BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Apr 2023 | Green Network S.p.a.Green Network S.p.a. was fined by the Garante for illegal telemarketing practices in the energy sector. The authority found a breach of data protection principles. | IT | Garante | GDPR | €237,000 | ↗ |
| 12 May 2021 | xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure. | HR | AZOP | GDPR | €30,553 | ↗ |
| 05 Apr 2018 | I Tel s.r.l.I Tel s.r.l. was fined EUR 230,000 by the Italian data protection authority, Garante. The case concerned the registration of phone cards to 23 individuals without their consent, in breach of data protection rules. | IT | Garante | GDPR | €230,000 | ↗ |
| 21 Feb 2013 | Elettrodomestici Parise sncElettrodomestici Parise snc was fined 222,000 EUR by the Italian Garante. The company improperly registered numerous phone cards to unaware third parties and then sold them to phone centers, breaching data protection rules. | IT | Garante | GDPR | €222,000 | ↗ |
| 01 Jan 2025 | Εθνική Τράπεζα της Ελλάδος Α.Ε.The data protection authority imposed a EUR 220,000 fine on Εθνική Τράπεζα της Ελλάδος Α.Ε. for a GDPR violation. The case concerned deficiencies in personal data protection and compliance with GDPR requirements. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €220,000 | ↗ |
| 01 Jan 2024 | GESTERNOVA, S.A.GESTERNOVA, S.A. was fined by the AEPD in the amount of 220,000 EUR for processing personal data without a valid legal basis. The authority also found that the company failed to provide the required information to the data subject, in breach of GDPR Articles 6(1), 13, and 14. | ES | AEPD | GDPR | €220,000 | ↗ |
| 26 Apr 2023 | CARTONAJES BAÑERES, S.A.CARTONAJES BAÑERES, S.A. was fined by the AEPD 220,000 EUR for processing biometric data without the required data protection impact assessment. The authority also found a failure to comply with data subjects’ access rights. | ES | AEPD | GDPR | €220,000 | ↗ |
| 16 Oct 2019 | Dane anonimowe (S. Sp. z o.o. z siedzibą w P., karę pieniężną w kwocie 201 559,50 PLN)UODO imposed a fine of PLN 201,559.50 on S. Sp. z o.o. for failing to implement appropriate technical and organizational measures. The authority also found that personal data were processed without a lawful basis, which led to the sanction. | PL | UODO | GDPR | €46,923 | ↗ |
| 21 Sept 2023 | F12 Management LtdF12 Management Ltd made 1,346,019 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a £200,000 fine and issued an enforcement notice. | GB | ICO | ePrivacy | €230,000 | ↗ |
| 15 Feb 2023 | It's OK LimitedBetween 1 July 2019 and 1 June 2020, It's OK Limited made 1,752,149 unsolicited direct marketing calls to subscribers who had been registered with the TPS for at least 28 days. The company had no evidence that the recipients had not objected to receiving such calls, breaching regulation 21 of PECR. | GB | ICO | ePrivacy | €225,000 | ↗ |
| 08 Jun 2020 | Volt munkavállaló munkavégzési célú elektronikus leveleihez való hozzáféréseThe controller unlawfully denied access to the complainant's archived personal emails from 2018. It also failed to provide transparent information about the actions taken in response to the data subject's request. | HU | NAIH | GDPR | €582 | ↗ |
| 01 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the original user's consent. The incident led to unauthorized access to personal and banking data. | ES | AEPD | GDPR | €200,000 | ↗ |
| 28 Aug 2024 | SOCIETE SPECIALISEE DANS LA GESTION DES FLUX DE DONNEES DE SANTEThe CNIL imposed an administrative fine of EUR 200,000 on SOCIETE SPECIALISEE DANS LA GESTION DES FLUX DE DONNEES DE SANTE. The case concerns a breach of data protection rules supervised by the French authority. | FR | CNIL | GDPR | €200,000 | ↗ |
| 16 Mar 2023 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for failing to implement adequate security measures. A SIM card duplication enabled unauthorized access to a customer’s personal data and financial accounts. | ES | AEPD | GDPR | €200,000 | ↗ |
| 12 Oct 2023 | Onda Più S.r.l.Onda Più S.r.l. was fined EUR 200,000 by the Garante for activating energy supply contracts without customer consent. The authority also found the use of inaccurate and outdated personal data. | IT | Garante | GDPR | €200,000 | ↗ |
| 21 Jun 2021 | GSMA LTD.GSMA LTD. was fined by the AEPD for requiring biometric data, including passport details and photos, for facial recognition at the Mobile World Congress without a valid legal basis. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 11 Mar 2025 | UNIÓN DE CRÉDITO PARA LA FINANC. MOB. E INMOB., CREDIFIMO, E.F.C., SAUCREDIFIMO was fined by the AEPD for unlawfully processing personal data by including an individual's data in a credit file without a lawful basis. The authority found a breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 19 Mar 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for failing to verify the identity of a person who obtained a SIM duplicate. This omission led to unauthorized transactions and was treated as a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 03 Feb 2021 | Cyberbook ASCyberbook AS was fined 200,000 NOK by Datatilsynet for unlawfully forwarding a former employee's emails without informing them. The authority found breaches of GDPR requirements on legal basis, information duties, and data deletion. | NO | Datatilsynet | GDPR | €19,316 | ↗ |
| 03 Apr 2023 | HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined EUR 200,000 by the AEPD for insufficient security measures in its hospital information system. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational safeguards. | ES | AEPD | GDPR | €200,000 | ↗ |