A fine of EUR 65,000 was imposed. The decision is final and has entered into force.LVDVIGDPR€65,000
17 Apr 2014SSTC srlSSTC srl was fined EUR 66,000 by the Italian authority Garante. The case concerned telemarketing activities carried out without the prior consent of the contacted individuals, in breach of data protection rules.ITGaranteGDPR€66,000
20 Nov 2017ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 66,000 by the AEPD for sending unsolicited promotional SMS messages. The authority also noted that recipients were not given a means to object to the processing of their data for marketing purposes.ESAEPDePrivacy€66,000
15 Nov 2012Dusty s.r.l.Dusty s.r.l. was fined by the Italian Garante 66,000 EUR for implementing a biometric data collection system for employee attendance without properly appointing data processing officers and without obtaining the required consent. The authority found violations of several provisions of the data protection code.ITGaranteGDPR€66,000
06 Sept 2017ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 66,000 by the AEPD for sending commercial SMS messages without consent. The authority also found that recipients were not given an effective option to object, in breach of the LSSI rules.ESAEPDePrivacy€66,000
12 Dec 2025Police Service of ScotlandThe Information Commissioner's Office (ICO) fined the Police Service of Scotland £66,000 and issued a reprimand for serious failures in handling sensitive personal information. The case concerned improper handling of information requiring special protection, increasing the risk to affected individuals.GBICOGDPR€75,280
17 Jun 2025Szpital, za naruszenie przepisów art. 5 ust. 1 lit. f) i ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679,UODO imposed an administrative fine of PLN 66,500 on the hospital. The authority found that the hospital failed to implement appropriate technical and organizational measures to secure personal data and protect data subjects' rights. It also failed to regularly test, measure, and assess the effectiveness of those safeguards.PLUODOGDPR€15,546
11 Jan 2018N.J.L. & Time di Bernasconi NadiaN.J.L. & Time di Bernasconi Nadia was fined 68,000 EUR by the Garante. The authority found that promotional emails were sent without proper consent, in breach of data protection rules.ITGaranteGDPR€68,000
04 Nov 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 70,000 EUR for processing a fraudulent phone number portability request without the data subject's consent. The authority found a breach of GDPR Article 6(1).ESAEPDGDPR€70,000
29 Jan 2024IDFINANCE SPAIN, S.A.U.The AEPD fined IDFINANCE SPAIN, S.A.U. 70,000 EUR for including personal data in credit information systems in connection with a disputed debt. The authority found that the processing breached Article 6 GDPR.ESAEPDGDPR€70,000
23 Apr 2021Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without proper consent. The case involved a call to a customer about a service package that the customer had not authorized.ESAEPDGDPR€70,000
06 Jun 2024WORLD 2 MEET, S.L.WORLD 2 MEET, S.L. was fined EUR 70,000 by the AEPD for requesting excessive personal data from guests during traveler registration. The company required full copies of identity documents, which breached the data minimization principle.ESAEPDGDPR€70,000
05 May 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD EUR 70,000 for a data protection breach involving unauthorized SIM card duplication. The incident led to unauthorized bank transfers from the complainant's account.ESAEPDGDPR€70,000
23 Apr 2021Vodafone España, S.A.U.The AEPD fined Vodafone España, S.A.U. EUR 70,000 for failing to adequately prevent identity theft. As a result, unauthorized phone line contracts were entered into using a customer's personal data.ESAEPDGDPR€70,000
17 Jan 2023ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without valid consent. The case concerned a contract entered into in the name of a deceased person without authorization.ESAEPDGDPR€70,000
07 Mar 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for improperly handling a SIM card duplication request. The failure led to unauthorized transactions on a customer's bank account and was found to breach Article 6(1) GDPR.ESAEPDGDPR€70,000
01 Jan 2023Vodafone España, S.A.U.The AEPD fined Vodafone España EUR 70,000 for providing a SIM card duplicate to a third party without the data subject's consent. This enabled unauthorized access to personal and banking information.ESAEPDGDPR€70,000
12 Nov 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for continuing to send billing emails to a complainant despite an arbitration ruling. The ruling required the company to stop all services and delete the complainant’s data, which it failed to do.ESAEPDGDPR€70,000