Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2024ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. was fined by the AEPD EUR 140,000 for unauthorized access to personal data. The authority found a breach of GDPR confidentiality and security principles.ESAEPDGDPR€140,000
29 Apr 2026DIGI SPAIN TELECOM, S.L.U.DIGI SPAIN TELECOM, S.L.U. was fined by the AEPD 140,000 EUR for processing personal data without a legal basis. The case concerned a SIM card duplication incident that resulted in unauthorized data processing.ESAEPDGDPR€140,000
09 Feb 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined by the AEPD for unlawfully processing personal data and for failing to provide access to personal data requested by a former client. The case concerns non-compliance with data protection obligations.ESAEPDGDPR€140,000
25 Jan 2018Scaramuzza MarioScaramuzza Mario was fined EUR 140,000 by the Garante for the unauthorized activation of multiple payment cards using personal data without the consent of the individuals concerned. The case indicates a breach of lawful processing requirements and the absence of a valid legal basis.ITGaranteGDPR€140,000
01 Jan 2023GENERAL LOGISTICS SYSTEMS SPAIN, S.A.GENERAL LOGISTICS SYSTEMS SPAIN, S.A. was fined by the AEPD 140,000 EUR for processing the personal data of two complainants without proper authorization. The breach resulted in identity theft and misuse of personal data.ESAEPDGDPR€140,000
25 Feb 2020Addiko Bank d.d.The High Administrative Court of the Republic of Croatia upheld AZOP’s decision of 25 February 2020 against Addiko Bank d.d. The confirmed administrative fine was 145,995.09 EUR for obstructing customers’ access to their personal data and credit documentation.HRAZOPGDPR€145,000
11 Apr 2023CORPORACION DE MEDIOS DE EXTREMADURA, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. The authority found a breach of the data minimization principle and imposed a 150,000 EUR fine.ESAEPDGDPR€150,000
25 Jun 2025Vodafone-PanafonVodafone-Panafon was fined EUR 150,000 by the HDPA for inadequate technical and organizational security measures. The authority found a violation of Article 12 of Law 3471/2006.GRHDPAePrivacy€150,000
25 Mar 2021Dragefossen ASDragefossen AS was fined 150,000 NOK by Datatilsynet for unlawfully live streaming surveillance footage from a camera in Rognan sentrum on the internet. The authority found no legal basis for the processing, which breached GDPR Articles 6 and 5.NODatatilsynetGDPR€14,756
17 Aug 2021UdlændingestyrelsenThe Danish DPA, Datatilsynet, recommended a fine of DKK 150,000 against Udlændingestyrelsen. The case concerned inadequate security measures in personal data processing, which could have affected the rights of residents at deportation centers.DKDatatilsynetGDPR€20,171
30 Mar 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 150,000 EUR for failing to delete personal data after phone contracts ended. This led to continued SMS notifications with zero-balance invoices being sent to former customers.ESAEPDGDPR€150,000
04 Nov 2019Coöperatie Menzis U.A.The Dutch Data Protection Authority, AP, imposed a fine of EUR 150,000 on Coöperatie Menzis U.A. The authority found that the company had inadequate technical measures to prevent unauthorized access to personal health data.NLAPGDPR€150,000
30 Jul 2025ONEY SERVICIOS FINANCIEROS EFC, S.A.The AEPD fined ONEY Servicios Financieros EFC, S.A. 150,000 EUR for failing to adequately protect personal data. The breach led to a security incident in which a third party accessed a customer's account through a vishing attack.ESAEPDGDPR€150,000
13 Apr 2023Sociale verzekeringsbankThe Dutch AP fined Sociale verzekeringsbank EUR 150,000. The authority found that the organization failed to implement adequate technical and organizational measures to ensure a risk-appropriate level of security when processing personal data during telephone contact with AOW beneficiaries, in breach of GDPR Article 32.NLAPGDPR€150,000
09 Oct 2019Vreau Credit S.R.L.Vreau Credit S.R.L. was fined by ANSPDCP for failing to notify the supervisory authority of a data breach without undue delay and for unauthorized processing of personal data. The violations resulted in a loss of data confidentiality and indicate inadequate compliance controls.ROANSPDCPGDPR€150,000
16 Jan 2024Poxell LtdThe ICO found that Poxell Ltd made 2,647,805 unsolicited direct marketing calls between 31 March 2022 and 20 July 2022, breaching regulations 21 and 24 of PECR. This led to 413 complaints to the ICO and TPS, with recipients reporting persistent calls about energy-related products and home improvements.GBICOePrivacy€174,000
31 Mar 2021ORANGE ESPAGNE, S.A.U.Orange Espagne, S.A.U. was fined by the AEPD 150,000 EUR for violations related to direct marketing communications. The case concerned conduct that may have breached data protection rules.ESAEPDePrivacy€150,000
09 Nov 2023Complete Marketing Services LtdBetween 8 June 2021 and 4 February 2022, Complete Marketing Services Ltd instigated 242,497 unsolicited direct marketing calls in breach of PECR. The ICO became aware of the matter after complaints about live marketing calls relating to road traffic accidents and personal injury claims were reported via the TPS.GBICOePrivacy€172,000
09 Oct 2018WIND HELLAS TELECOMMUNICATIONS S.A.The fine was imposed for making unsolicited marketing calls to subscribers who had opted out of such contact. This conduct breached privacy and data protection rules.GRHDPAePrivacy€150,000
09 Jul 2025VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 150,000 EUR for issuing a SIM card duplicate without proper consent. The incident led to unauthorized bank transfers and involved processing personal data without a lawful basis.ESAEPDGDPR€150,000