BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Mar 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 150,000 EUR for failing to delete personal data after phone contracts ended. This led to continued SMS notifications with zero-balance invoices being sent to former customers. | ES | AEPD | GDPR | €150,000 | ↗ |
| 04 Nov 2019 | Coöperatie Menzis U.A.The Dutch Data Protection Authority, AP, imposed a fine of EUR 150,000 on Coöperatie Menzis U.A. The authority found that the company had inadequate technical measures to prevent unauthorized access to personal health data. | NL | AP | GDPR | €150,000 | ↗ |
| 30 Jul 2025 | ONEY SERVICIOS FINANCIEROS EFC, S.A.The AEPD fined ONEY Servicios Financieros EFC, S.A. 150,000 EUR for failing to adequately protect personal data. The breach led to a security incident in which a third party accessed a customer's account through a vishing attack. | ES | AEPD | GDPR | €150,000 | ↗ |
| 13 Apr 2023 | Sociale verzekeringsbankThe Dutch AP fined Sociale verzekeringsbank EUR 150,000. The authority found that the organization failed to implement adequate technical and organizational measures to ensure a risk-appropriate level of security when processing personal data during telephone contact with AOW beneficiaries, in breach of GDPR Article 32. | NL | AP | GDPR | €150,000 | ↗ |
| 09 Oct 2019 | Vreau Credit S.R.L.Vreau Credit S.R.L. was fined by ANSPDCP for failing to notify the supervisory authority of a data breach without undue delay and for unauthorized processing of personal data. The violations resulted in a loss of data confidentiality and indicate inadequate compliance controls. | RO | ANSPDCP | GDPR | €150,000 | ↗ |
| 16 Jan 2024 | Poxell LtdThe ICO found that Poxell Ltd made 2,647,805 unsolicited direct marketing calls between 31 March 2022 and 20 July 2022, breaching regulations 21 and 24 of PECR. This led to 413 complaints to the ICO and TPS, with recipients reporting persistent calls about energy-related products and home improvements. | GB | ICO | ePrivacy | €174,000 | ↗ |
| 31 Mar 2021 | ORANGE ESPAGNE, S.A.U.Orange Espagne, S.A.U. was fined by the AEPD 150,000 EUR for violations related to direct marketing communications. The case concerned conduct that may have breached data protection rules. | ES | AEPD | ePrivacy | €150,000 | ↗ |
| 09 Nov 2023 | Complete Marketing Services LtdBetween 8 June 2021 and 4 February 2022, Complete Marketing Services Ltd instigated 242,497 unsolicited direct marketing calls in breach of PECR. The ICO became aware of the matter after complaints about live marketing calls relating to road traffic accidents and personal injury claims were reported via the TPS. | GB | ICO | ePrivacy | €172,000 | ↗ |
| 09 Oct 2018 | WIND HELLAS TELECOMMUNICATIONS S.A.The fine was imposed for making unsolicited marketing calls to subscribers who had opted out of such contact. This conduct breached privacy and data protection rules. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 09 Jul 2025 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 150,000 EUR for issuing a SIM card duplicate without proper consent. The incident led to unauthorized bank transfers and involved processing personal data without a lawful basis. | ES | AEPD | GDPR | €150,000 | ↗ |
| 11 Apr 2023 | SOCIEDAD VASCONGADA DE PUBLICACIONES, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. AEPD found that this breached the data minimization principle. | ES | AEPD | GDPR | €150,000 | ↗ |
| 04 Nov 2019 | Coöperatie VGZ U.A.The Autoriteit Persoonsgegevens imposed a EUR 150,000 penalty on Coöperatie VGZ U.A. for failing to implement appropriate technical measures to protect personal data from unauthorized access. The authority found a breach of data protection law. | NL | AP | GDPR | €150,000 | ↗ |
| 01 Jan 2025 | RaiItaly’s data protection authority fined Rai EUR 150,000 over a Report broadcast on 8 December 2024 that disclosed a private conversation. The case concerns unlawful processing of personal data in a television report. | IT | Garante per la protezione dei dati personali | GDPR | €150,000 | ↗ |
| 04 Mar 2021 | Anonymizováno (ÚOOÚ UOOU-02022/20-24)The entity was fined for unauthorized publication of personal data of thirty individuals on a website. The authority found a breach of the basic principles of personal data processing under GDPR. | CZ | UOOU | GDPR | €5,724 | ↗ |
| 11 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD EUR 150,000 for processing personal data without proper authorization. The case involved a fraudulent contract created using the complainant’s identity, and the authority found that the company did not adequately verify the identity of the person entering into the contract. | ES | AEPD | GDPR | €150,000 | ↗ |
| 16 Sept 2021 | Università Commerciale “Luigi Bocconi” di MilanoUniversità Commerciale “Luigi Bocconi” di Milano was fined EUR 150,000 by the Garante for data protection breaches during remote exams. The authority found an insufficient legal basis, inadequate transparency, and weak security measures for transfers of data to the USA. | IT | Garante | GDPR | €150,000 | ↗ |
| 09 Aug 2013 | General Secretariat for Information SystemsThe General Secretariat for Information Systems was fined EUR 150,000 by the HDPA for failing to implement appropriate security measures. The breach led to unauthorized processing of Greek taxpayers’ personal tax data from 2000 to 2012. | GR | HDPA | GDPR | €150,000 | ↗ |
| 09 Oct 2018 | OTEThe Hellenic Data Protection Authority imposed a fine of EUR 150,000 on OTE. The case concerned unsolicited promotional calls made to subscribers who had previously opted out of such contact. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 08 Jun 2023 | SOCIÉTÉ DE VOYANCECNIL imposed a fine of EUR 150,000 on SOCIÉTÉ DE VOYANCE. The case concerns a regulatory breach, with no further details provided on the specific nature of the violation. | FR | CNIL | GDPR | €150,000 | ↗ |
| 11 Sept 2024 | Universitetet i AgderThe Norwegian DPA, Datatilsynet, fined the University of Agder 150,000 NOK for failing to implement adequate measures to protect personal data in Microsoft Teams. The incident exposed sensitive information relating to around 16,000 individuals. | NO | Datatilsynet | GDPR | €12,566 | ↗ |