Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jun 2021Ministero dell’InternoThe Italian Data Protection Authority fined Ministero dell’Interno EUR 75,000 for posting videos on social media that breached data protection rules. The footage related to a criminal case was shared by the police and contained violent content, which was found inconsistent with data protection principles.ITGaranteGDPR€75,000
18 Jun 2025Waxholms Ångfartygs AB (WÅAB)IMY fined Waxholms Ångfartygs AB SEK 75,000 for processing personal data without a lawful basis. The authority also found processing of sensitive personal data without an applicable exception, in breach of GDPR Articles 6 and 9.SEIMYGDPR€6,802
04 Feb 2020TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined 75,000 EUR by the AEPD for processing personal data without consent. The case concerned unauthorized portability of a phone line.ESAEPDGDPR€75,000
12 Jun 2014H3g s.p.a.H3g s.p.a. was fined EUR 75,000 by the Garante for violations related to customer profiling without the required consent. The case concerned personal data processing that did not comply with data protection requirements.ITGaranteGDPR€75,000
07 Aug 2020TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 75,000 EUR for unauthorized access to a customer's data and harassment through excessive calls and messages. The case indicates failures in data protection controls and customer contact practices.ESAEPDGDPR€75,000
17 May 2021TELEFÓNICA DE ESPAÑA, S.A.U.Telefónica de España, S.A.U. was fined by the AEPD for using personal data to contract a service without the data subject’s consent and for listing the complainant in credit information files for a debt that was not recognized. The case concerns processing without a valid legal basis and improper reporting of alleged debt.ESAEPDGDPR€75,000
01 Jan 2019EDP ENERGÍA, S.A.U.EDP ENERGÍA, S.A.U. was fined by the AEPD EUR 75,000 for processing personal data without consent. The case concerned an energy contract to which the complainant was not a party, constituting a breach of Article 6(1) GDPR.ESAEPDGDPR€75,000
20 Jul 2020Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD €75,000 for charging a complainant for services linked to a third-party mobile number without consent. The authority found a breach of Article 6(1) GDPR because there was no lawful basis for the processing and related charges.ESAEPDGDPR€75,000
01 Jan 2019Vodafone España, S.A.U.Vodafone España, S.A.U. was fined EUR 75,000 by the AEPD for a data protection breach. The case involved unauthorized contract portability using a customer's personal data without consent.ESAEPDGDPR€75,000
29 Dec 2023SOCIETE DE SITES EN LIGNE DE JEUX-CONCOURS ET TESTS PRODUITSCNIL imposed a fine of 75,000 EUR on SOCIETE DE SITES EN LIGNE DE JEUX-CONCOURS ET TESTS PRODUITS and issued an injunction. The case concerns identified breaches of rules supervised by CNIL.FRCNILGDPR€75,000
18 Jun 2025Aktiebolaget Storstockholms Lokaltrafik (SL)Aktiebolaget Storstockholms Lokaltrafik (SL) was fined 75,000 SEK by IMY for processing personal data without a legal basis and special-category data without a valid exception. The authority found breaches of GDPR Articles 6 and 9.SEIMYGDPR€6,802
16 Sept 2021Favrskov KommuneFavrskov Kommune was fined 75,000 DKK for failing to implement appropriate security measures, including encryption, to protect sensitive personal data on a stolen laptop. The authority found a breach of GDPR Article 32.DKDatatilsynetGDPR€10,086
22 Oct 2019IBERDROLA COMERCIALIZACIÓN DE ÚLTIMO RECURSO, S.A.U. (CURENERGIA COMERCIALIZADORA DE ULTIMO RECURSO, S.A.U.)CURENERGIA was fined EUR 75,000 by the AEPD for using a former client's personal data without consent. The data was used to carry out a fraudulent contract registration. The case indicates a breach of lawful processing and personal data protection requirements.ESAEPDGDPR€75,000
11 Feb 2021Ministero dello Sviluppo EconomicoThe Ministry of Economic Development was fined by the Garante for publishing personal data, including managers' CVs, on its institutional website without a proper legal basis. The authority found this conduct to be in breach of GDPR requirements.ITGaranteGDPR€75,000
15 Dec 2016Ordinanza ingiunzione - 15 dicembre 2016 [6526145]The Garante imposed a EUR 72,000 fine for sending promotional SMS messages without the recipients’ consent. The contact data came from a database obtained through agreements with a German company, which involved the transfer of personal data abroad.ITGaranteGDPR€72,000
23 Feb 2017Lucini & Lucini Communication LtdLucini & Lucini Communication Ltd was fined EUR 72,000 by the Garante. The authority found that the company collected personal data through its websites and sent promotional emails without proper consent.ITGaranteGDPR€72,000
04 Nov 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 70,000 EUR for processing a fraudulent phone number portability request without the data subject's consent. The authority found a breach of GDPR Article 6(1).ESAEPDGDPR€70,000
29 Jan 2024IDFINANCE SPAIN, S.A.U.The AEPD fined IDFINANCE SPAIN, S.A.U. 70,000 EUR for including personal data in credit information systems in connection with a disputed debt. The authority found that the processing breached Article 6 GDPR.ESAEPDGDPR€70,000
23 Apr 2021Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without proper consent. The case involved a call to a customer about a service package that the customer had not authorized.ESAEPDGDPR€70,000
06 Jun 2024WORLD 2 MEET, S.L.WORLD 2 MEET, S.L. was fined EUR 70,000 by the AEPD for requesting excessive personal data from guests during traveler registration. The company required full copies of identity documents, which breached the data minimization principle.ESAEPDGDPR€70,000