BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Apr 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for including personal data in a credit solvency file without proper prior notice. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 05 Dec 2024 | ESL Consultancy Services Ltd Between 15 September 2022 and 5 December 2023, 37,977 complaints were received about direct marketing messages sent at the instigation of ESL Consultancy Services Ltd. The ICO fined the company GBP 200,000 and issued an enforcement notice. | GB | ICO | GDPR | €241,000 | ↗ |
| 07 Jan 2022 | Elektro & Automasjon Systemer ASElektro & Automasjon Systemer AS was fined NOK 200,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The company checked a co-owner of another company despite having no business relationship or justification for the credit check. | NO | Datatilsynet | GDPR | €19,942 | ↗ |
| 06 Feb 2023 | VODAFONE ESPAÑA, S.A.U.The AEPD imposed a 200,000 EUR fine on VODAFONE ESPAÑA, S.A.U. for breaching Article 6(1) GDPR. The case involved unauthorized SIM card duplication that enabled fraudulent bank charges. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 200,000 EUR by the AEPD for issuing a duplicate SIM card without the customer’s consent. The incident led to unauthorized financial transactions, indicating significant failures in authorization and security controls. | ES | AEPD | GDPR | €200,000 | ↗ |
| 16 Sept 2025 | Bharat Singh ChandBharat Singh Chand, a self-employed lead generator, sent or instigated the sending of 966,449 direct marketing SMS messages between 3 December 2023 and 3 July 2024. The activity breached regulations 22 and 23 of PECR and generated 19,138 complaints to the 7726 spam reporting service. He was fined £200,000 and issued with an enforcement notice. | GB | ICO | ePrivacy | €231,000 | ↗ |
| 11 Apr 2023 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 200,000 for failing to remove personal data from a credit information system after the debt was sold. The authority found that the continued processing of the data was not compliant with data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 18 Sept 2023 | SOCIETE DE TRANSPORT DE FRET AERIENCNIL imposed a fine of EUR 200,000 on SOCIETE DE TRANSPORT DE FRET AERIEN. The case concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €200,000 | ↗ |
| 09 Jan 2023 | TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR after a SIM swapping incident enabled unauthorized bank transactions. The authority found a breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 15 Jul 2024 | ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD 200,000 EUR for failing to properly handle a data subject’s request for deletion and for processing personal data without a legal basis. The case concerns breaches of core data protection obligations. | ES | AEPD | GDPR | €200,000 | ↗ |
| 19 Feb 2024 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 200,000 by the AEPD for processing personal data without a legal basis. The case concerned a phone number portability carried out without the user's consent, which breached the requirement for lawful processing. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | ENDESA ENERGIA, S.A.U.ENDESA ENERGIA, S.A.U. was fined €200,000 by the AEPD for changing the contract holder and bank account without consent. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | CAIXABANK, S.A.CAIXABANK was fined by the AEPD for sending a privacy policy update to a non-client. The authority found that the stated legitimate-interest basis for processing did not have proper consent support. | ES | AEPD | GDPR | €200,000 | ↗ |
| 03 Apr 2023 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including an individual's data in a creditworthiness file without a lawful basis. The authority found this conduct violated Article 6 of the GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 25 Feb 2025 | SERVICIOS ESPECIALES, S.A.SERVICIOS ESPECIALES, S.A. was fined by the AEPD 200,000 EUR for disclosing the identity of a complainant in a workplace harassment case. The authority found a breach of personal data confidentiality principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 22 Jan 2024 | Hvidovre KommuneHvidovre Kommune was fined by Datatilsynet for failing to maintain an appropriate level of security. The issue allowed unauthorized access to protected addresses of children through the municipal dental service's self-service solution, which incorrectly extended access to both custodial parents. | DK | Datatilsynet | GDPR | €26,816 | ↗ |
| 11 Aug 2022 | Lakásszövetkezeti adatközlő lapon gyűjtött személyes adatokThe entity was fined for requiring housing cooperative members to provide unnecessary personal data and for giving inadequate information about data processing. The authority found violations of GDPR Articles 6 and 13. | HU | NAIH | GDPR | €508 | ↗ |
| 01 Jan 2024 | VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España 200,000 EUR for processing personal data without meeting the legal requirements of Article 6(1) GDPR. The case was linked to a fraudulent SIM card swap that resulted in unauthorized bank transfers. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for processing personal data without consent. The case involved duplicating a SIM card without the user's authorization, which led to unauthorized bank transactions. | ES | AEPD | GDPR | €200,000 | ↗ |
| 27 Jul 2021 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for failing to implement adequate security measures to verify the identity of customers accessing sensitive information through an automated phone system. The authority found a breach of data integrity and confidentiality principles. | ES | AEPD | GDPR | €200,000 | ↗ |