Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Nov 2025UNIVERSIDADThe university was fined EUR 200,000 by the AEPD for processing special categories of personal data, including biometric data, without proper justification. The authority also found that a data protection impact assessment had not been carried out before implementing online exams.ESAEPDGDPR€200,000
01 Jan 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD 200,000 EUR for making commercial calls to a complainant despite the numbers being on the Robinson list. The case indicates a breach of data protection rules governing direct marketing.ESAEPDGDPR€200,000
21 Jun 2016Česká republika – Ministerstvo školství, mládeže a tělovýchovyThe Czech Republic’s Ministry of Education, Youth and Sports was fined by the UOOU for processing sensitive personal data about students’ disabilities without a legal basis. The case indicates a breach of personal data protection rules and requires review of the lawful basis and data scope.CZUOOUGDPR€7,390
29 Oct 2024TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD for allowing a SIM card to be duplicated without the customer's consent. The incident led to fraudulent activity on the customer's bank account, indicating serious weaknesses in identity verification and security controls.ESAEPDGDPR€200,000
24 Jul 2020I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.UI-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U was fined by the AEPD EUR 200,000 for sending letters to customers without a legal basis. The authority found that this breached the principles of data minimization and purpose limitation.ESAEPDGDPR€200,000
27 May 2021Intesa Sanpaolo s.p.a.Intesa Sanpaolo s.p.a. was fined by the Garante in the amount of 200,000 EUR for unlawfully communicating banking data to an unauthorized third party. The case concerned breaches of data protection principles, including lawfulness and restricted access to information.ITGaranteGDPR€200,000
07 Dec 2023Nirvam S.r.l.Nirvam S.r.l., an online dating platform, was fined 200,000 EUR by the Garante. The authority found inadequate personal data protection measures and GDPR breaches related to data processing and security.ITGaranteGDPR€200,000
05 Dec 2024TMETME was fined EUR 200,000 by the AEPD for changing the ownership of a mobile line without consent and for issuing a duplicate SIM card without a valid legal basis. The authority found that these actions failed to meet the requirements for lawful processing and proper authorization of subscriber account changes.ESAEPDGDPR€200,000
03 Dec 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The AEPD imposed a EUR 200,000 fine on Banco Bilbao Vizcaya Argentaria, S.A. for processing personal data without a legal basis. The conduct included signing documents without consent and marking consent checkboxes for commercial purposes without authorization.ESAEPDGDPR€200,000
22 Jul 2021Regione LombardiaRegione Lombardia was fined by the Garante 200,000 EUR for publishing personal data on its website that could reveal individuals' economic and social hardship. The authority found that this breached GDPR transparency and data protection requirements.ITGaranteGDPR€200,000
06 Oct 2023Texas Andreas Petersen A/SThe Danish Data Protection Authority reported Texas Andreas Petersen A/S to the police and recommended a fine of at least DKK 200,000. The case concerned the collection and sharing of website visitors' personal data without a legal basis.DKDatatilsynetGDPR€26,818
08 Apr 2024IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including personal data in a credit information system without proper notification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€200,000
07 Oct 2019OTEOTE was fined by the HDPA EUR 200,000 for failing to process unsubscribe requests from marketing emails due to a technical error. The issue affected about 8,000 subscribers and had been ongoing since 2013.GRHDPAGDPR€200,000
27 Feb 2023VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for breaching Article 6(1) GDPR after a SIM card was duplicated without consent. The incident enabled unauthorized access to a customer's bank accounts, indicating serious failures in verification and data protection controls.ESAEPDGDPR€200,000
24 Nov 2020LSS-boendeGnosjö kommun - Socialutskottet was fined by IMY for unlawful video surveillance in an LSS residence. The authority found processing of personal and sensitive data without a legal basis and no data protection impact assessment.SEIMYGDPR€19,600
11 Dec 2024Granit Bostad Beritsholm ABGranit Bostad Beritsholm AB was fined by IMY for conducting video surveillance without a lawful basis. The authority also found that required information was not provided to affected individuals, constituting a GDPR breach.SEIMYGDPR€17,366
20 Aug 2019Gymnasienämnden i Skellefteå kommunGymnasienämnden i Skellefteå kommun was fined by IMY for using facial recognition to record student attendance. The authority found that the processing was more intrusive than necessary and lacked a valid exception for biometric data.SEIMYGDPR€18,578
05 Dec 2024KASPRThe CNIL imposed an administrative fine of EUR 200,000 on KASPR on 5 December 2024. The authority found GDPR breaches relating to lawful basis, retention, transparency, information, and access rights in connection with KASPR's data scraping activities.FRCNILGDPR€200,000
07 Oct 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for unauthorized remote management of a former employee's personal device. The authority found that the conduct breached the principles of lawful personal data processing.ESAEPDGDPR€200,000
13 Sept 2024ARES CAPITAL, S.A.ARES CAPITAL, S.A. was fined by the AEPD for requiring employees to use personal phones for work together with continuous monitoring apps. The authority found that the company did not provide sufficient information about data collection, breaching GDPR rules on lawful basis, transparency, and data processing principles.ESAEPDGDPR€200,000