Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Oct 2025Provvedimento del 9 ottobre 2025 [10184697]The Garante imposed a EUR 70,000 fine on a company managing a hospital for violations related to the processing of health data. The case also involved a change in the complainant's treatment path and a failure to notify the authority of a data breach.ITGaranteGDPR€70,000
06 Apr 2022BANKINTER, S.A.BANKINTER, S.A. was fined EUR 70,000 by the AEPD for a data protection breach. The case involved the unauthorized disclosure of sensitive banking information caused by an isolated IT error.ESAEPDGDPR€70,000
05 Jul 2022CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined 70,000 EUR by the AEPD. The company continued to demand payment of a debt that had been annulled by a court ruling, which breached data protection rules.ESAEPDGDPR€70,000
28 Jun 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined EUR 70,000 by the AEPD for a SIM card duplication incident. The incident enabled unauthorized attempts to access the complainant's bank accounts and was treated as a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
28 Feb 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD 70,000 EUR for processing personal data without consent. The case concerned a mobile line contracted in the complainant’s name without proper identity verification.ESAEPDGDPR€70,000
22 Feb 2022VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 70,000 EUR for issuing a duplicate SIM card to a third party without proper authorization. This enabled unauthorized access to the complainant’s bank data and resulted in fraudulent transactions.ESAEPDGDPR€70,000
29 May 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España 70,000 EUR for processing call and SMS diversion without the customer's consent. The conduct was linked to a bank fraud incident, indicating a serious failure in data protection and service authorization controls.ESAEPDGDPR€70,000
21 Apr 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. EUR 70,000 for allowing a SIM card swap without the user's consent. The incident enabled unauthorized access to the customer's bank information and resulted in a fraudulent bank transfer.ESAEPDGDPR€70,000
21 Aug 2023Uipath SRLUipath SRL was fined by ANSPDCP EUR 70,000 for violations related to cross-border data processing. The case concerned compliance issues in the transfer or handling of data across borders.ROANSPDCPGDPR€70,000
01 Jan 2024EDP SOLAR ESPAÑA, S.A.EDP SOLAR ESPAÑA, S.A. was fined by the AEPD for failing to meet data protection obligations. The breach concerned Article 5(1)(c) of the GDPR, which requires data minimization.ESAEPDGDPR€70,000
29 Nov 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for failing to comply with a data subject access request. The case concerned the company’s failure to provide a requested recording of a contract concluded by telephone.ESAEPDGDPR€70,000
09 May 2023TELEFÓNICA SERVICIOS INTEGRALES DE DISTRIBUCIÓN, S.A.ZELERIS, a Telefónica subsidiary, was fined by the AEPD for delivering a package containing personal data to the wrong address without consent. The case indicates a breach of data protection rules in the handling and delivery of shipments.ESAEPDGDPR€70,000
12 Feb 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 70,000 EUR by the AEPD for a data protection breach involving unauthorized SIM card duplication and an attempted line takeover. The authority found a violation of GDPR Article 6(1).ESAEPDGDPR€70,000
23 Apr 2021Vodafone España, S.A.U.Vodafone España, S.A.U. was fined EUR 70,000 by the AEPD after a third party gained unauthorized access to a customer account. The incident led to changes in personal data and services without the customer’s consent.ESAEPDGDPR€70,000
01 Jan 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for unlawfully duplicating a customer's SIM card without consent. The incident led to unauthorized access to the customer's personal and banking data.ESAEPDGDPR€70,000
22 Feb 2024L’Igiene Urbana Evolution s.r.l.L’Igiene Urbana Evolution s.r.l. was fined €70,000 by the Garante for unlawfully processing biometric data through facial recognition to monitor employee attendance. The authority found that this practice violated GDPR requirements.ITGaranteGDPR€70,000
12 Oct 2023Scionti Selezioni Superiori S.r.l.Scionti Selezioni Superiori S.r.l. was fined EUR 70,000 by the Garante for failing to implement adequate measures to prevent unauthorized access to customer data. The data was then used for promotional purposes without the individuals' consent.ITGaranteGDPR€70,000
14 Mar 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD in the amount of 70,000 EUR for issuing a bill despite confirming that no debt existed and that personal data had been deleted. The authority found this conduct to be contrary to Article 6(1) of the GDPR.ESAEPDGDPR€70,000
09 Jan 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card without proper authorization. The incident enabled unauthorized access to a customer's bank account.ESAEPDGDPR€70,000
28 Feb 2023PELAYO MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJAPelayo Mutua de Seguros y Reaseguros A Prima Fija was fined 70,000 EUR by the AEPD. The authority found that the company disclosed personal data to a third party without consent, breaching GDPR confidentiality and security obligations.ESAEPDGDPR€70,000