Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Apr 2018MTS s.r.l.s.MTS s.r.l.s. was fined EUR 76,000 by the Garante for making unsolicited promotional calls. The company also failed to respond to the authority's request for information, which constituted a data protection breach.ITGaranteGDPR€76,000
16 Sept 2021Barilla G. e R. fratelli S.p.A.Barilla G. e R. fratelli S.p.A. was fined by the Garante EUR 75,000 for violations linked to the use of a video surveillance system at its operational site. The system did not comply with data protection requirements.ITGaranteGDPR€75,000
22 Feb 2024Azienda Usl Valle d’AostaThe Garante imposed a EUR 75,000 fine on Azienda Usl Valle d’Aosta for unauthorized access to patient health records. Healthcare professionals who were not involved in the patients’ care accessed the data, breaching GDPR data protection requirements.ITGaranteGDPR€75,000
15 Apr 2021Clear Channel Italia S.p.A.Clear Channel Italia S.p.A. was fined by the Garante EUR 75,000 for conducting intrusive checks on employees’ devices without a proper legal basis. The authority found breaches of data minimization and proportionality principles.ITGaranteGDPR€75,000
30 Mar 2021TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 75,000 EUR for using a customer's phone number without consent. This led to numerous unsolicited calls, despite prior claims that security measures had been implemented.ESAEPDGDPR€75,000
29 Nov 2019Vodafone España, S.A.U.Vodafone España, S.A.U. was fined EUR 75,000 by the AEPD for continuing to send communications to a complainant after a request for data deletion. The issue was caused by an IT error that left the complainant’s email address in the system.ESAEPDGDPR€75,000
24 Mar 2025Komendant Główny PolicjiThe President of the Polish data protection authority imposed an administrative fine of PLN 75,000 on the Commander-in-Chief of the Police. The authority found that, during a press conference, personal data and health information of a woman were disclosed without a legal basis.PLUrząd Ochrony Danych OsobowychGDPR€17,960
24 Jun 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 75,000 EUR for continuing to send promotional SMS messages to an individual whose personal data had previously been deleted. The authority found this conduct to be in breach of Article 6 GDPR.ESAEPDGDPR€75,000
06 Sept 2012BT Italia s.p.a.BT Italia s.p.a. was fined by the Garante EUR 75,000 for sending unsolicited promotional faxes without recipient consent. The conduct breached data protection and direct marketing rules.ITGaranteGDPR€75,000
19 Mar 2025Komendanta Głównego PolicjiUODO imposed an administrative fine of PLN 75,000 on the Chief Police Commander. The decision was based on breaches of Article 6(1) and Article 9(1) of Regulation 2016/679 concerning the processing of personal data and special-category data.PLUODOGDPR€17,906
05 Feb 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 75,000 by the AEPD for processing personal data without a legal basis. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€75,000
12 May 2017Strategy MentorThe fine was imposed for sending unsolicited marketing emails to a large number of recipients without prior consent. This conduct breached ePrivacy rules governing electronic marketing communications.GRHDPAePrivacy€75,000
12 Oct 2023S.T.A. Società Trattamento Acque s.r.l.S.T.A. Società Trattamento Acque s.r.l. was fined €75,000 by the Garante. The authority found a breach of Article 15 GDPR after the company failed to respond to an employee's request for access to professional training records.ITGaranteGDPR€75,000
18 Jul 2023Università Telematica E-CampusUniversità Telematica E-Campus was fined EUR 75,000 by the Garante. The authority found that the university sent promotional SMS messages without consent and failed to respond to data deletion requests. These actions breached GDPR requirements.ITGaranteGDPR€75,000
18 Feb 2020Equifax Iberica, S.L.Equifax Iberica, S.L. was fined by the AEPD in the amount of 75,000 EUR for processing personal data without a proper legal basis. The authority cited a breach of Article 6(1)(f) of the GDPR.ESAEPDGDPR€75,000
29 Sept 2021Kræftens BekæmpelseKræftens Bekæmpelse was fined by Datatilsynet 75,000 DKK for inadequate protection of sensitive health data. The incident affected at least 1,448 individuals and resulted from missing security measures that allowed unauthorized access to personal data.DKDatatilsynetGDPR€10,086
17 Oct 2019VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España, S.A.U. EUR 75,000 for incorrectly charging a customer's account and retaining inaccurate personal data. The case concerns breaches of data protection principles, including data accuracy and proper processing.ESAEPDGDPR€75,000
03 Dec 2020Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD 75,000 EUR for failing to properly verify the identity of individuals requesting changes in line ownership. This failure resulted in unauthorized access and processing of personal data.ESAEPDGDPR€75,000
26 Nov 2019EDP COMERCIALIZADORA, S.A.U.EDP COMERCIALIZADORA, S.A.U. was fined by the AEPD 75,000 EUR for processing personal data without consent. The case involved data linked to a gas contract unrelated to the complainant, which breached Article 6(1) of the GDPR.ESAEPDGDPR€75,000
04 Sept 2025SOCIETE EXERCANT UNE ACTIVITE DE GRANDE DISTRIBUTIONThe CNIL imposed an administrative fine of EUR 75,000 on SOCIETE EXERCANT UNE ACTIVITE DE GRANDE DISTRIBUTION and issued an injunction. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€75,000