BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Aug 2023 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 100,000 EUR for processing personal data without proper authorization. The case involved unsolicited marketing calls and messages sent to a complainant who had no commercial relationship with the company. | ES | AEPD | GDPR | €100,000 | ↗ |
| 10 Jul 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 100,000 for repeatedly sending a former customer electronic notices about invoice availability. The authority found that the processing lacked a valid legal basis under GDPR Article 6.1. | ES | AEPD | GDPR | €100,000 | ↗ |
| 11 Apr 2024 | Olimpia S.r.l.Olimpia S.r.l. was fined for making unsolicited promotional calls without prior consent and for using numbers listed in the Public Opposition Register. The conduct breached GDPR requirements on data protection and security measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 15 Sept 2022 | Regione LazioThe Garante imposed a 100,000 EUR fine on Regione Lazio for improper processing of health data in the SIPSOweb system. The authority found that sensitive health information was processed without a proper legal basis and with incorrect role designation. | IT | Garante | GDPR | €100,000 | ↗ |
| 14 Feb 2022 | COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company sent a customer's electricity supply contract containing personal data to an incorrect address. This breached data protection principles and led to a fine by the AEPD. | ES | AEPD | GDPR | €100,000 | ↗ |
| 07 Feb 2013 | Edipro s.a.s.Edipro s.a.s. was fined by the Garante in the amount of EUR 100,000 for violations related to unsolicited telemarketing. The authority also cited the indiscriminate collection and communication of personal data. | IT | Garante | GDPR | €100,000 | ↗ |
| 04 Mar 2021 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined for processing personal data without a legal basis. The company linked a prepaid phone line to an individual without consent and shared the data with law enforcement. | ES | AEPD | GDPR | €100,000 | ↗ |
| 16 Nov 2023 | Autostrade per l’Italia S.p.A.Autostrade per l’Italia S.p.A. was fined by the Garante 100,000 EUR for failing to respond to employees' requests for access and rectification of personal data linked to annual severance pay calculations. The case concerns a failure to meet obligations for handling data subject rights requests. | IT | Garante | GDPR | €100,000 | ↗ |
| 17 Oct 2024 | OK MOBILITY ESPAÑA, S.L.OK MOBILITY ESPAÑA, S.L. was fined by the AEPD in the amount of 100,000 EUR for failing to respond to a data access request. The authority cited breaches of GDPR Articles 5(1)(e), 13, and 15. | ES | AEPD | GDPR | €100,000 | ↗ |
| 07 Mar 2024 | Ministero della saluteThe Italian Ministry of Health was fined EUR 100,000 by the Garante for inadequate data protection and communication measures in the National Health Information System. The authority found breaches of GDPR requirements on data security and breach notification. | IT | Garante | GDPR | €100,000 | ↗ |
| 23 Mar 2021 | KUTXABANK, S.A.KUTXABANK, S.A. was fined EUR 100,000 by the AEPD for failing to properly handle a data deletion request. The issue affected the complainant’s ability to open a new account. | ES | AEPD | GDPR | €100,000 | ↗ |
| 11 Jan 2024 | Findomestic Banca S.p.A.Findomestic Banca S.p.A. was fined by the Garante 100,000 EUR for sending unsolicited promotional communications by phone and mail. The authority found that these contacts were made without obtaining proper consent from the data subject. | IT | Garante | GDPR | €100,000 | ↗ |
| 26 Jan 2021 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD 100,000 EUR for unlawfully registering a prepaid phone line under the complainant’s ID and accessing credit information without a legitimate interest. The company also failed to properly comply with requests for access to and deletion of personal data. | ES | AEPD | GDPR | €100,000 | ↗ |
| 20 Oct 2025 | The Medical Specialist GroupThe Medical Specialist Group LLP reported a personal data breach after suspicious emails indicated that cyber criminals had accessed its mail server. An internal investigation found the server had been compromised in August 2021 through multiple vulnerabilities, allowing access to and theft of stored emails containing personal data. | GG | ODPA | GDPR | €115,000 | ↗ |
| 27 Jan 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 100,000 EUR for making a commercial call to a number registered on the Robinson list. The authority found that this breached data protection and direct marketing opt-out requirements. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Jan 2025 | Diskrimineringsombudsmannen (DO)Integritetsskyddsmyndigheten (IMY) imposed a 100,000 SEK administrative sanction on Diskrimineringsombudsmannen (DO). The case concerned insufficient security measures for personal data collected via a web form, which resulted in unintended disclosure to a processor. | SE | Integritetsskyddsmyndigheten (IMY) | GDPR | €8,727 | ↗ |
| 26 May 2022 | Intesa Sanpaolo S.p.A.Intesa Sanpaolo S.p.A. was fined EUR 100,000 by the Garante for unlawfully disclosing personal banking data to unauthorized third parties. The case concerned a breach of data protection rules and required review of the bank’s data-sharing controls. | IT | Garante | GDPR | €100,000 | ↗ |
| 23 Apr 2024 | Odsherred KommuneOdsherred Kommune was fined by Datatilsynet for failing to implement adequate security measures, including encryption of laptops containing sensitive personal data. The deficiency resulted in a data breach. | DK | Datatilsynet | GDPR | €13,404 | ↗ |
| 17 Dec 2020 | Azienda Unità Sanitaria Locale Toscana Sud EstAzienda Unità Sanitaria Locale Toscana Sud Est was fined for processing personal data without proper safeguards. The authority also found that patient data was shared without anonymization, in breach of GDPR requirements. | IT | Garante | GDPR | €100,000 | ↗ |
| 07 Jun 2024 | AXA REAL ESTATE INVESTMENT MANAGERS IBERICA S.A.AXA Real Estate Investment Managers Iberica S.A. was fined by the AEPD for failing to implement adequate security measures. The deficiency resulted in a data breach involving personal data stored on an encrypted USB drive. | ES | AEPD | GDPR | €100,000 | ↗ |