Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Jun 2019TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined by the AEPD for incorrect processing of personal data. The error caused billing mistakes because one customer’s data was mixed with another subscriber’s information.ESAEPDGDPR€60,000
26 Nov 2020Ministero dell’InternoThe Ministry of the Interior was fined by the Garante for the unauthorized dissemination of video and images related to a police incident. The authority found a breach of GDPR rules governing the processing of personal data.ITGaranteGDPR€60,000
10 Apr 2023BIROU GAS, S.L.BIROU GAS, S.L. was fined EUR 60,000 by the AEPD for breaching Article 58(1) of the GDPR. The company did not respond to information requests from the supervisory authority.ESAEPDGDPR€60,000
01 Jan 2019XFERA MÓVILES, S.A. (MASMOVIL)XFERA MÓVILES, S.A. (MASMOVIL) was fined by the AEPD €60,000 for changing a customer's contract details without proper consent. The authority found that the processing lacked a valid legal basis under GDPR Article 6(1)(a).ESAEPDGDPR€60,000
02 Jul 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD EUR 60,000 for failing to implement adequate security measures. This allowed unauthorized access to personal data through its website.ESAEPDGDPR€60,000
23 Sept 2019VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 60,000 EUR for processing personal data without consent. The breach led to an unauthorized service change and debt collection attempts.ESAEPDGDPR€60,000
01 Jan 2019CORPORACION DE RADIO Y TELEVISION ESPAÑOLA SACORPORACION DE RADIO Y TELEVISION ESPAÑOLA SA was fined by the AEPD for a security incident involving the loss of unencrypted USB drives containing personal data. The authority found a breach of Article 32 GDPR on appropriate technical and organisational security measures.ESAEPDGDPR€60,000
08 Jan 2015OTEThe Hellenic Data Protection Authority fined OTE EUR 60,000 for failing to implement adequate security measures. The deficiency led to a data breach involving personal data of a large number of subscribers.GRHDPAePrivacy€60,000
29 Jun 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 60,000 for unauthorized processing of personal data. The case involved a fraudulent contract and the porting of a customer's phone line without a valid legal basis.ESAEPDGDPR€60,000
01 Feb 2018Provincia di BeneventoProvincia di Benevento was fined by the Garante for unlawfully publishing special-category personal data on its website, including health information and tax codes. The authority found a breach of data protection rules.ITGaranteGDPR€60,000
16 May 2018Paesano FrancescoPaesano Francesco was fined EUR 60,000 by the Garante for activating six phone cards without the consent of the individuals concerned. The case concerns a breach of data protection rules and the absence of a valid legal basis for processing.ITGaranteGDPR€60,000
02 Mar 2026Nordic Cleaning ApSThe Danish DPA reported Klein2 ApS and Nordic Cleaning ApS to the police for failing to comply with orders to address access requests. Nordic Cleaning ApS accepted a fine notice of 60,000 DKK.DKDatatilsynetGDPR€8,031
23 May 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD for assigning a customer's DNI to a third party. This enabled unauthorized access to personal data and invoices, constituting a data protection breach.ESAEPDGDPR€60,000
01 Jan 2020Lycamobile, S.L.Lycamobile, S.L. was fined by the AEPD 60,000 EUR for falsifying the personal data of prepaid card users. The case concerns a breach of data protection rules.ESAEPDGDPR€60,000
26 Mar 2021CAIXABANK S.A.CAIXABANK S.A. was fined EUR 60,000 by the AEPD for processing personal data without consent. The case concerned a current account contract signed on behalf of the complainant without proper authorization.ESAEPDGDPR€60,000
15 Nov 2019HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined by the AEPD 60,000 EUR for sending a patient's medical report to an insurance company without proper consent. The case concerns a breach of data protection rules and the special protection applicable to health data.ESAEPDGDPR€60,000
01 Jan 2019XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 60,000 by the AEPD for processing personal data without a legal basis. The authority found a breach of Article 6 GDPR, meaning the processing lacked a lawful basis.ESAEPDGDPR€60,000
14 Jun 2018Anonymizováno (ÚOOÚ UOOU-00051/18-14)The entity was fined for processing the personal data of apartment building residents through a camera system without their consent. The authority found this to be a breach of Czech data protection law.CZUOOUGDPR€2,339
25 Jul 2019VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined by the AEPD 60,000 EUR for failing to ensure adequate security of personal data. The breach resulted in unauthorized or unlawful processing, indicating deficiencies in security controls.ESAEPDGDPR€60,000
17 Oct 2024Serfin 97 S.r.l.Serfin 97 S.r.l. was fined EUR 60,000 by the Garante for unlawful processing of personal data. The company used a third party’s email address to contact a debtor for debt recovery purposes, which breached data protection rules.ITGaranteGDPR€60,000