Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Dec 2019Nusvar ABNusvar AB was fined SEK 35,000 by IMY. The authority found unauthorized processing of personal data relating to criminal offenses and a failure to comply with data minimization principles in credit reporting activities.SEIMYGDPR€3,313
23 Jan 2024CAIXA POPULAR - CAIXA RURAL SOC. COOP. DE CRÉDITO VCAIXA POPULAR was fined EUR 35,000 by the AEPD for a personal data breach. The incident allowed unauthorized third-party access and affected the confidentiality and integrity of the data.ESAEPDGDPR€35,000
21 May 2015BONANZA DIGITAL SERVICES, S.L.BONANZA DIGITAL SERVICES, S.L. was fined EUR 35,000 by the AEPD for sending 20 unsolicited advertising SMS messages without prior consent. The company also failed to provide an opt-out mechanism, breaching the LSSI.ESAEPDePrivacy€35,000
12 Sept 2025A Düsseldorf-based personnel recruitment companyOn 2025-09-12, the LDI NRW announced a data protection fine of over 35,000 EUR against a Düsseldorf-based personnel recruitment company. The authority said the company repeatedly ignored job seekers’ requests for access and deletion and failed to respond to the supervisory authority’s inquiries.DELandesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenGDPR€35,000
18 Mar 2025ALVEA SOLUCIONES TECNOLÓGICAS, S.L.ALVEA Soluciones Tecnológicas, S.L. was fined 35,000 EUR by the AEPD for improper handling of personal data. The authority cited sharing data without consent and failing to comply with data retention policies.ESAEPDGDPR€35,000
29 Oct 2013ESPASA CALPE, S.A.ESPASA CALPE, S.A. was fined EUR 35,000 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI despite prior requests to be removed from the mailing list.ESAEPDePrivacy€35,000
25 Sept 2025E-Power S.r.l.E-Power S.r.l. was fined EUR 35,000 by the Garante for making promotional calls without a valid legal basis. The authority also found that the company failed to respond to data subject rights requests, which breaches GDPR requirements.ITGaranteGDPR€35,000
27 May 2019VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined 35,000 EUR by the AEPD for processing personal data without consent. The case involved charging a former customer for services not contracted due to a technical error.ESAEPDGDPR€35,000
01 Jan 2012LET’s BONUS, S.L.LET’s BONUS, S.L. was fined EUR 34,001 by the AEPD for sending unsolicited commercial emails to a user. The conduct continued despite multiple requests to stop, which breached Article 21 of the LSSI.ESAEPDePrivacy€34,001
10 Jun 2011Azienda mobilità trasporti di Bari s.p.a.Azienda mobilità trasporti di Bari s.p.a. was fined by the Garante for processing employees' biometric data without proper notice, consent, or adequate information. The authority found violations of several provisions of the Italian data protection code.ITGaranteGDPR€34,000
02 Dec 2015A.M.A.M. Azienda Meridionale Acque Messina s.p.a.A.M.A.M. Azienda Meridionale Acque Messina s.p.a. was fined by the Garante for processing employees' biometric data without notification and without requesting prior verification. The authority found that the company breached data protection rules.ITGaranteGDPR€34,000
06 Sept 2012Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined 34,000 EUR by the Garante. The authority found a breach of notification obligations under data protection rules.ITGaranteGDPR€34,000
29 Apr 2026Pianeta s.r.l.Pianeta s.r.l. was fined by the Garante 34,000 EUR for unlawfully processing personal data linked to a loyalty card program. The data were used to initiate disciplinary action against an employee, which breached GDPR requirements.ITGaranteGDPR€34,000
08 Feb 2023DKN.5131.50.2021StatusprawomocnaTytuUODO imposed a PLN 33,012 fine on the controller and the processor for failing to implement appropriate technical and organizational measures to secure personal data. The authority also found that the controller did not verify whether the processor provided sufficient guarantees of GDPR compliance and protection of data subjects' rights.PLUODOGDPR€6,967
21 Jun 2023Dane anonimowe (H. Sp. z o.o. z siedzibą w W. przy Al.)UODO imposed a PLN 33,012 fine on H. Sp. z o.o. The penalty was issued because the company failed to provide the President of the Personal Data Protection Office with access to information necessary to perform supervisory duties.PLUODOGDPR€7,447
01 Jan 2012IDEAS CREATIVAS DE OPERACION S.L.IDEAS CREATIVAS DE OPERACION S.L. was fined EUR 33,001 by the AEPD for sending unsolicited commercial emails despite requests for data cancellation. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€33,001
16 Oct 2013FRANCE TELECOM ESPAÑA, S.A.FRANCE TELECOM ESPAÑA, S.A. was fined by the AEPD for sending commercial emails to a complainant despite a request not to use personal data for advertising purposes. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€33,001
13 Jul 2012NH HOTELES, S.A.NH HOTELES, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant after confirming the cancellation of their personal data. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€33,001
28 Oct 2013LEGALITAS ASISTENCIA LEGAL, S.L.LEGALITAS ASISTENCIA LEGAL, S.L. was fined by the AEPD 33,000 EUR for sending unsolicited commercial communications. The conduct continued despite requests for data cancellation, which breached Article 21 of the LSSI.ESAEPDePrivacy€33,000
04 Jul 2025Niepubliczny Zakład Opieki ZdrowotnejUODO imposed a PLN 32,832 administrative fine on Niepubliczny Zakład Opieki Zdrowotnej for failing to conduct a risk analysis for processing patient data during home visits. The authority also found that appropriate technical and organizational measures to secure the data had not been implemented.PLUODOGDPR€7,733