Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Aug 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 100,000 EUR for processing personal data without proper authorization. The case involved unsolicited marketing calls and messages sent to a complainant who had no commercial relationship with the company.ESAEPDGDPR€100,000
10 Jul 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 100,000 for repeatedly sending a former customer electronic notices about invoice availability. The authority found that the processing lacked a valid legal basis under GDPR Article 6.1.ESAEPDGDPR€100,000
11 Apr 2024Olimpia S.r.l.Olimpia S.r.l. was fined for making unsolicited promotional calls without prior consent and for using numbers listed in the Public Opposition Register. The conduct breached GDPR requirements on data protection and security measures.ITGaranteGDPR€100,000
15 Sept 2022Regione LazioThe Garante imposed a 100,000 EUR fine on Regione Lazio for improper processing of health data in the SIPSOweb system. The authority found that sensitive health information was processed without a proper legal basis and with incorrect role designation.ITGaranteGDPR€100,000
14 Feb 2022COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company sent a customer's electricity supply contract containing personal data to an incorrect address. This breached data protection principles and led to a fine by the AEPD.ESAEPDGDPR€100,000
07 Feb 2013Edipro s.a.s.Edipro s.a.s. was fined by the Garante in the amount of EUR 100,000 for violations related to unsolicited telemarketing. The authority also cited the indiscriminate collection and communication of personal data.ITGaranteGDPR€100,000
04 Mar 2021VODAFONE ESPAÑA, S.A.U.Vodafone España was fined for processing personal data without a legal basis. The company linked a prepaid phone line to an individual without consent and shared the data with law enforcement.ESAEPDGDPR€100,000
16 Nov 2023Autostrade per l’Italia S.p.A.Autostrade per l’Italia S.p.A. was fined by the Garante 100,000 EUR for failing to respond to employees' requests for access and rectification of personal data linked to annual severance pay calculations. The case concerns a failure to meet obligations for handling data subject rights requests.ITGaranteGDPR€100,000
17 Oct 2024OK MOBILITY ESPAÑA, S.L.OK MOBILITY ESPAÑA, S.L. was fined by the AEPD in the amount of 100,000 EUR for failing to respond to a data access request. The authority cited breaches of GDPR Articles 5(1)(e), 13, and 15.ESAEPDGDPR€100,000
07 Mar 2024Ministero della saluteThe Italian Ministry of Health was fined EUR 100,000 by the Garante for inadequate data protection and communication measures in the National Health Information System. The authority found breaches of GDPR requirements on data security and breach notification.ITGaranteGDPR€100,000
23 Mar 2021KUTXABANK, S.A.KUTXABANK, S.A. was fined EUR 100,000 by the AEPD for failing to properly handle a data deletion request. The issue affected the complainant’s ability to open a new account.ESAEPDGDPR€100,000
11 Jan 2024Findomestic Banca S.p.A.Findomestic Banca S.p.A. was fined by the Garante 100,000 EUR for sending unsolicited promotional communications by phone and mail. The authority found that these contacts were made without obtaining proper consent from the data subject.ITGaranteGDPR€100,000
26 Jan 2021VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD 100,000 EUR for unlawfully registering a prepaid phone line under the complainant’s ID and accessing credit information without a legitimate interest. The company also failed to properly comply with requests for access to and deletion of personal data.ESAEPDGDPR€100,000
20 Oct 2025The Medical Specialist GroupThe Medical Specialist Group LLP reported a personal data breach after suspicious emails indicated that cyber criminals had accessed its mail server. An internal investigation found the server had been compromised in August 2021 through multiple vulnerabilities, allowing access to and theft of stored emails containing personal data.GGODPAGDPR€115,000
27 Jan 2021Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 100,000 EUR for making a commercial call to a number registered on the Robinson list. The authority found that this breached data protection and direct marketing opt-out requirements.ESAEPDGDPR€100,000
01 Jan 2025Diskrimineringsombudsmannen (DO)Integritetsskyddsmyndigheten (IMY) imposed a 100,000 SEK administrative sanction on Diskrimineringsombudsmannen (DO). The case concerned insufficient security measures for personal data collected via a web form, which resulted in unintended disclosure to a processor.SEIntegritetsskyddsmyndigheten (IMY)GDPR€8,727
26 May 2022Intesa Sanpaolo S.p.A.Intesa Sanpaolo S.p.A. was fined EUR 100,000 by the Garante for unlawfully disclosing personal banking data to unauthorized third parties. The case concerned a breach of data protection rules and required review of the bank’s data-sharing controls.ITGaranteGDPR€100,000
23 Apr 2024Odsherred KommuneOdsherred Kommune was fined by Datatilsynet for failing to implement adequate security measures, including encryption of laptops containing sensitive personal data. The deficiency resulted in a data breach.DKDatatilsynetGDPR€13,404
17 Dec 2020Azienda Unità Sanitaria Locale Toscana Sud EstAzienda Unità Sanitaria Locale Toscana Sud Est was fined for processing personal data without proper safeguards. The authority also found that patient data was shared without anonymization, in breach of GDPR requirements.ITGaranteGDPR€100,000
07 Jun 2024AXA REAL ESTATE INVESTMENT MANAGERS IBERICA S.A.AXA Real Estate Investment Managers Iberica S.A. was fined by the AEPD for failing to implement adequate security measures. The deficiency resulted in a data breach involving personal data stored on an encrypted USB drive.ESAEPDGDPR€100,000