Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 May 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD EUR 70,000 for a data protection breach involving unauthorized SIM card duplication. The incident led to unauthorized bank transfers from the complainant's account.ESAEPDGDPR€70,000
23 Apr 2021Vodafone España, S.A.U.The AEPD fined Vodafone España, S.A.U. EUR 70,000 for failing to adequately prevent identity theft. As a result, unauthorized phone line contracts were entered into using a customer's personal data.ESAEPDGDPR€70,000
17 Jan 2023ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without valid consent. The case concerned a contract entered into in the name of a deceased person without authorization.ESAEPDGDPR€70,000
07 Mar 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for improperly handling a SIM card duplication request. The failure led to unauthorized transactions on a customer's bank account and was found to breach Article 6(1) GDPR.ESAEPDGDPR€70,000
01 Jan 2023Vodafone España, S.A.U.The AEPD fined Vodafone España EUR 70,000 for providing a SIM card duplicate to a third party without the data subject's consent. This enabled unauthorized access to personal and banking information.ESAEPDGDPR€70,000
12 Nov 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for continuing to send billing emails to a complainant despite an arbitration ruling. The ruling required the company to stop all services and delete the complainant’s data, which it failed to do.ESAEPDGDPR€70,000
20 Dec 2024FUNDACIÓN SOCIEDAD CIENTÍFICA DE ONCOLOGÍA MÉDICAFUNDACIÓN SOCIEDAD CIENTÍFICA DE ONCOLOGÍA MÉDICA was fined 70,000 EUR by the AEPD for a data breach affecting confidentiality. The authority found a violation of Article 5(1)(f) GDPR, which requires personal data to be processed securely and confidentially.ESAEPDGDPR€70,000
28 May 2024CUI ZSQ FOOD, S.L.CUI ZSQ FOOD, S.L. was fined by the AEPD 70,000 EUR for using a video surveillance system to intimidate employees. The company shared footage of an employee’s absence in a work chat, which breached data protection rules.ESAEPDGDPR€70,000
27 Jan 2021Azienda ospedaliera regionale “San Carlo” di PotenzaAzienda ospedaliera regionale “San Carlo” di Potenza was fined EUR 70,000 by the Garante for violations related to the processing of personal data. The case concerned the handling of sensitive health data.ITGaranteGDPR€70,000
21 Sept 2023SGS Home Protect LtdSGS Home Protect Ltd made 24,214 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of 70,000 GBP and issued an enforcement notice.GBICOePrivacy€80,724
09 Mar 2023INTERURBANA DE AUTOBUSES, S.A.INTERURBANA DE AUTOBUSES, S.A. was fined by the AEPD 70,000 EUR for publishing employees’ personal data without consent. The breach involved exposing unnecessary information on notice boards accessible to others, contrary to data minimization requirements.ESAEPDGDPR€70,000
19 Dec 2024Studio Riabilitazione Creditizia s.r.l.s.The Garante fined Studio Riabilitazione Creditizia s.r.l.s. €70,000 for improperly accessing financial data from the Central Credit Register without proper authorization. The authority found this conduct breached data protection principles.ITGaranteGDPR€70,000
15 Mar 2023BANKINTER CONSUMER FINANCE E.F.C., S.A.Bankinter Consumer Finance issued a duplicate card without the customer's consent and sent it to an incorrect address. This led to unauthorized transactions and indicated a failure in data protection and payment security controls.ESAEPDGDPR€70,000
17 Feb 2022VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined EUR 70,000 by the AEPD for issuing a duplicate SIM card to a third party without the customer's consent. This enabled unauthorized access to the customer's bank account.ESAEPDGDPR€70,000
17 Mar 2023ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 70,000 by the AEPD for activating a call forwarding service without the user's consent. This led to unauthorized access to the user's bank accounts and transactions.ESAEPDGDPR€70,000
17 Mar 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.The AEPD fined TELEFÓNICA MÓVILES ESPAÑA, S.A. 70,000 EUR for changing a customer's mobile tariff without consent. The authority found that the action breached Article 6(1) GDPR because there was no valid legal basis for the change.ESAEPDGDPR€70,000
11 May 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 70,000 by the AEPD for issuing a duplicate SIM card without the customer's consent. This enabled unauthorized access to the customer's bank account, indicating a serious failure in security and data protection controls.ESAEPDGDPR€70,000
06 Feb 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 70,000 EUR by the AEPD for a personal data breach. An error in assigning identification numbers allowed one customer to access another customer's personal data.ESAEPDGDPR€70,000
24 Oct 2023FIBRA ÓPTICA MÁLAGA, S.L.FIBRA ÓPTICA MÁLAGA, S.L. changed a customer's contact email and bank account details without consent. The AEPD found a breach of GDPR Article 6(1) and imposed a 70,000 EUR fine.ESAEPDGDPR€70,000
31 Mar 2022ALQUILER SEGURO, S.A.U.ALQUILER SEGURO, S.A.U. accessed personal data from Asnef for purposes other than those intended. The AEPD found this to be a breach of data protection rules and imposed a 70,000 EUR fine.ESAEPDGDPR€70,000