Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Feb 2020TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined 75,000 EUR by the AEPD for processing personal data without consent. The case concerned unauthorized portability of a phone line.ESAEPDGDPR€75,000
12 Jun 2014H3g s.p.a.H3g s.p.a. was fined EUR 75,000 by the Garante for violations related to customer profiling without the required consent. The case concerned personal data processing that did not comply with data protection requirements.ITGaranteGDPR€75,000
07 Aug 2020TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 75,000 EUR for unauthorized access to a customer's data and harassment through excessive calls and messages. The case indicates failures in data protection controls and customer contact practices.ESAEPDGDPR€75,000
17 May 2021TELEFÓNICA DE ESPAÑA, S.A.U.Telefónica de España, S.A.U. was fined by the AEPD for using personal data to contract a service without the data subject’s consent and for listing the complainant in credit information files for a debt that was not recognized. The case concerns processing without a valid legal basis and improper reporting of alleged debt.ESAEPDGDPR€75,000
01 Jan 2019EDP ENERGÍA, S.A.U.EDP ENERGÍA, S.A.U. was fined by the AEPD EUR 75,000 for processing personal data without consent. The case concerned an energy contract to which the complainant was not a party, constituting a breach of Article 6(1) GDPR.ESAEPDGDPR€75,000
20 Jul 2020Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD €75,000 for charging a complainant for services linked to a third-party mobile number without consent. The authority found a breach of Article 6(1) GDPR because there was no lawful basis for the processing and related charges.ESAEPDGDPR€75,000
01 Jan 2019Vodafone España, S.A.U.Vodafone España, S.A.U. was fined EUR 75,000 by the AEPD for a data protection breach. The case involved unauthorized contract portability using a customer's personal data without consent.ESAEPDGDPR€75,000
29 Dec 2023SOCIETE DE SITES EN LIGNE DE JEUX-CONCOURS ET TESTS PRODUITSCNIL imposed a fine of 75,000 EUR on SOCIETE DE SITES EN LIGNE DE JEUX-CONCOURS ET TESTS PRODUITS and issued an injunction. The case concerns identified breaches of rules supervised by CNIL.FRCNILGDPR€75,000
18 Jun 2025Aktiebolaget Storstockholms Lokaltrafik (SL)Aktiebolaget Storstockholms Lokaltrafik (SL) was fined 75,000 SEK by IMY for processing personal data without a legal basis and special-category data without a valid exception. The authority found breaches of GDPR Articles 6 and 9.SEIMYGDPR€6,802
16 Sept 2021Favrskov KommuneFavrskov Kommune was fined 75,000 DKK for failing to implement appropriate security measures, including encryption, to protect sensitive personal data on a stolen laptop. The authority found a breach of GDPR Article 32.DKDatatilsynetGDPR€10,086
22 Oct 2019IBERDROLA COMERCIALIZACIÓN DE ÚLTIMO RECURSO, S.A.U. (CURENERGIA COMERCIALIZADORA DE ULTIMO RECURSO, S.A.U.)CURENERGIA was fined EUR 75,000 by the AEPD for using a former client's personal data without consent. The data was used to carry out a fraudulent contract registration. The case indicates a breach of lawful processing and personal data protection requirements.ESAEPDGDPR€75,000
11 Feb 2021Ministero dello Sviluppo EconomicoThe Ministry of Economic Development was fined by the Garante for publishing personal data, including managers' CVs, on its institutional website without a proper legal basis. The authority found this conduct to be in breach of GDPR requirements.ITGaranteGDPR€75,000
26 Apr 2018MTS s.r.l.s.MTS s.r.l.s. was fined EUR 76,000 by the Garante for making unsolicited promotional calls. The company also failed to respond to the authority's request for information, which constituted a data protection breach.ITGaranteGDPR€76,000
30 Jul 2015Roberto NaccaratoRoberto Naccarato was fined by the Garante for processing the personal data of 12 individuals without providing proper information or obtaining consent. The authority found this to be a breach of Italian data protection law.ITGaranteGDPR€76,800
12 Mar 2024DKN.5131.28.2023StatusprawomocnaTytuUODO imposed an administrative fine of PLN 78,575.4 for failing to report a personal data breach without undue delay. The incident was not notified to the supervisory authority within 72 hours of becoming aware of the breach.PLUODOGDPR€18,331
29 Jan 2015Comunicando di Rizzotto Fabio & C. s.a.s.Comunicando di Rizzotto Fabio & C. s.a.s. was fined €80,000 by the Garante for activating 88 phone cards in the names of 16 individuals without their knowledge. The authority found this to be a breach of data protection rules.ITGaranteGDPR€80,000
12 Feb 2024MEYDIS, S.L.MEYDIS, S.L. was fined EUR 80,000 by the AEPD for failing to provide required information during an investigation. The authority found a breach of Article 58.1 of the GDPR.ESAEPDGDPR€80,000
10 Jul 2025Poste Vita S.p.a.Poste Vita S.p.a. was fined EUR 80,000 by the Garante for unlawfully disclosing personal data relating to life insurance policies to an unauthorized third party. The data were then used in judicial proceedings.ITGaranteGDPR€80,000
17 Dec 2019ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 80,000 by the AEPD for using personal data to fraudulently contract phone lines without consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€80,000
07 Nov 2025MAJOREL SP SOLUTIONS, S.A.MAJOREL SP SOLUTIONS, S.A. was fined by the AEPD 80,000 EUR for processing personal data without a lawful basis. The authority found a breach of Article 6(1)(b) GDPR.ESAEPDGDPR€80,000