BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Jan 2024 | International Card Services B.V.International Card Services B.V. was fined by the Dutch AP in the amount of EUR 150,000. The company failed to carry out a Data Protection Impact Assessment (DPIA) before implementing a customer identification and verification process, in breach of Article 35 GDPR. | NL | AP | GDPR | €150,000 | ↗ |
| 22 Feb 2024 | Sigma s.r.l.Sigma s.r.l. was fined EUR 150,000 by the Garante for unauthorized activation of paid services and devices using customer data without consent. The authority found that the company’s conduct breached GDPR rules on personal data processing. | IT | Garante | GDPR | €150,000 | ↗ |
| 22 Jun 2021 | VirksomhetenThe Norwegian DPA fined Virksomheten NOK 150,000 for accessing a former employee’s email account without a legal basis and for failing to close the account. The authority found breaches of GDPR rules on information duties, data deletion, and handling objections. | NO | Datatilsynet | GDPR | €14,678 | ↗ |
| 26 Sept 2024 | SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA FOURNITURE DE SERVICES INFORMATIQUES ET NUMERIQUESCNIL imposed an administrative fine of EUR 150,000 on SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA FOURNITURE DE SERVICES INFORMATIQUES ET NUMERIQUES. The decision was issued on 26 September 2024. | FR | CNIL | GDPR | €150,000 | ↗ |
| 09 Oct 2018 | CosmoteCosmote was fined EUR 150,000 by the HDPA for making unsolicited promotional calls to subscribers who had opted out of such contact. The authority found that this conduct breached privacy and personal data protection rules. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 01 Nov 2018 | UWVThe Dutch Data Protection Authority imposed a penalty on UWV for failing to implement multi-factor authentication in its employer portal. The authority found this breached Article 32 GDPR on appropriate data security measures. | NL | AP | GDPR | €150,000 | ↗ |
| 04 Aug 2020 | PrivatBo A.M.B.A. af 1993PrivatBo was reported to the police, and Datatilsynet recommended a fine of 150,000 DKK for inadequate data security measures. The incident led to the unintended disclosure of tenants' confidential information on USB drives. | DK | Datatilsynet | GDPR | €20,145 | ↗ |
| 25 Feb 2020 | Addiko Bank d.d.The High Administrative Court of the Republic of Croatia upheld AZOP’s decision of 25 February 2020 against Addiko Bank d.d. The confirmed administrative fine was 145,995.09 EUR for obstructing customers’ access to their personal data and credit documentation. | HR | AZOP | GDPR | €145,000 | ↗ |
| 18 Apr 2023 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 140,000 EUR for a data protection breach involving incorrect billing information. A customer's mobile line was charged under another person's name, indicating an error in the processing of personal data. | ES | AEPD | GDPR | €140,000 | ↗ |
| 12 Jan 2024 | Grocery Delivery E-Services UK Ltd t/a HelloFreshThe ICO fined Grocery Delivery E-Services UK Ltd t/a HelloFresh 140,000 GBP for sending 79 million spam emails and 1 million spam texts over seven months. The marketing consent was inadequate because it did not mention text messages and was bundled with an age confirmation statement that may have unfairly encouraged agreement. Customers were also not clearly told that their data would continue to be used for marketing for up to 24 months after cancelling subscriptions. | GB | ICO | GDPR | €162,000 | ↗ |
| 01 Mar 2022 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for failing to adequately prevent unauthorized SIM card duplication. The incident enabled fraudulent access and transactions on a customer's accounts. | ES | AEPD | GDPR | €140,000 | ↗ |
| 01 Jan 2024 | ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. was fined by the AEPD EUR 140,000 for unauthorized access to personal data. The authority found a breach of GDPR confidentiality and security principles. | ES | AEPD | GDPR | €140,000 | ↗ |
| 29 Apr 2026 | DIGI SPAIN TELECOM, S.L.U.DIGI SPAIN TELECOM, S.L.U. was fined by the AEPD 140,000 EUR for processing personal data without a legal basis. The case concerned a SIM card duplication incident that resulted in unauthorized data processing. | ES | AEPD | GDPR | €140,000 | ↗ |
| 09 Feb 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined by the AEPD for unlawfully processing personal data and for failing to provide access to personal data requested by a former client. The case concerns non-compliance with data protection obligations. | ES | AEPD | GDPR | €140,000 | ↗ |
| 25 Jan 2018 | Scaramuzza MarioScaramuzza Mario was fined EUR 140,000 by the Garante for the unauthorized activation of multiple payment cards using personal data without the consent of the individuals concerned. The case indicates a breach of lawful processing requirements and the absence of a valid legal basis. | IT | Garante | GDPR | €140,000 | ↗ |
| 01 Jan 2023 | GENERAL LOGISTICS SYSTEMS SPAIN, S.A.GENERAL LOGISTICS SYSTEMS SPAIN, S.A. was fined by the AEPD 140,000 EUR for processing the personal data of two complainants without proper authorization. The breach resulted in identity theft and misuse of personal data. | ES | AEPD | GDPR | €140,000 | ↗ |
| 11 Jan 2021 | Dane anonimowe (M. S.A. z siedzibą w Z. przy ul.)The President of UODO imposed an administrative fine of PLN 136,437 on M. S.A. The penalty was issued because the company did not report a personal data breach to the supervisory authority without undue delay. | PL | UODO | GDPR | €30,123 | ↗ |
| 18 Dec 2024 | Toyota Bank Polska S.A.The Polish supervisory authority imposed an administrative fine of EUR 132,000 on Toyota Bank Polska S.A. on 18 December 2024. The penalty concerned breaches of GDPR Articles 30, 35, and 38, including DPO independence, profiling documentation, and DPIA obligations. | PL | President of the Personal Data Protection Office (UODO) | GDPR | €132,000 | ↗ |
| 18 Jun 2015 | Wind Telecomunicazioni SpaWind Telecomunicazioni Spa was fined EUR 130,000 by the Garante. The case concerned the unlawful disclosure of mobile phone numbers in the White Pages directory without proper consent. | IT | Garante | GDPR | €130,000 | ↗ |
| 02 Oct 2014 | Addressvitt s.r.l.Addressvitt s.r.l. was fined by the Garante in the amount of EUR 130,000 for processing personal data without providing adequate information or obtaining consent. The case also involved data taken from public telephone directories and used without proper authorization. | IT | Garante | GDPR | €130,000 | ↗ |