Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Jan 2023Fusiona Soluciones Energéticas, S.A.Fusiona Soluciones Energéticas, S.A. was fined by the AEPD for unlawfully processing personal data. The company included an individual's data in a credit information system without a lawful basis.ESAEPDGDPR€50,000
27 Apr 2022DIARIO ABC, S.L.DIARIO ABC, S.L. was fined 50,000 EUR by the AEPD for publishing audio of a victim's testimony in a high-profile court case. The authority found that the publication could identify the victim and therefore breached data protection rules.ESAEPDGDPR€50,000
12 Mar 2026ITAS MutuaITAS Mutua was fined EUR 50,000 by the Garante for failing to adequately respond to a former employee’s request for access to personal data. The authority found a breach of GDPR Article 15.ITGaranteGDPR€50,000
27 Apr 202220 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined by the AEPD 50,000 EUR for publishing audio of a victim’s court statement in a high-profile case. The authority found a breach of data protection rules.ESAEPDGDPR€50,000
02 Nov 2021Közterület megfigyelése magánszemély általThe case concerned unlawful processing of personal data through surveillance cameras installed on a property. The authority found breaches of GDPR Articles 5, 6, and 13 and imposed a fine of HUF 50,000 on the controller.HUNAIHGDPR€139
29 Jan 2026Università Telematica e-CampusThe Garante fined Università Telematica e-Campus EUR 50,000 for violations related to biometric data processing. The authority also found that the university failed to carry out a proper Data Protection Impact Assessment (DPIA).ITGaranteGDPR€50,000
17 Jul 2024Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 50,000 by the Garante for sending promotional emails without obtaining proper customer consent. The authority found this conduct to be a breach of GDPR rules on electronic marketing.ITGaranteGDPR€50,000
01 Jan 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for breaching data protection rules. The case concerned deficiencies in the security and integrity of data processing.ESAEPDGDPR€50,000
23 Apr 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for changing a customer's mobile line ownership without consent. The company also charged the customer's account amounts related to a third party's phone line.ESAEPDGDPR€50,000
02 Mar 2023H&M Hennes & Mauritz s.r.l.H&M Hennes & Mauritz s.r.l. was fined EUR 50,000 by the Garante for violations related to installing surveillance systems without the required authorization. Employees were informed about the systems, but this did not cure the underlying compliance breach.ITGaranteGDPR€50,000
14 May 2020Geanonimiseerd (APD 25/2020)The APD Litigation Chamber imposed a EUR 50,000 fine on an anonymized social media platform for processing personal data without a valid legal basis. The case involved several GDPR breaches, including data processing principles and consent requirements.BEAPDGDPR€50,000
16 Jan 2023Kildare County CouncilThe Irish DPC imposed a fine of EUR 50,000 on Kildare County Council in inquiry 05/SIU/2018. The fine has been collected.IEDPCGDPR€50,000
10 Jan 2025CRUZ ROJA ESPAÑOLACRUZ ROJA ESPAÑOLA was fined EUR 50,000 by the AEPD for a personal data protection breach. The case involved the unauthorized disclosure of patient data in a communication about a change in embryo bank management.ESAEPDGDPR€50,000
26 Sept 2024Città metropolitana di TorinoCittà metropolitana di Torino was fined by the Garante 50,000 EUR for publishing personal data on its institutional website about individuals fined by voluntary ecological guards. The disclosure included names and contact details, breaching data protection rules.ITGaranteGDPR€50,000
19 Nov 2020ALTERNA OPERADOR INTEGRAL, S.L.ALTERNA OPERADOR INTEGRAL, S.L. was fined by the AEPD EUR 50,000 for changing an electricity provider without the customer's consent. The authority found that the processing lacked a valid legal basis under Article 6(1)(b) GDPR.ESAEPDGDPR€50,000
25 May 2018Anonymizováno (ÚOOÚ UOOU-07350/18-21)The entity was fined 50,000 CZK by UOOU for failing to provide the necessary cooperation during an inspection. The breach concerned the legal duty to assist the supervisory authority.CZUOOUGDPR€1,941
12 May 2026SWDESWDE was fined by the APD 50,000 EUR for unlawful call recordings and monitoring used for quality evaluation and training purposes. The authority found breaches of transparency, data minimization, and other GDPR principles.BEAPDGDPR€50,000
18 Apr 2018Futur3 s.r.l.Futur3 s.r.l. was fined EUR 50,000 by the Garante for requiring users to give mandatory consents for marketing and profiling purposes that were not directly related to the requested Wi‑Fi service. The authority found this to be a breach of data protection rules.ITGaranteGDPR€50,000
02 Mar 2023Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 50,000 by the Garante for violations in the processing of personal data. The authority found non-compliance with the principles of data minimization and integrity and confidentiality.ITGaranteGDPR€50,000
27 Oct 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD for requesting payment for services contracted without the complainant’s consent. The case concerns a data protection breach linked to processing and debt collection without a valid legal basis.ESAEPDGDPR€50,000