BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Feb 2022 | DIGI SPAIN TELECOM, S.L.DIGI Spain Telecom, S.L. was fined by the AEPD in the amount of EUR 70,000 for a breach of Article 6(1) GDPR. The case concerned the unauthorized duplication of a SIM card in an identity theft incident, which resulted in financial losses for the complainant. | ES | AEPD | GDPR | €70,000 | ↗ |
| 17 Dec 2020 | University College DublinThe Irish DPC imposed a fine of EUR 70,000 on University College Dublin in inquiry IN-19-7-4. The fine has been collected. | IE | DPC | GDPR | €70,000 | ↗ |
| 02 Jun 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for continuing to send investment reports by postal mail despite the complainant’s request to receive them by email. The authority found a breach of the right to object and to stop data processing. | ES | AEPD | GDPR | €70,000 | ↗ |
| 17 May 2022 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 70,000 by the AEPD for issuing a SIM card duplicate to a third party without the claimant’s consent. The authority also found that the third party’s identity was not verified, constituting a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 07 Jan 2022 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD EUR 70,000 for including personal data in credit information systems without a proper legal basis. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without consent. The conduct led to unauthorized contracts and credit reporting issues. | ES | AEPD | GDPR | €70,000 | ↗ |
| 22 Feb 2023 | ENERGÍA COLECTIVA, S.L.ENERGÍA COLECTIVA, S.L. was fined by the AEPD 70,000 EUR for changing an individual's electricity provider without consent. The authority found a breach of Article 6 GDPR, which requires a lawful basis for processing personal data. | ES | AEPD | GDPR | €70,000 | ↗ |
| 23 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD EUR 70,000 for allowing unauthorized access to a customer's personal data. The data was then used to fraudulently contract mobile lines without the customer's consent. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2023 | Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without a proper legal basis. The breach enabled unauthorized SIM card duplication and subsequent fraudulent bank transactions. | ES | AEPD | GDPR | €70,000 | ↗ |
| 24 Mar 2021 | IBERDROLA CLIENTES, SAUIberdrola Clientes, SAU was fined EUR 70,000 by the AEPD for changing the contracted power in a supply agreement without the consent of the contract holder. The authority found that this conduct breached data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 25 Oct 2012 | Enterprise Group S.r.l.Enterprise Group S.r.l. was fined EUR 70,000 by the Garante. The case concerned unsolicited promotional communications sent by fax without proper consent, in breach of data protection rules. | IT | Garante | GDPR | €70,000 | ↗ |
| 01 Jan 2023 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for a data breach after an employee accessed a customer's banking information and shared it without consent. The authority found that data security measures were violated. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 70,000 by the AEPD for disclosing one client's personal address to another client. The authority found a breach of personal data confidentiality obligations under the GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 May 2022 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for unauthorized access to a former customer's account. The access enabled a third party to make purchases and subscriptions, indicating improper processing of personal data without consent. | ES | AEPD | GDPR | €70,000 | ↗ |
| 20 Apr 2023 | HOLALUZ-CLIDOM, S.A.HOLALUZ-CLIDOM, S.A. was fined EUR 70,000 by the AEPD for processing personal data without consent. The company registered energy supplies for properties without the owner's consent, which breached Article 6(1) GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2023 | OPEN BANK, S.A.Openbank was fined by the AEPD for opening a bank account without the individual's authorization. The account was later used for fraudulent activities, indicating failures in verification and data protection controls. | ES | AEPD | GDPR | €70,000 | ↗ |
| 06 Apr 2022 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for processing personal data without consent. The case concerned a contract being formalized without the complainant’s consent, which breached lawful processing requirements. | ES | AEPD | GDPR | €70,000 | ↗ |
| 28 Apr 2022 | Società Ospedale San Raffaele s.r.l.The Garante fined Società Ospedale San Raffaele s.r.l. EUR 70,000 for making online medical reports accessible to other patients. The case involved a breach of personal data protection and confidentiality of health information. | IT | Garante | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for processing personal data without consent. The breach led to unauthorized access to personal data and fraudulent financial transactions. | ES | AEPD | GDPR | €70,000 | ↗ |
| 02 Feb 2022 | SUPERCOR, S.A.SUPERCOR, S.A. was fined by the AEPD for using surveillance cameras in employee rest areas without proper notification. The authority found this conduct to be in breach of GDPR Article 6. | ES | AEPD | GDPR | €70,000 | ↗ |