BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Feb 2023 | ENERGÍA COLECTIVA, S.L.ENERGÍA COLECTIVA, S.L. was fined by the AEPD 70,000 EUR for changing an individual's electricity provider without consent. The authority found a breach of Article 6 GDPR, which requires a lawful basis for processing personal data. | ES | AEPD | GDPR | €70,000 | ↗ |
| 23 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD EUR 70,000 for allowing unauthorized access to a customer's personal data. The data was then used to fraudulently contract mobile lines without the customer's consent. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2023 | Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without a proper legal basis. The breach enabled unauthorized SIM card duplication and subsequent fraudulent bank transactions. | ES | AEPD | GDPR | €70,000 | ↗ |
| 24 Mar 2021 | IBERDROLA CLIENTES, SAUIberdrola Clientes, SAU was fined EUR 70,000 by the AEPD for changing the contracted power in a supply agreement without the consent of the contract holder. The authority found that this conduct breached data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 25 Oct 2012 | Enterprise Group S.r.l.Enterprise Group S.r.l. was fined EUR 70,000 by the Garante. The case concerned unsolicited promotional communications sent by fax without proper consent, in breach of data protection rules. | IT | Garante | GDPR | €70,000 | ↗ |
| 01 Jan 2023 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for a data breach after an employee accessed a customer's banking information and shared it without consent. The authority found that data security measures were violated. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 70,000 by the AEPD for disclosing one client's personal address to another client. The authority found a breach of personal data confidentiality obligations under the GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 May 2022 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for unauthorized access to a former customer's account. The access enabled a third party to make purchases and subscriptions, indicating improper processing of personal data without consent. | ES | AEPD | GDPR | €70,000 | ↗ |
| 20 Apr 2023 | HOLALUZ-CLIDOM, S.A.HOLALUZ-CLIDOM, S.A. was fined EUR 70,000 by the AEPD for processing personal data without consent. The company registered energy supplies for properties without the owner's consent, which breached Article 6(1) GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2023 | OPEN BANK, S.A.Openbank was fined by the AEPD for opening a bank account without the individual's authorization. The account was later used for fraudulent activities, indicating failures in verification and data protection controls. | ES | AEPD | GDPR | €70,000 | ↗ |
| 06 Apr 2022 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for processing personal data without consent. The case concerned a contract being formalized without the complainant’s consent, which breached lawful processing requirements. | ES | AEPD | GDPR | €70,000 | ↗ |
| 28 Apr 2022 | Società Ospedale San Raffaele s.r.l.The Garante fined Società Ospedale San Raffaele s.r.l. EUR 70,000 for making online medical reports accessible to other patients. The case involved a breach of personal data protection and confidentiality of health information. | IT | Garante | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for processing personal data without consent. The breach led to unauthorized access to personal data and fraudulent financial transactions. | ES | AEPD | GDPR | €70,000 | ↗ |
| 02 Feb 2022 | SUPERCOR, S.A.SUPERCOR, S.A. was fined by the AEPD for using surveillance cameras in employee rest areas without proper notification. The authority found this conduct to be in breach of GDPR Article 6. | ES | AEPD | GDPR | €70,000 | ↗ |
| 13 Jan 2022 | IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 70,000 by the AEPD for changing an electricity supply contract without the customer's knowledge or consent. The authority found that this conduct breached data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 15 Apr 2025 | LVMH IBERIA, S.L.LVMH IBERIA, S.L. was fined by the AEPD 70,000 EUR for adding an employee’s personal phone number to a WhatsApp group without consent. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 08 Jul 2022 | Anonymizováno (ÚOOÚ UOOU-03988/20-54)The entity was fined for processing personal data without a legal basis. The infringement involved sending unsolicited offers using data obtained from the business register. | CZ | UOOU | GDPR | €2,844 | ↗ |
| 31 May 2018 | Iqbal QasimIqbal Qasim was fined by the Garante in the amount of EUR 70,000 for registering phone SIM cards to third parties without their consent. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €70,000 | ↗ |
| 01 Jan 2023 | TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD 70,000 EUR for changing the ownership of a mobile line without proper verification. The failure enabled unauthorized access to the complainant’s bank data and fraudulent transactions. | ES | AEPD | GDPR | €70,000 | ↗ |
| 18 Feb 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 70,000 EUR by the AEPD for incorrectly linking a customer's phone lines to another person's details. The case concerned a breach of data protection rules and indicated deficiencies in personal data processing. | ES | AEPD | GDPR | €70,000 | ↗ |