Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Aug 2022Lolland KommuneLolland Kommune was fined 50,000 DKK for failing to implement basic security measures. Employees were able to disable passwords on mobile devices, exposing sensitive citizen data to unauthorized access.DKDatatilsynetGDPR€6,721
23 May 2022EL DIARIO DE PRENSA DIGITAL, S.L.EL DIARIO DE PRENSA DIGITAL, S.L. was fined by the AEPD 50,000 EUR for publishing audio of a victim's testimony in a high-profile court case. The authority found a breach of the GDPR data minimization principle.ESAEPDGDPR€50,000
15 Jun 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD for continuing to pursue a debt that had already been settled. The authority treated this as a breach of data protection rules.ESAEPDGDPR€50,000
25 May 2022Roularta Media GroupRoularta Media Group was fined EUR 50,000 by the APD for using cookies on its media websites without obtaining valid user consent. The authority found this practice breached GDPR and ePrivacy Directive requirements.BEAPDePrivacy€50,000
28 Sept 2023Azienda Usl Toscana centroThe Garante imposed a fine of EUR 50,000 on Azienda Usl Toscana centro for data protection violations related to the former Sanatorio Guido Banti premises. The case concerned irregularities in the processing of personal data in that context.ITGaranteGDPR€50,000
01 Jan 2024FLEXICAR IBÉRICA, S.L.FLEXICAR IBÉRICA, S.L. was fined €50,000 by the AEPD for a personal data breach. The incident occurred when information belonging to other clients was mistakenly shared via WhatsApp.ESAEPDGDPR€50,000
20 Dec 2023Dane anonimowe (Wójta Gminy P.)UODO imposed a PLN 50,000 administrative fine on the controller for failing to implement appropriate technical and organizational measures proportionate to the risk of processing. The authority found insufficient safeguards for confidentiality, integrity, availability, and resilience of systems, as well as inadequate recovery capability after an incident.PLUODOGDPR€11,518
10 Jul 2025Magna PT S.p.A.Magna PT S.p.A. was fined EUR 50,000 by the Garante for requiring employees to complete a questionnaire after absences due to illness. The authority found that this practice breached GDPR rules on the processing of personal data.ITGaranteGDPR€50,000
01 Jan 2019TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD. The authority found that the company used personal data to fraudulently contract phone lines without the data subjects’ consent.ESAEPDGDPR€50,000
18 Apr 2018Marigliano GianpaoloMarigliano Gianpaolo was fined by the Garante 50,000 EUR for unlawfully using personal data to activate 15 phone cards without the consent of the individuals concerned. The case indicates a breach of lawful processing requirements and consent rules.ITGaranteGDPR€50,000
21 Sept 2020CONSEGURIDAD S.L.CONSEGURIDAD S.L. was fined 50,000 EUR by the AEPD for failing to appoint a Data Protection Officer. The authority found a breach of Article 37(1)(b) of the GDPR.ESAEPDGDPR€50,000
10 Jun 2022ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 50,000 EUR by the AEPD for processing personal data without consent. The breach resulted in identity theft in a phone contract.ESAEPDGDPR€50,000
03 Oct 2023Digivo Media LimitedBetween 24 March 2021 and 7 September 2021, 415,041 text messages were sent without valid consent, breaching Regulation 22 of PECR. The ICO identified the matter after reviewing debt management complaints submitted via the SPAM reporting tool.GBICOePrivacy€57,620
13 Jul 2022GRUPO TRANSAHER, S.L.GRUPO TRANSAHER, S.L. was fined by the AEPD 50,000 EUR for installing surveillance cameras in employee rest areas. The authority found that the company did not properly inform employees and may have infringed their privacy under the GDPR.ESAEPDGDPR€50,000
23 Apr 2018Anonymizováno (ÚOOÚ UOOU-06702/17-47)The entity was fined CZK 50,000 by the UOOU for failing to cooperate during an inspection. The authority found a breach of the duty to create conditions for the inspection and provide necessary assistance.CZUOOUGDPR€1,968
02 Feb 2018Anonymizováno (ÚOOÚ UOOU-06702/17-37)The entity was fined CZK 50,000 by the Czech data protection authority for failing to provide the required cooperation during an ongoing inspection. This breached the duty to create conditions for the inspection and to allow the inspector to exercise their powers.CZUOOUGDPR€1,985
07 Sept 2023IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORAIberia was fined by the AEPD EUR 50,000 for a breach related to personal data handling during a flight from Quito to Dublin. Passengers were asked to provide identity documents and marriage certificates to justify travel during COVID-19 restrictions.ESAEPDGDPR€50,000
14 Mar 2013PONTE EN FORMA ONLINE, S.L.PONTE EN FORMA ONLINE, S.L. was fined by the AEPD EUR 50,000 for sending unsolicited commercial email communications. The conduct breached Article 21 of the LSSI, which restricts marketing emails sent without prior consent.ESAEPDePrivacy€50,000
01 Jan 2025PROYECTOS VISUALES ZARAGOZA SLPROYECTOS VISUALES ZARAGOZA SL was fined by the AEPD 50,000 EUR for a personal data breach. The authority found that the company failed to ensure data integrity and confidentiality under Article 5(1)(f) GDPR.ESAEPDGDPR€50,000
24 Mar 2021Ålesund kommuneÅlesund kommune was fined by Datatilsynet for using the Strava app in schools without conducting a risk assessment. As a result, students’ personal data was processed without adequate controls and safeguards.NODatatilsynetGDPR€4,923