BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Oct 2019 | OTEOTE was fined by the HDPA EUR 200,000 for failing to process unsubscribe requests from marketing emails due to a technical error. The issue affected about 8,000 subscribers and had been ongoing since 2013. | GR | HDPA | GDPR | €200,000 | ↗ |
| 27 Feb 2023 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for breaching Article 6(1) GDPR after a SIM card was duplicated without consent. The incident enabled unauthorized access to a customer's bank accounts, indicating serious failures in verification and data protection controls. | ES | AEPD | GDPR | €200,000 | ↗ |
| 24 Nov 2020 | LSS-boendeGnosjö kommun - Socialutskottet was fined by IMY for unlawful video surveillance in an LSS residence. The authority found processing of personal and sensitive data without a legal basis and no data protection impact assessment. | SE | IMY | GDPR | €19,600 | ↗ |
| 11 Dec 2024 | Granit Bostad Beritsholm ABGranit Bostad Beritsholm AB was fined by IMY for conducting video surveillance without a lawful basis. The authority also found that required information was not provided to affected individuals, constituting a GDPR breach. | SE | IMY | GDPR | €17,366 | ↗ |
| 20 Aug 2019 | Gymnasienämnden i Skellefteå kommunGymnasienämnden i Skellefteå kommun was fined by IMY for using facial recognition to record student attendance. The authority found that the processing was more intrusive than necessary and lacked a valid exception for biometric data. | SE | IMY | GDPR | €18,578 | ↗ |
| 05 Dec 2024 | KASPRThe CNIL imposed an administrative fine of EUR 200,000 on KASPR on 5 December 2024. The authority found GDPR breaches relating to lawful basis, retention, transparency, information, and access rights in connection with KASPR's data scraping activities. | FR | CNIL | GDPR | €200,000 | ↗ |
| 07 Oct 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for unauthorized remote management of a former employee's personal device. The authority found that the conduct breached the principles of lawful personal data processing. | ES | AEPD | GDPR | €200,000 | ↗ |
| 13 Sept 2024 | ARES CAPITAL, S.A.ARES CAPITAL, S.A. was fined by the AEPD for requiring employees to use personal phones for work together with continuous monitoring apps. The authority found that the company did not provide sufficient information about data collection, breaching GDPR rules on lawful basis, transparency, and data processing principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 12 Nov 2014 | One Italia s.r.l.One Italia s.r.l. was fined €200,000 by the Garante for sending unsolicited promotional messages related to a value-added service. The authority found that proper consent and adequate information were not obtained, in breach of data protection rules. | IT | Garante | GDPR | €200,000 | ↗ |
| 17 Jan 2023 | Hälso- och sjukvårdsnämnden i Region DalarnaHälso- och sjukvårdsnämnden i Region Dalarna was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security when sending physical appointment letters. The authority found this did not meet the requirements of Article 32 GDPR. | SE | IMY | GDPR | kr 200,000 | ↗ |
| 01 Jan 2023 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 200,000 by the AEPD for issuing a duplicate SIM card to a third party without the complainant's consent. The incident enabled unauthorized access to personal and banking data, indicating a serious data protection failure. | ES | AEPD | GDPR | €200,000 | ↗ |
| 17 Apr 2023 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD 200,000 EUR for a data protection breach involving unauthorized SIM card duplication. The incident led to identity theft and fraudulent bank charges. | ES | AEPD | GDPR | €200,000 | ↗ |
| 14 Aug 2024 | Vejen KommuneVejen Kommune was fined by Datatilsynet for insufficient security measures after stolen computers containing children's data were found to be unencrypted. The case also revealed up to 300 other unencrypted computers in the municipality. | DK | Datatilsynet | GDPR | €26,802 | ↗ |
| 14 Jan 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 200,000 for continuing to send emails to a complainant despite earlier sanctions for similar conduct. The authority treated this as a recurring breach of GDPR Article 6.1, indicating processing without a valid legal basis. | ES | AEPD | GDPR | €200,000 | ↗ |
| 10 Jan 2026 | DÉCIMAS, S.L.DÉCIMAS, S.L. was fined by the AEPD in the amount of EUR 200,000 for a personal data breach. The incident exposed personal data and breached GDPR Article 5(1)(f). | ES | AEPD | GDPR | €200,000 | ↗ |
| 10 Mar 2023 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the customer's consent. The action enabled unauthorized bank transactions, indicating a serious breach of data protection and authentication security. | ES | AEPD | GDPR | €200,000 | ↗ |
| 23 Feb 2023 | TársasházThe NAIH imposed a 200,000 HUF fine on Társasház for GDPR breaches linked to its electronic surveillance system. The authority found deficiencies in the processing purposes, legal basis, and information provided to data subjects. | HU | NAIH | GDPR | €524 | ↗ |
| 09 Jul 2020 | Merlini s.r.l.Merlini s.r.l. was fined 200,000 EUR by the Garante. The authority found that the collection of potential clients' personal data did not comply with GDPR consent requirements and that call-center activities were carried out outside the telemarketing procedures established by Wind Tre. | IT | Garante | GDPR | €200,000 | ↗ |
| 12 Feb 2015 | Enel Energia S.p.a.Enel Energia S.p.a. was fined by the Garante 200,000 EUR for failing to provide information and obtain consent for processing personal data for promotional purposes. The breach affected a large database of approximately 43.1 million contacts. | IT | Garante | GDPR | €200,000 | ↗ |
| 18 Mar 2023 | TOTALENERGIES CLIENTES, S.A.TOTALENERGIES CLIENTES, S.A. was fined EUR 200,000 by the AEPD for linking a customer’s personal data to a third party during gas supply service registration. The authority found this breached data protection principles. | ES | AEPD | GDPR | €200,000 | ↗ |