Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Jun 2021B.B.B.The entity was fined by the AEPD EUR 3,000 for publicly disseminating surveillance footage without justification. The conduct breached data protection principles.ESAEPDGDPR€3,000
10 Jul 2025Comune di ConversanoComune di Conversano was fined €3,000 by the Garante for failing to communicate the contact details of its Data Protection Officer. The breach concerned the obligation under Article 37 GDPR to notify the supervisory authority.ITGaranteGDPR€3,000
01 Jan 2013FLAYBOX S.L.FLAYBOX S.L. was fined by the AEPD in the amount of EUR 3,100 for sending unsolicited promotional emails despite the recipient's request to unsubscribe. The authority found a breach of Articles 21.1 and 21.2 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€3,100
16 Feb 2022Anonymisé (CNPD decision-04-fr-2022)The CNPD found that the companies failed to meet the Article 13 GDPR information obligation toward data subjects, including employees and third parties. The breach concerned the lack of proper notice about data processing activities.LUCNPDGDPR€3,100
01 Jan 2015SOTO GLOBAL SERVICE, S.L.SOTO GLOBAL SERVICE, S.L. was fined by the AEPD €3,200 for sending nine unsolicited commercial emails without prior consent. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€3,200
03 Feb 2023Epic LtdEpic Ltd was fined by the CyDPC in the amount of 3,250 EUR for making unsolicited calls to former customers without a legal basis. The authority also found insufficient technical and organizational measures to ensure compliant data processing and inadequate data security controls.CYCyDPCGDPR€3,250
25 May 2018Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the AEPD for sending unsolicited commercial SMS messages to a non-customer without consent. The case concerns a breach of direct marketing rules and the requirement to obtain prior consent.ESAEPDePrivacy€3,300
12 Jun 2017VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 3,300 EUR for sending commercial communications to a former customer after a request for data cancellation. The authority also noted an allegation of sharing personal data with third parties without consent.ESAEPDePrivacy€3,300
19 Sept 2017CEPSA COMERCIAL PETRÓLEO, S.A.U.CEPSA was fined by the AEPD 3,300 EUR for sending two unsolicited commercial emails without prior consent from the recipients. The authority found this breached Article 21 of the LSSI on commercial communications.ESAEPDePrivacy€3,300
01 Jan 2019VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España, S.A.U. 3,300 EUR for sending unsolicited commercial SMS messages despite the recipient's objection. This conduct breached Article 21 of the LSSI on commercial communications.ESAEPDePrivacy€3,300
23 Jan 2017BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€3,300
21 Nov 2017IBERIA LINEAS AEREAS DE ESPAÑA, S.A. OPERADORA, SOCIEDAD UNIPERSONALIberia was fined by the AEPD in the amount of 3,300 EUR for sending commercial emails without the recipient's consent. The authority found a breach of Article 21.1 of the LSSI on unsolicited electronic communications.ESAEPDePrivacy€3,300
01 Jan 2015CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD in the amount of EUR 3,300. The authority found that the company sent unsolicited advertising emails and failed to properly handle unsubscribe requests, in breach of Article 21 of the LSSI.ESAEPDePrivacy€3,300
01 Jan 2016HAPPY SOCIAL MEDIA, LTDHAPPY SOCIAL MEDIA, LTD was fined by the AEPD EUR 3,400 for sending unsolicited marketing emails. The authority found that the messages did not include a simple opt-out mechanism, which breached the LSSI.ESAEPDePrivacy€3,400
19 Feb 2016Asociación de Empresarios de Tecnologías de la Información y Comunicaciones de Andalucía (ETICOM)ETICOM was fined €3,400 by the AEPD for sending unsolicited commercial emails without prior consent from recipients. The authority also found that the messages did not include a simple opt-out mechanism, in breach of Article 21 of the LSSI.ESAEPDePrivacy€3,400
15 Jul 2021Anonymisé (CNPD decision-27-fr-2021)The company did not meet GDPR requirements to inform individuals about data processing, especially in relation to video surveillance and employee notices. CNPD treated this as a breach of the information obligations owed to data subjects.LUCNPDGDPR€3,500
19 Feb 2015VUELING AIRLINES S.A.VUELING AIRLINES S.A. was fined by the AEPD EUR 3,500 for sending unsolicited commercial emails to the complainant. The conduct breached Article 21.1 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€3,500
23 May 2024Ordine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di MateraOrdine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di Matera was fined 3,500 EUR by the Garante. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization, in the handling of personal data.ITGaranteGDPR€3,500
03 Sept 2019ЧСИThe CPDP fined a private bailiff (ЧСИ) for failing to provide a data subject with access to personal data collected through video surveillance. The authority found a breach of Article 12 GDPR.BGCPDPGDPR€1,790
17 Apr 2026Ausl ModenaAusl Modena was fined by the Garante in the amount of 3,500 EUR for creating duplicate patient records. The case involved processing health data without proper transparency and compliance with data protection rules.ITGaranteGDPR€3,500