Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Feb 2024Trasporto Passeggeri Emilia-Romagna S.p.A.The Garante fined Trasporto Passeggeri Emilia-Romagna S.p.A. 50,000 EUR for improper data processing and a lack of transparency in collecting consent for marketing purposes. The case concerned failures to properly inform data subjects and to meet consent requirements.ITGaranteGDPR€50,000
06 May 2021YThe APD Litigation Chamber imposed a 50,000 EUR fine on Y. The authority found that the privacy policy lacked transparency and breached several GDPR provisions.BEAPDGDPR€50,000
13 Jul 2023EUROPA PRESS DE CATALUNYA, S.A.EUROPA PRESS DE CATALUNYA, S.A. was fined by the AEPD 50,000 EUR for publishing audio of a victim's court statement in a high-profile case. The authority found that the company processed excessive personal data in breach of GDPR Article 5(1)(c).ESAEPDGDPR€50,000
01 Jul 2010TELEFONICA MOVILES ESPAÑA S.A.U.TELEFONICA MOVILES ESPAÑA S.A.U. was fined by the AEPD EUR 50,000 for sending unsolicited SMS advertisements without proper consent. The conduct breached Article 21.2 of the LSSI on electronic marketing communications.ESAEPDePrivacy€50,000
29 Apr 2022RADIO TELEVISION MADRID, S.A.RADIO TELEVISION MADRID, S.A. was fined by the AEPD 50,000 EUR for processing excessive personal data. The case concerned the publication of audio of a victim's court statement in a high-profile case, which breached the data minimization principle.ESAEPDGDPR€50,000
29 Apr 2025Regione LombardiaThe Garante fined Regione Lombardia 50,000 EUR for violations related to the processing of personal data. The authority cited inadequate technical and organizational measures to protect data, as well as improper handling of employee metadata and internet navigation logs.ITGaranteGDPR€50,000
21 Aug 2020ZSOUODO imposed a PLN 50,000 fine on ZSO for breaching personal data protection rules. The case concerned non-compliance with requirements under data protection regulations.PLUODOGDPR€11,369
27 Jan 2021De Nationale Dienst voor Promotie van Kinderartikelen, NVThe company was fined for unlawfully sharing personal data of (expectant) mothers with third parties for direct marketing without valid consent. The authority found breaches of GDPR transparency and information obligations.BEAPDGDPR€50,000
23 Jun 2025Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 50,000 EUR for unlawfully transferring personal data to third parties without the data subject's consent. The authority found breaches of GDPR principles of lawfulness and accuracy.GRHDPAGDPR€50,000
05 Aug 2020BANKIA, S.A.BANKIA, S.A. was fined by the AEPD 50,000 EUR for retaining a former client’s personal data for more than 16 years without a valid basis. The authority found this to be a breach of data protection principles, especially storage limitation.ESAEPDGDPR€50,000
14 Oct 2022VODAFONE ONO, S.A.U.The AEPD fined VODAFONE ONO, S.A.U. 50,000 EUR for consulting a credit information system without the individual's consent. The company had no contractual relationship with the person, so there was no valid basis for the inquiry.ESAEPDGDPR€50,000
25 May 2022RoulartaThe Belgian data protection authority, APD, sanctioned Roularta in decision 85/2022 of 25 May 2022. The case concerned the placement of non-essential cookies on its press websites without prior user consent. The fine was EUR 50,000.BEAutorité de protection des donnéesGDPR€50,000
24 Oct 2023UNIPREX, S.A.UNIPREX, S.A. was fined 50,000 EUR by the AEPD for processing an excessive amount of personal data. The authority found that the data collected went beyond what was necessary for the intended purpose.ESAEPDGDPR€50,000
29 Nov 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for sending a customer's personal data to the wrong address. The authority found this to be a breach of data security requirements under GDPR Article 5(1)(f).ESAEPDGDPR€50,000
26 Apr 2024SANTANDER CONSUMER, S.A.SANTANDER CONSUMER, S.A. was fined by the AEPD in the amount of 50,000 EUR for sending postal advertising after the complainant had exercised the right to object to processing for marketing purposes. The case concerns failure to respect the data subject’s objection to commercial use of personal data.ESAEPDGDPR€50,000
29 Apr 2022EDITORIAL PRENSA CANARIA, S.A.The company was fined by the AEPD 50,000 EUR for publishing audio of a victim's testimony in a high-profile court case. The authority found a breach of data protection principles.ESAEPDGDPR€50,000
09 Aug 2018InsingerGilissen Bankiers N.V.Theodoor Gilissen Bankiers N.V. failed to provide a complete overview of personal data processing upon request, which breached data protection rules. Its successor, InsingerGilissen Bankiers N.V., was fined EUR 48,000.NLAPGDPR€48,000
02 Mar 2017Trilogy s.r.l.Trilogy s.r.l. was fined EUR 48,000 by the Garante for making unsolicited marketing calls. The authority found that the company failed to provide the required information and did not obtain consent, in breach of the Italian Data Protection Code.ITGaranteGDPR€48,000
31 May 2023Dane anonimowe (P. Sp. z o.o. z siedzibą w W. przy ul.)UODO imposed a PLN 47,160 fine on the anonymous company for failing to implement appropriate technical and organizational measures to secure personal data processing in IT systems. The authority also found a lack of regular testing, measuring, and evaluation of the effectiveness of those measures, as well as failure to report the personal data breach without undue delay. In addition, the company did not notify affected individuals without undue delay despite a high risk to their rights and freedoms.PLUODOGDPR€10,395
13 Sept 2012YVES ROCHER ESPAÑA, S.A.YVES ROCHER ESPAÑA, S.A. was fined EUR 47,001 by the AEPD for continuing to send advertising emails to an individual who had requested data deletion and confirmation of that deletion. The authority found that marketing communications continued despite the request.ESAEPDePrivacy€47,001