Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2024COMUNIDAD DE PROPIETARIOS L.L.L.COMUNIDAD DE PROPIETARIOS L.L.L. was fined by the AEPD 2,000 EUR for posting a list of debtor co-owners in a publicly accessible area and for sending erroneous debtor lists by email without justification. The authority found that these actions breached data protection principles.ESAEPDGDPR€2,000
01 Jan 2024UAB VintedUAB Vinted received a EUR 2.385 million GDPR fine in Lithuania. The authority cited issues in user data processing, handling of data subject rights, and risk management.LTValstybinė duomenų apsaugos inspekcijaGDPR€2,385,000
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 120,000 EUR for a data protection breach involving unauthorized SIM card duplication. The incident enabled fraudulent activity, and the authority found that the company had not implemented sufficient preventive measures.ESAEPDGDPR€120,000
01 Jan 2024WAGESTREAM SPAIN S.L.U.WAGESTREAM SPAIN S.L.U. was fined by the AEPD for processing employees’ personal data without proper consent. The case involved names, personal email addresses, bank account numbers, and salary details, in breach of Article 6(1) GDPR.ESAEPDGDPR€2,000
01 Jan 2024UNIVERSITAS NEBRISSENSIS, S.A.UNIVERSITAS NEBRISSENSIS, S.A. was fined by the AEPD EUR 50,000 for requesting a full copy of a student's ID. The authority found that this breached GDPR data minimization principles and security requirements.ESAEPDGDPR€50,000
01 Jan 2024ESCOLA LES CAROLINES COOP. V.The school was fined by the AEPD 10,000 EUR for processing a minor’s image without a lawful basis. The child’s photograph was displayed on posters inside the school premises, which was found to breach GDPR Article 6(1).ESAEPDGDPR€10,000
01 Jan 2024ACTIVOS INTELIGENTES, S.L.ACTIVOS INTELIGENTES, S.L. was fined by the AEPD 5,000 EUR for requiring guests to submit selfies with their ID cards during check-in. The authority found the data collection excessive and not properly justified or explained in terms of processing purposes.ESAEPDGDPR€5,000
01 Jan 2024SUPERVISTA OPTICS SLUSUPERVISTA OPTICS SLU was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a user who had previously opted out. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€20,000
01 Jan 2024INCIBEINCIBE was fined EUR 2,000 by the AEPD for failing to implement data protection by design and by default, in breach of Article 25 GDPR. The procedure concerning the alleged breach of Article 5(1)(f) was dismissed because no serious threat to rights and freedoms was found.ESAEPDGDPR€2,000
01 Jan 2024GASEXPRESS PATRAIX, S.L.GASEXPRESS PATRAIX, S.L. was fined by the AEPD 25,000 EUR for allowing unauthorized access to previous users' data in its automated gas station system. The exposed information included DNI numbers and partial credit card numbers.ESAEPDGDPR€25,000
01 Jan 2024AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD 2,000 EUR for improperly accessing personal data linked to a phone number without the owner's consent. The authority found a breach of Article 7 of the GDPR.ESAEPDGDPR€2,000
01 Jan 2024MAD COOL FESTIVAL, S.L.MAD COOL FESTIVAL, S.L. was fined 3,500 EUR by the AEPD for a data breach on its website. The incident exposed users’ personal data, indicating non-compliance with GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€3,500
01 Jan 2024COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company was fined EUR 80,000 by the AEPD for processing a gas contract without the complainant's consent. It used personal data without authorization, which constitutes a breach of data protection law.ESAEPDGDPR€80,000
01 Jan 2024XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD for failing to ensure the security and confidentiality of personal data. The incident resulted in a data breach and created a risk of identity theft.ESAEPDGDPR€4,000,000
01 Jan 2024FLEXICAR IBÉRICA, S.L.FLEXICAR IBÉRICA, S.L. was fined €50,000 by the AEPD for a personal data breach. The incident occurred when information belonging to other clients was mistakenly shared via WhatsApp.ESAEPDGDPR€50,000
01 Jan 2024a small recruitment bureauA small recruitment bureau in the Netherlands was fined EUR 6,000 by the Autoriteit Persoonsgegevens for failing to respond on time to an ex-candidate’s request to delete personal data. The Raad van State upheld the fine in case ECLI:NL:RVS:2024:2221.NLAutoriteit PersoonsgegevensGDPR€6,000
01 Jan 2024FRUTAS CALISA, S.L.FRUTAS CALISA, S.L. was fined 300 EUR by the AEPD for contacting an individual via WhatsApp without prior consent. The authority found this conduct to be a breach of Article 6(1) GDPR.ESAEPDGDPR€300
01 Jan 2024EXCEL HOTELS & RESORTS, S.A.EXCEL HOTELS & RESORTS, S.A. was fined by the AEPD 40,000 EUR for leaving property owners’ personal data unattended, including ID and passport numbers. The authority found that this created unauthorized access to sensitive personal information and breached data protection principles.ESAEPDGDPR€40,000
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 130,000 EUR for unauthorized SIM card duplication. The incident led to identity theft and fraudulent charges, and the authority found the data protection measures insufficient.ESAEPDGDPR€130,000
01 Jan 2024EDP SOLAR ESPAÑA, S.A.EDP SOLAR ESPAÑA, S.A. was fined by the AEPD for failing to meet data protection obligations. The breach concerned Article 5(1)(c) of the GDPR, which requires data minimization.ESAEPDGDPR€70,000