Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 May 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for processing personal data without proper consent, in breach of Article 6(1) GDPR. The penalty was set at EUR 70,000, with reductions available for early payment and acknowledgment of responsibility.ESAEPDGDPR€70,000
21 Apr 2021ParkkiPateThe Finnish Data Protection Ombudsman fined ParkkiPate EUR 70,000 for GDPR violations. The case concerned data minimization, identification of data subjects, and the handling of access rights.FITSVGDPR€70,000
31 May 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 70,000 EUR for failing to implement adequate security measures. This allowed a third party to impersonate a customer, change contact details, and gain unauthorized access to personal and banking data.ESAEPDGDPR€70,000
11 Jan 2018N.J.L. & Time di Bernasconi NadiaN.J.L. & Time di Bernasconi Nadia was fined 68,000 EUR by the Garante. The authority found that promotional emails were sent without proper consent, in breach of data protection rules.ITGaranteGDPR€68,000
17 Jun 2025Szpital, za naruszenie przepisów art. 5 ust. 1 lit. f) i ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679,UODO imposed an administrative fine of PLN 66,500 on the hospital. The authority found that the hospital failed to implement appropriate technical and organizational measures to secure personal data and protect data subjects' rights. It also failed to regularly test, measure, and assess the effectiveness of those safeguards.PLUODOGDPR€15,546
17 Apr 2014SSTC srlSSTC srl was fined EUR 66,000 by the Italian authority Garante. The case concerned telemarketing activities carried out without the prior consent of the contacted individuals, in breach of data protection rules.ITGaranteGDPR€66,000
20 Nov 2017ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 66,000 by the AEPD for sending unsolicited promotional SMS messages. The authority also noted that recipients were not given a means to object to the processing of their data for marketing purposes.ESAEPDePrivacy€66,000
15 Nov 2012Dusty s.r.l.Dusty s.r.l. was fined by the Italian Garante 66,000 EUR for implementing a biometric data collection system for employee attendance without properly appointing data processing officers and without obtaining the required consent. The authority found violations of several provisions of the data protection code.ITGaranteGDPR€66,000
06 Sept 2017ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 66,000 by the AEPD for sending commercial SMS messages without consent. The authority also found that recipients were not given an effective option to object, in breach of the LSSI rules.ESAEPDePrivacy€66,000
12 Dec 2025Police Service of ScotlandThe Information Commissioner's Office (ICO) fined the Police Service of Scotland £66,000 and issued a reprimand for serious failures in handling sensitive personal information. The case concerned improper handling of information requiring special protection, increasing the risk to affected individuals.GBICOGDPR€75,280
26 Oct 2023Argentum Data Solutions LtdBetween 1 January 2021 and 31 January 2022, a total of 2,330,423 SMS messages were sent without consent. Argentum Data Solutions Ltd sent 24,309 messages directly and allowed its lines to be used by third parties to send the remaining 2,306,114. The conduct breached regulation 22 of PECR and came to the ICO’s attention through complaints reported via the 7726 spam tool.GBICOePrivacy€74,568
25 Sept 2025JacksonsThe ODPA fined Jacksons £65,000 after finding that the company unlawfully changed customer marketing preferences. The investigation identified anomalies in customer records and direct marketing communications made against customers’ wishes.GGODPAGDPR€74,302
18 Aug 2020HSEThe Irish DPC fined HSE EUR 65,000 in inquiry IN-19-9-1. The fine was collected.IEDPCGDPR€65,000
20 Jun 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD €65,000 for improper handling of personal data. The company failed to notify the rectification or deletion of personal data, which led to unwarranted debt collection calls.ESAEPDGDPR€65,000
21 Sept 2023RHAP LtdRHAP Ltd made 15,288 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a £65,000 fine and issued an enforcement notice.GBICOePrivacy€74,958
14 Jan 2021SIA "Lursoft IT"A fine of EUR 65,000 was imposed. The decision is final and has entered into force.LVDVIGDPR€65,000
28 May 2015Xpedite Systems s.r.l.Xpedite Systems s.r.l. was fined 64,000 EUR by the Garante for sending unsolicited promotional faxes without the required notice and consent. The authority found this to be a breach of privacy rules.ITGaranteGDPR€64,000
13 Jun 2013BBJ s.r.l.BBJ s.r.l. was fined by the Garante EUR 64,000 for running SMS and email marketing campaigns without providing the required information to data subjects and without obtaining their consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€64,000
20 Jul 2017Crea Futuro s.r.l.Crea Futuro s.r.l. was fined by the Garante 64,000 EUR for processing personal data without providing adequate information and obtaining consent. The breach affected about 2 million people, indicating a broad compliance impact.ITGaranteGDPR€64,000
12 Mar 2015Giuseppe PernaGiuseppe Perna was fined 64,000 EUR by the Garante for collecting and selling users’ email and IP addresses without proper consent and notice. The authority found this conduct to be in breach of data protection rules.ITGaranteGDPR€64,000