BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Aug 2024 | SOCIETE SPECIALISEE DANS LA GESTION DES FLUX DE DONNEES DE SANTEThe CNIL imposed an administrative fine of EUR 200,000 on SOCIETE SPECIALISEE DANS LA GESTION DES FLUX DE DONNEES DE SANTE. The case concerns a breach of data protection rules supervised by the French authority. | FR | CNIL | GDPR | €200,000 | ↗ |
| 16 Mar 2023 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for failing to implement adequate security measures. A SIM card duplication enabled unauthorized access to a customer’s personal data and financial accounts. | ES | AEPD | GDPR | €200,000 | ↗ |
| 12 Oct 2023 | Onda Più S.r.l.Onda Più S.r.l. was fined EUR 200,000 by the Garante for activating energy supply contracts without customer consent. The authority also found the use of inaccurate and outdated personal data. | IT | Garante | GDPR | €200,000 | ↗ |
| 21 Jun 2021 | GSMA LTD.GSMA LTD. was fined by the AEPD for requiring biometric data, including passport details and photos, for facial recognition at the Mobile World Congress without a valid legal basis. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 11 Mar 2025 | UNIÓN DE CRÉDITO PARA LA FINANC. MOB. E INMOB., CREDIFIMO, E.F.C., SAUCREDIFIMO was fined by the AEPD for unlawfully processing personal data by including an individual's data in a credit file without a lawful basis. The authority found a breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 19 Mar 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for failing to verify the identity of a person who obtained a SIM duplicate. This omission led to unauthorized transactions and was treated as a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 03 Feb 2021 | Cyberbook ASCyberbook AS was fined 200,000 NOK by Datatilsynet for unlawfully forwarding a former employee's emails without informing them. The authority found breaches of GDPR requirements on legal basis, information duties, and data deletion. | NO | Datatilsynet | GDPR | €19,316 | ↗ |
| 03 Apr 2023 | HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined EUR 200,000 by the AEPD for insufficient security measures in its hospital information system. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational safeguards. | ES | AEPD | GDPR | €200,000 | ↗ |
| 15 Apr 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for including personal data in a credit solvency file without proper prior notice. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 05 Dec 2024 | ESL Consultancy Services Ltd Between 15 September 2022 and 5 December 2023, 37,977 complaints were received about direct marketing messages sent at the instigation of ESL Consultancy Services Ltd. The ICO fined the company GBP 200,000 and issued an enforcement notice. | GB | ICO | GDPR | €241,000 | ↗ |
| 07 Jan 2022 | Elektro & Automasjon Systemer ASElektro & Automasjon Systemer AS was fined NOK 200,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The company checked a co-owner of another company despite having no business relationship or justification for the credit check. | NO | Datatilsynet | GDPR | €19,942 | ↗ |
| 06 Feb 2023 | VODAFONE ESPAÑA, S.A.U.The AEPD imposed a 200,000 EUR fine on VODAFONE ESPAÑA, S.A.U. for breaching Article 6(1) GDPR. The case involved unauthorized SIM card duplication that enabled fraudulent bank charges. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 200,000 EUR by the AEPD for issuing a duplicate SIM card without the customer’s consent. The incident led to unauthorized financial transactions, indicating significant failures in authorization and security controls. | ES | AEPD | GDPR | €200,000 | ↗ |
| 16 Sept 2025 | Bharat Singh ChandBharat Singh Chand, a self-employed lead generator, sent or instigated the sending of 966,449 direct marketing SMS messages between 3 December 2023 and 3 July 2024. The activity breached regulations 22 and 23 of PECR and generated 19,138 complaints to the 7726 spam reporting service. He was fined £200,000 and issued with an enforcement notice. | GB | ICO | ePrivacy | €231,000 | ↗ |
| 11 Apr 2023 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 200,000 for failing to remove personal data from a credit information system after the debt was sold. The authority found that the continued processing of the data was not compliant with data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 18 Sept 2023 | SOCIETE DE TRANSPORT DE FRET AERIENCNIL imposed a fine of EUR 200,000 on SOCIETE DE TRANSPORT DE FRET AERIEN. The case concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €200,000 | ↗ |
| 09 Jan 2023 | TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR after a SIM swapping incident enabled unauthorized bank transactions. The authority found a breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 15 Jul 2024 | ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD 200,000 EUR for failing to properly handle a data subject’s request for deletion and for processing personal data without a legal basis. The case concerns breaches of core data protection obligations. | ES | AEPD | GDPR | €200,000 | ↗ |
| 19 Feb 2024 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 200,000 by the AEPD for processing personal data without a legal basis. The case concerned a phone number portability carried out without the user's consent, which breached the requirement for lawful processing. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | ENDESA ENERGIA, S.A.U.ENDESA ENERGIA, S.A.U. was fined €200,000 by the AEPD for changing the contract holder and bank account without consent. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €200,000 | ↗ |