Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Jan 2021XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 40,000 by the AEPD for failing to respond to a data access request. The case concerns non-compliance with GDPR obligations relating to data subject rights.ESAEPDGDPR€40,000
08 Sept 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD €40,000 for processing personal data without a legal basis. The case involved fraudulent contracts created in individuals’ names without their consent, breaching the principle of lawful processing.ESAEPDGDPR€40,000
19 Feb 2024XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 200,000 by the AEPD for processing personal data without a legal basis. The case concerned a phone number portability carried out without the user's consent, which breached the requirement for lawful processing.ESAEPDGDPR€200,000
27 Apr 2021XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 3,000 for sending commercial emails without the recipient’s consent. The authority found a breach of Article 21 of the LSSI, despite the recipient’s attempts to unsubscribe.ESAEPDePrivacy€3,000
05 Feb 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 75,000 by the AEPD for processing personal data without a legal basis. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€75,000
11 Feb 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 5,000 by the Spanish Data Protection Agency (AEPD) for failing to provide requested information. The conduct breached Article 58(1) of the GDPR and hindered the authority’s supervisory powers.ESAEPDGDPR€5,000
01 Jan 2019XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 60,000 by the AEPD for processing personal data without a legal basis. The authority found a breach of Article 6 GDPR, meaning the processing lacked a lawful basis.ESAEPDGDPR€60,000
02 Apr 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 52,000 by the AEPD for sending SMS messages to a complainant about another customer's unpaid bills. The authority found that this disclosure breached data protection rules.ESAEPDGDPR€52,000
21 Jan 2019XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD in the amount of 2,500 EUR for sending unsolicited commercial SMS messages. The authority found that this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€2,500
10 Jan 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 30,000 for a data protection breach. A customer's data was incorrectly linked to another person, which allowed unauthorized access to personal information.ESAEPDGDPR€30,000
10 Feb 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD for processing personal data without valid consent. The case concerned a debt claim made against an individual for a contract they had not entered into.ESAEPDGDPR€60,000
23 Jan 2025XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined 100,000 EUR by the AEPD for inaccuracies in data retention relating to SIM card purchasers. The authority found a breach of the GDPR data accuracy obligation.ESAEPDGDPR€100,000
01 Jan 2019XFERA MÓVILES S.A.XFERA MÓVILES S.A. was fined 60,000 EUR by the AEPD for processing personal data without consent. As a result, unauthorized contracts were sent to a customer, indicating improper use of personal data.ESAEPDGDPR€60,000
01 Jan 2019Xfera Móviles, S.A.Xfera Móviles, S.A. was fined by the AEPD 70,000 EUR for the unauthorized disclosure of personal data caused by an error. The authority found a breach of the GDPR principle of integrity and confidentiality.ESAEPDGDPR€70,000
25 Nov 2024XFERA CONSUMER FINANCE ESTABLECIMIENTO FINANCIERO DE CRÉDITO, S.A.The AEPD fined XFERA Consumer Finance 5,000 EUR for sending a customer unsolicited advertising SMS messages. The messages were sent after the customer had asked to stop receiving such communications, indicating a breach of marketing communication rules.ESAEPDePrivacy€5,000
23 Sept 2014XD SOFTWARE, S.L.XD SOFTWARE, S.L. was fined by the AEPD in the amount of 6,000 EUR for sending unsolicited commercial emails and messages without recipient consent. The conduct breached Article 21 of the LSSI and involved marketing communications sent without prior authorization.ESAEPDePrivacy€6,000
30 Mar 2023XCOM DIGITAL LAB, S.L.XCOM DIGITAL LAB, S.L. was fined by the AEPD EUR 800 for sending unsolicited commercial emails. The company failed to comply with Article 21 of the LSSI despite repeated requests from the recipient to unsubscribe.ESAEPDePrivacy€800
05 Dec 2025XThe European Commission imposed a EUR 120 million fine on X for breaching transparency requirements under the Digital Services Act. The penalty covered deceptive verification design, an inadequate ad repository, and restricted access for researchers.EUEuropean CommissionDSA€120,000,000
23 Dec 2021wyżej wymienionąAn administrative fine was imposed on an individual conducting business activity. The violation consisted of failing to provide the President of the Personal Data Protection Office with access to personal data and information necessary to perform his duties.PLUODOGDPR€983
22 Dec 2021wyżej wymienionąA financial penalty was imposed on an individual conducting business activity for failing to ensure that the President of the Personal Data Protection Office had access to personal data and information necessary to perform his duties. The case concerned obstruction of the supervisory authority’s powers.PLUODOGDPR€982