Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Mar 2020Hørsholm KommuneThe Danish DPA reported Gladsaxe and Hørsholm Municipalities to the police for inadequate data security measures. The court fined Hørsholm Municipality DKK 50,000 for failing to encrypt computers containing sensitive personal data, which led to a data breach.DKDatatilsynetGDPR€6,692
04 Feb 2020VODAFONE ESPAÑA, S.A.U.The AEPD imposed a 50,000 EUR fine on VODAFONE ESPAÑA, S.A.U. for sending an SMS indicating a contract using incorrect personal data. The authority found a breach of Article 6 GDPR concerning the lawful basis for processing.ESAEPDGDPR€50,000
30 Jun 2020Lejre KommuneLejre Kommune was fined by Datatilsynet for failing to implement appropriate security measures. This led to unauthorized access to sensitive personal data, including information about minors.DKDatatilsynetGDPR€6,709
27 Jan 2021Azienda USL della RomagnaAzienda USL della Romagna was fined by the Garante 50,000 EUR for failing to implement procedures to prevent unauthorized disclosure of patients' health information. The authority found a breach of GDPR Article 9 on special categories of personal data.ITGaranteGDPR€50,000
15 Dec 2022Giessegi Industria Mobili S.p.A.Giessegi Industria Mobili S.p.A. was fined by the Garante 50,000 EUR for unlawful processing of personal data. The company installed a device to track the geographical location of a vehicle used by an employee, in breach of GDPR requirements.ITGaranteGDPR€50,000
18 Nov 2019EUSKALTEL, S.A.EUSKALTEL, S.A. was fined by the AEPD 50,000 EUR for a data protection incident. Due to incorrect handling of customer information, personal data was sent to the wrong individuals.ESAEPDGDPR€50,000
16 Sept 2022D.A.S. DEFENSA DEL AUTOMOVILISTA Y DE SINIESTROS-INTERNACIONAL, S.A. DE SEGUROS Y REASEGUROSD.A.S. Seguros was fined by the AEPD 50,000 EUR for breaching data protection principles. The company improperly disclosed personal and financial data related to an insurance policy to a third party.ESAEPDGDPR€50,000
18 Mar 2021Vodafone España, S.A.U.The AEPD imposed a 50,000 EUR fine on Vodafone España, S.A.U. for unauthorized processing of personal data. The case involved fraudulent contracting of mobile services in the complainant's name.ESAEPDGDPR€50,000
06 Feb 2023ONEY SERVICIOS FINANCIEROS E.F.C., S.A.ONEY SERVICIOS FINANCIEROS E.F.C., S.A. was fined by the AEPD 50,000 EUR for inaccurately processing personal data. The company included incorrect debt information in credit information systems, breaching data protection principles.ESAEPDGDPR€50,000
18 Jun 2021IZA OBRAS Y PROMOCIONES, S.A.IZA OBRAS Y PROMOCIONES, S.A. was fined by the AEPD 50,000 EUR for disclosing an employee’s health data and personal email address without consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€50,000
02 Jun 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for improper handling of personal data. A complaint revealed discrepancies in the data linked to a customer's identity, and the penalty was reduced due to early payment.ESAEPDGDPR€50,000
19 Dec 2025HelsaMiNorway’s digital accessibility regulator found 119 accessibility errors at HelsaMi, with 64 issues still unresolved after the initial remediation deadline. The operator was ordered to fix the problems by 2025-12-19 or face a daily penalty of NOK 50,000 until compliance is achieved.NOTilsynet for universell utforming av IKTEAA€4,197
24 Feb 2020BANKIA, S.A.BANKIA, S.A. was fined by the AEPD EUR 50,000 for sending commercial advertising by postal mail to a customer who had objected to the processing of their data for advertising purposes. The authority found this conduct contrary to GDPR Article 6(1)(f).ESAEPDGDPR€50,000
23 Apr 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for changing a customer's tariff without consent. The case involved identity impersonation and improper processing of personal data under the GDPR.ESAEPDGDPR€50,000
09 Jul 2021ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 50,000 EUR by the AEPD for failing to implement adequate security measures. The deficiency led to unauthorized bank transfers from a customer's account after a SIM card incident.ESAEPDGDPR€50,000
04 Nov 2019Coöperatie Menzis U.A.Menzis was fined by the AP for failing to implement appropriate technical measures to protect personal data. The authority found a breach of Article 32 GDPR.NLAPGDPR€50,000
29 May 2023NOVA TELECOMMUNICATIONS & MEDIA MONOPROSOPI A.E.The company was fined for repeatedly sending unsolicited electronic communications for marketing purposes despite the complainant’s objections. The authority also found failures to comply with requests for access, objection, and restriction of processing.GRHDPAePrivacy€50,000
04 Mar 2022ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined EUR 50,000 by the AEPD for a personal data protection violation. The case involved unauthorized changes to a contract holder's information, resulting in a security breach under Article 32 of the GDPR.ESAEPDGDPR€50,000
19 Jan 2021EQUIFAX IBERICA, S.L.EQUIFAX IBERICA, S.L. was fined by the AEPD 50,000 EUR for including personal data in a credit file without a valid debt and without proper notice. The authority found this breached data processing principles.ESAEPDGDPR€50,000
27 Sept 2010GESTEVISION TELECINCO, S.A.GESTEVISION TELECINCO, S.A. was fined by the AEPD 50,000 EUR for sending mass promotional SMS messages. The authority found that recipients were not given a simple and free way to object to the processing of their data for marketing purposes, in breach of Article 21.2 of the LSSI.ESAEPDePrivacy€50,000