Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Feb 2019XX S.r.l.The company was fined EUR 4,000 by the Garante. The authority found that it processed personal data for promotional purposes without obtaining valid consent from the data subjects.ITGaranteGDPR€4,000
29 Sept 2011XX s.a.s.XX s.a.s. was fined for sending unsolicited promotional emails without the recipients' explicit consent. The authority also found that the required privacy notice was not provided, constituting a data protection breach.ITGaranteGDPR€10,400
18 Oct 2024X, ul.UODO imposed an administrative fine of PLN 25,000 on X, ul. for breaching Article 37(1)(a) and Article 37(7) of Regulation 2016/679. The authority also ordered the processing operations to be brought into compliance with GDPR requirements.PLUODOGDPR€5,803
13 Jul 2016Xu Ja s.n.c.Xu Ja s.n.c. was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned failure to provide simplified information about video surveillance, as required under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
28 May 2015Xpedite Systems s.r.l.Xpedite Systems s.r.l. was fined 64,000 EUR by the Garante for sending unsolicited promotional faxes without the required notice and consent. The authority found this to be a breach of privacy rules.ITGaranteGDPR€64,000
28 Apr 2025Xiting ROM SRLIn April 2025, ANSPDCP completed an investigation at Xiting ROM SRL and found violations of GDPR provisions. As a result, a fine of EUR 1,000 was imposed.ROANSPDCPGDPR€1,000
30 Oct 2014Xiao Bin JiangXiao Bin Jiang was fined EUR 2,400 by the Garante. The violation concerned the failure to provide data subjects with the required information about the processing of personal data through a video surveillance system at a commercial establishment.ITGaranteGDPR€2,400
01 Jan 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD EUR 60,000 for incorrectly including personal data in a creditworthiness file. The authority found a breach of the GDPR accuracy principle under Article 5(1)(d).ESAEPDGDPR€60,000
02 Jul 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD EUR 60,000 for failing to implement adequate security measures. This allowed unauthorized access to personal data through its website.ESAEPDGDPR€60,000
20 Jun 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD €65,000 for improper handling of personal data. The company failed to notify the rectification or deletion of personal data, which led to unwarranted debt collection calls.ESAEPDGDPR€65,000
11 Jun 2020XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined EUR 55,000 by the AEPD for linking a phone number to a third party’s data. This created unauthorized access and a risk of data alteration, breaching data protection rules.ESAEPDGDPR€55,000
19 Mar 2025XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited SMS advertisements to a number registered on the Robinson List. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€10,000
21 Sept 2018XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD in the amount of 4,000 EUR for sending unsolicited commercial SMS messages without the recipient’s consent. The conduct breached Article 21.1 of the LSSI, which requires prior consent for marketing communications.ESAEPDePrivacy€4,000
01 Jan 2024XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD for failing to ensure the security and confidentiality of personal data. The incident resulted in a data breach and created a risk of identity theft.ESAEPDGDPR€4,000,000
01 Jan 2020XFERA MÓVILES, S.A. (MASMOVIL)XFERA MÓVILES, S.A. (MASMOVIL) was fined by the AEPD for processing personal data without a lawful basis, in breach of Article 6 GDPR. The case indicates that the company lacked a valid legal ground for the processing activity.ESAEPDGDPR€60,000
01 Jan 2019XFERA MÓVILES, S.A. (MASMOVIL)XFERA MÓVILES, S.A. (MASMOVIL) was fined by the AEPD €60,000 for changing a customer's contract details without proper consent. The authority found that the processing lacked a valid legal basis under GDPR Article 6(1)(a).ESAEPDGDPR€60,000
11 Jun 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 5,000 by the AEPD for failing to provide requested information. The breach concerned the duty to cooperate with the data protection authority during its proceedings.ESAEPDGDPR€5,000
09 Aug 2022XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined 5,000 EUR by the AEPD for sending commercial SMS messages without the recipient’s consent. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
01 Jul 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the Spanish Data Protection Agency (AEPD) for failing to provide requested information. The breach concerned cooperation obligations under data protection rules.ESAEPDGDPR€5,000
04 Feb 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the Spanish data protection authority, AEPD, in the amount of 5,000 EUR. The sanction concerned obstruction of the authority’s inspection function, which breaches Article 58(1) GDPR.ESAEPDGDPR€5,000