Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Dec 2024FUNDACIÓN SOCIEDAD CIENTÍFICA DE ONCOLOGÍA MÉDICAFUNDACIÓN SOCIEDAD CIENTÍFICA DE ONCOLOGÍA MÉDICA was fined 70,000 EUR by the AEPD for a data breach affecting confidentiality. The authority found a violation of Article 5(1)(f) GDPR, which requires personal data to be processed securely and confidentially.ESAEPDGDPR€70,000
28 May 2024CUI ZSQ FOOD, S.L.CUI ZSQ FOOD, S.L. was fined by the AEPD 70,000 EUR for using a video surveillance system to intimidate employees. The company shared footage of an employee’s absence in a work chat, which breached data protection rules.ESAEPDGDPR€70,000
27 Jan 2021Azienda ospedaliera regionale “San Carlo” di PotenzaAzienda ospedaliera regionale “San Carlo” di Potenza was fined EUR 70,000 by the Garante for violations related to the processing of personal data. The case concerned the handling of sensitive health data.ITGaranteGDPR€70,000
21 Sept 2023SGS Home Protect LtdSGS Home Protect Ltd made 24,214 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of 70,000 GBP and issued an enforcement notice.GBICOePrivacy€80,724
09 Mar 2023INTERURBANA DE AUTOBUSES, S.A.INTERURBANA DE AUTOBUSES, S.A. was fined by the AEPD 70,000 EUR for publishing employees’ personal data without consent. The breach involved exposing unnecessary information on notice boards accessible to others, contrary to data minimization requirements.ESAEPDGDPR€70,000
19 Dec 2024Studio Riabilitazione Creditizia s.r.l.s.The Garante fined Studio Riabilitazione Creditizia s.r.l.s. €70,000 for improperly accessing financial data from the Central Credit Register without proper authorization. The authority found this conduct breached data protection principles.ITGaranteGDPR€70,000
15 Mar 2023BANKINTER CONSUMER FINANCE E.F.C., S.A.Bankinter Consumer Finance issued a duplicate card without the customer's consent and sent it to an incorrect address. This led to unauthorized transactions and indicated a failure in data protection and payment security controls.ESAEPDGDPR€70,000
17 Feb 2022VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined EUR 70,000 by the AEPD for issuing a duplicate SIM card to a third party without the customer's consent. This enabled unauthorized access to the customer's bank account.ESAEPDGDPR€70,000
17 Mar 2023ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 70,000 by the AEPD for activating a call forwarding service without the user's consent. This led to unauthorized access to the user's bank accounts and transactions.ESAEPDGDPR€70,000
17 Mar 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.The AEPD fined TELEFÓNICA MÓVILES ESPAÑA, S.A. 70,000 EUR for changing a customer's mobile tariff without consent. The authority found that the action breached Article 6(1) GDPR because there was no valid legal basis for the change.ESAEPDGDPR€70,000
11 May 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 70,000 by the AEPD for issuing a duplicate SIM card without the customer's consent. This enabled unauthorized access to the customer's bank account, indicating a serious failure in security and data protection controls.ESAEPDGDPR€70,000
06 Feb 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 70,000 EUR by the AEPD for a personal data breach. An error in assigning identification numbers allowed one customer to access another customer's personal data.ESAEPDGDPR€70,000
24 Oct 2023FIBRA ÓPTICA MÁLAGA, S.L.FIBRA ÓPTICA MÁLAGA, S.L. changed a customer's contact email and bank account details without consent. The AEPD found a breach of GDPR Article 6(1) and imposed a 70,000 EUR fine.ESAEPDGDPR€70,000
31 Mar 2022ALQUILER SEGURO, S.A.U.ALQUILER SEGURO, S.A.U. accessed personal data from Asnef for purposes other than those intended. The AEPD found this to be a breach of data protection rules and imposed a 70,000 EUR fine.ESAEPDGDPR€70,000
03 Feb 2022DIGI SPAIN TELECOM, S.L.DIGI Spain Telecom, S.L. was fined by the AEPD in the amount of EUR 70,000 for a breach of Article 6(1) GDPR. The case concerned the unauthorized duplication of a SIM card in an identity theft incident, which resulted in financial losses for the complainant.ESAEPDGDPR€70,000
17 Dec 2020University College DublinThe Irish DPC imposed a fine of EUR 70,000 on University College Dublin in inquiry IN-19-7-4. The fine has been collected.IEDPCGDPR€70,000
02 Jun 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for continuing to send investment reports by postal mail despite the complainant’s request to receive them by email. The authority found a breach of the right to object and to stop data processing.ESAEPDGDPR€70,000
17 May 2022ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 70,000 by the AEPD for issuing a SIM card duplicate to a third party without the claimant’s consent. The authority also found that the third party’s identity was not verified, constituting a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
07 Jan 2022CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD EUR 70,000 for including personal data in credit information systems without a proper legal basis. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
01 Jan 2022ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without consent. The conduct led to unauthorized contracts and credit reporting issues.ESAEPDGDPR€70,000