BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Nov 2014 | One Italia s.r.l.One Italia s.r.l. was fined €200,000 by the Garante for sending unsolicited promotional messages related to a value-added service. The authority found that proper consent and adequate information were not obtained, in breach of data protection rules. | IT | Garante | GDPR | €200,000 | ↗ |
| 17 Jan 2023 | Hälso- och sjukvårdsnämnden i Region DalarnaHälso- och sjukvårdsnämnden i Region Dalarna was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security when sending physical appointment letters. The authority found this did not meet the requirements of Article 32 GDPR. | SE | IMY | GDPR | kr 200,000 | ↗ |
| 01 Jan 2023 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 200,000 by the AEPD for issuing a duplicate SIM card to a third party without the complainant's consent. The incident enabled unauthorized access to personal and banking data, indicating a serious data protection failure. | ES | AEPD | GDPR | €200,000 | ↗ |
| 17 Apr 2023 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD 200,000 EUR for a data protection breach involving unauthorized SIM card duplication. The incident led to identity theft and fraudulent bank charges. | ES | AEPD | GDPR | €200,000 | ↗ |
| 14 Aug 2024 | Vejen KommuneVejen Kommune was fined by Datatilsynet for insufficient security measures after stolen computers containing children's data were found to be unencrypted. The case also revealed up to 300 other unencrypted computers in the municipality. | DK | Datatilsynet | GDPR | €26,802 | ↗ |
| 14 Jan 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 200,000 for continuing to send emails to a complainant despite earlier sanctions for similar conduct. The authority treated this as a recurring breach of GDPR Article 6.1, indicating processing without a valid legal basis. | ES | AEPD | GDPR | €200,000 | ↗ |
| 10 Jan 2026 | DÉCIMAS, S.L.DÉCIMAS, S.L. was fined by the AEPD in the amount of EUR 200,000 for a personal data breach. The incident exposed personal data and breached GDPR Article 5(1)(f). | ES | AEPD | GDPR | €200,000 | ↗ |
| 10 Mar 2023 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the customer's consent. The action enabled unauthorized bank transactions, indicating a serious breach of data protection and authentication security. | ES | AEPD | GDPR | €200,000 | ↗ |
| 23 Feb 2023 | TársasházThe NAIH imposed a 200,000 HUF fine on Társasház for GDPR breaches linked to its electronic surveillance system. The authority found deficiencies in the processing purposes, legal basis, and information provided to data subjects. | HU | NAIH | GDPR | €524 | ↗ |
| 09 Jul 2020 | Merlini s.r.l.Merlini s.r.l. was fined 200,000 EUR by the Garante. The authority found that the collection of potential clients' personal data did not comply with GDPR consent requirements and that call-center activities were carried out outside the telemarketing procedures established by Wind Tre. | IT | Garante | GDPR | €200,000 | ↗ |
| 12 Feb 2015 | Enel Energia S.p.a.Enel Energia S.p.a. was fined by the Garante 200,000 EUR for failing to provide information and obtain consent for processing personal data for promotional purposes. The breach affected a large database of approximately 43.1 million contacts. | IT | Garante | GDPR | €200,000 | ↗ |
| 18 Mar 2023 | TOTALENERGIES CLIENTES, S.A.TOTALENERGIES CLIENTES, S.A. was fined EUR 200,000 by the AEPD for linking a customer’s personal data to a third party during gas supply service registration. The authority found this breached data protection principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 23 Feb 2023 | Okmánymásolás és fényképek készítése és közzététele munkahelyenThe authority imposed a fine for copying applicants’ identity documents and for failing to provide adequate information to data subjects during the recruitment process. The case concerned breaches of information duties and personal data processing rules in the workplace. | HU | NAIH | GDPR | €524 | ↗ |
| 01 Jun 2023 | NH Italia S.p.A.NH Italia S.p.A. was fined EUR 200,000 by the Garante for failing to appoint specific data processors responsible for the installation and maintenance of video surveillance systems. The authority found this breached the GDPR principles of lawful, fair, and transparent processing of personal data. | IT | Garante | GDPR | €200,000 | ↗ |
| 21 Sept 2023 | Cover Appliance LtdCover Appliance Ltd made 511,499 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of 200,000 GBP and issued an enforcement notice. | GB | ICO | ePrivacy | €230,000 | ↗ |
| 02 Feb 2023 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for changing a customer's contract ownership and activating services without consent. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 26 Apr 2023 | Regionstyrelsen i Region SkåneRegionstyrelsen i Region Skåne was fined by IMY for storing unencrypted sensitive patient data on a USB drive that was lost. The authority found this to be a breach of Article 32 GDPR, which requires appropriate technical and organisational security measures. | SE | IMY | GDPR | €17,566 | ↗ |
| 31 Mar 2016 | avv. Gioacchino GenchiAvv. Gioacchino Genchi was fined by the Italian Garante for creating a database containing personal data, including phone traffic data. The database was accessible to his collaborators, which breached data protection rules. | IT | Garante | GDPR | €192,000 | ↗ |
| 18 Jan 2018 | KRI S.p.A.KRI S.p.A. was fined by the Italian data protection authority, Garante, for failing to notify the cessation of certain personal data processing activities. The case involved geolocation data and profiling, and the required notification was not made under the Italian data protection code. | IT | Garante | GDPR | €180,000 | ↗ |
| 21 Feb 2019 | Anonymizováno (ÚOOÚ UOOU-05185/14-53)The entity was fined by UOOU for publishing information about wiretaps and telecommunications records without consent. The authority treated this as a breach of privacy and personal data protection rules. | CZ | UOOU | GDPR | €7,018 | ↗ |