BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Mar 2018 | Ordinanza ingiunzione - 21 marzo 2018 [9004702]The Garante imposed a EUR 92,000 fine on a medical professional for processing the personal data of 23 patients without the required consent. The authority found a breach of privacy and data protection rules. | IT | Garante | GDPR | €92,000 | ↗ |
| 01 Jun 2016 | Ordinanza ingiunzione - 1 giugno 2016 [5423590]A paramedical professional processed clients’ personal data for health purposes without providing the required privacy notice or obtaining consent. The Garante found violations of Articles 13 and 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,400 | ↗ |
| 16 May 2018 | Ordinanza ingiunzione - 16 maggio 2018 [9023208]A general practitioner was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This failure allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Oct 2015 | Ordinanza ingiunzione - 15 ottobre 2015 [4703503]A fine was imposed for activating 85 SIM cards in the names of 31 people without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €93,000 | ↗ |
| 15 Dec 2016 | Ordinanza ingiunzione - 15 dicembre 2016 [6526145]The Garante imposed a EUR 72,000 fine for sending promotional SMS messages without the recipients’ consent. The contact data came from a database obtained through agreements with a German company, which involved the transfer of personal data abroad. | IT | Garante | GDPR | €72,000 | ↗ |
| 15 Apr 2021 | Ordinanza ingiunzione - 15 aprile 2021The case concerned a breach of data protection rules by a healthcare entity. Consent for processing personal data for epidemiological research was obtained improperly. | IT | Garante | GDPR | €5,000 | ↗ |
| 14 Feb 2019 | Ordinanza ingiunzione - 14 febbraio 2019 [9106367]A doctor used the email addresses of former patients to send electoral propaganda without first informing them or obtaining consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 13 Dec 2018 | Ordinanza ingiunzione - 13 dicembre 2018 [9124641]The sole proprietorship acting as an agent for Western Union carried out unauthorized money transfers using personal data without consent. The authority found a breach of data protection rules and imposed a EUR 8,000 fine. | IT | Garante | GDPR | €8,000 | ↗ |
| 17 Dec 2015 | Orange s.r.l.Orange s.r.l. was fined by the Garante in the amount of 8,800 EUR for processing personal data without the required information and consent. The authority also found that the company used a video surveillance system without providing adequate simplified information. | IT | Garante | GDPR | €8,800 | ↗ |
| 27 Jan 2025 | Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 01 Dec 2024 | Orange România SAThe Romanian data protection authority completed an investigation in December 2024 into Orange România SA and found a breach of Article 12(3) GDPR. The case concerned failure to meet the deadline for responding to a data subject access request, resulting in a EUR 40,000 fine. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €40,000 | ↗ |
| 27 Jan 2025 | Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements, creating regulatory risk for organizations processing data in Romania. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 01 Feb 2025 | Orange RomaniaThe Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) fined Orange Romania EUR 40,000 for GDPR violations. The authority found improper handling of personal data deletion requests and excessive collection of identity document copies. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €40,000 | ↗ |
| 01 Jan 2021 | ORANGE ESPAÑA VIRTUAL, S.L.SIMYO was fined for failing to adequately protect personal data, which enabled unauthorized SIM card duplication. The incident led to fraudulent bank transactions and indicates significant security shortcomings. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2015 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 5,000 EUR for sending unsolicited advertising SMS messages. The authority also found that the company did not provide an effective opt-out mechanism for non-customers, in breach of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 17 Dec 2019 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 80,000 by the AEPD for using personal data to fraudulently contract phone lines without consent. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €80,000 | ↗ |
| 17 Mar 2023 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 70,000 by the AEPD for activating a call forwarding service without the user's consent. This led to unauthorized access to the user's bank accounts and transactions. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2021 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 800,000 EUR by the AEPD for failing to adequately protect personal data. The breach enabled identity fraud and unauthorized access to banking information through SIM card duplication. | ES | AEPD | GDPR | €800,000 | ↗ |
| 31 Mar 2021 | ORANGE ESPAGNE, S.A.U.Orange Espagne, S.A.U. was fined by the AEPD 150,000 EUR for violations related to direct marketing communications. The case concerned conduct that may have breached data protection rules. | ES | AEPD | ePrivacy | €150,000 | ↗ |
| 01 Jan 2015 | ORANGE ESPAGNE, S.A.U.JAZZ TELECOM S.A.U. was fined for sending unsolicited SMS advertising to a non-customer. The authority found that the conduct breached the LSSI rules on marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |