Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Feb 2023ENERGÍA COLECTIVA, S.L.ENERGÍA COLECTIVA, S.L. was fined by the AEPD 70,000 EUR for changing an individual's electricity provider without consent. The authority found a breach of Article 6 GDPR, which requires a lawful basis for processing personal data.ESAEPDGDPR€70,000
23 Apr 2021Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD EUR 70,000 for allowing unauthorized access to a customer's personal data. The data was then used to fraudulently contract mobile lines without the customer's consent.ESAEPDGDPR€70,000
01 Jan 2023Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without a proper legal basis. The breach enabled unauthorized SIM card duplication and subsequent fraudulent bank transactions.ESAEPDGDPR€70,000
24 Mar 2021IBERDROLA CLIENTES, SAUIberdrola Clientes, SAU was fined EUR 70,000 by the AEPD for changing the contracted power in a supply agreement without the consent of the contract holder. The authority found that this conduct breached data protection rules.ESAEPDGDPR€70,000
25 Oct 2012Enterprise Group S.r.l.Enterprise Group S.r.l. was fined EUR 70,000 by the Garante. The case concerned unsolicited promotional communications sent by fax without proper consent, in breach of data protection rules.ITGaranteGDPR€70,000
01 Jan 2023BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for a data breach after an employee accessed a customer's banking information and shared it without consent. The authority found that data security measures were violated.ESAEPDGDPR€70,000
01 Jan 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 70,000 by the AEPD for disclosing one client's personal address to another client. The authority found a breach of personal data confidentiality obligations under the GDPR.ESAEPDGDPR€70,000
01 May 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for unauthorized access to a former customer's account. The access enabled a third party to make purchases and subscriptions, indicating improper processing of personal data without consent.ESAEPDGDPR€70,000
20 Apr 2023HOLALUZ-CLIDOM, S.A.HOLALUZ-CLIDOM, S.A. was fined EUR 70,000 by the AEPD for processing personal data without consent. The company registered energy supplies for properties without the owner's consent, which breached Article 6(1) GDPR.ESAEPDGDPR€70,000
01 Jan 2023OPEN BANK, S.A.Openbank was fined by the AEPD for opening a bank account without the individual's authorization. The account was later used for fraudulent activities, indicating failures in verification and data protection controls.ESAEPDGDPR€70,000
06 Apr 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for processing personal data without consent. The case concerned a contract being formalized without the complainant’s consent, which breached lawful processing requirements.ESAEPDGDPR€70,000
28 Apr 2022Società Ospedale San Raffaele s.r.l.The Garante fined Società Ospedale San Raffaele s.r.l. EUR 70,000 for making online medical reports accessible to other patients. The case involved a breach of personal data protection and confidentiality of health information.ITGaranteGDPR€70,000
01 Jan 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for processing personal data without consent. The breach led to unauthorized access to personal data and fraudulent financial transactions.ESAEPDGDPR€70,000
02 Feb 2022SUPERCOR, S.A.SUPERCOR, S.A. was fined by the AEPD for using surveillance cameras in employee rest areas without proper notification. The authority found this conduct to be in breach of GDPR Article 6.ESAEPDGDPR€70,000
13 Jan 2022IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 70,000 by the AEPD for changing an electricity supply contract without the customer's knowledge or consent. The authority found that this conduct breached data protection rules.ESAEPDGDPR€70,000
15 Apr 2025LVMH IBERIA, S.L.LVMH IBERIA, S.L. was fined by the AEPD 70,000 EUR for adding an employee’s personal phone number to a WhatsApp group without consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€70,000
08 Jul 2022Anonymizováno (ÚOOÚ UOOU-03988/20-54)The entity was fined for processing personal data without a legal basis. The infringement involved sending unsolicited offers using data obtained from the business register.CZUOOUGDPR€2,844
31 May 2018Iqbal QasimIqbal Qasim was fined by the Garante in the amount of EUR 70,000 for registering phone SIM cards to third parties without their consent. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€70,000
01 Jan 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD 70,000 EUR for changing the ownership of a mobile line without proper verification. The failure enabled unauthorized access to the complainant’s bank data and fraudulent transactions.ESAEPDGDPR€70,000
18 Feb 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 70,000 EUR by the AEPD for incorrectly linking a customer's phone lines to another person's details. The case concerned a breach of data protection rules and indicated deficiencies in personal data processing.ESAEPDGDPR€70,000