Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Mar 2018Ordinanza ingiunzione - 21 marzo 2018 [9004702]The Garante imposed a EUR 92,000 fine on a medical professional for processing the personal data of 23 patients without the required consent. The authority found a breach of privacy and data protection rules.ITGaranteGDPR€92,000
01 Jun 2016Ordinanza ingiunzione - 1 giugno 2016 [5423590]A paramedical professional processed clients’ personal data for health purposes without providing the required privacy notice or obtaining consent. The Garante found violations of Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€6,400
16 May 2018Ordinanza ingiunzione - 16 maggio 2018 [9023208]A general practitioner was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This failure allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
15 Oct 2015Ordinanza ingiunzione - 15 ottobre 2015 [4703503]A fine was imposed for activating 85 SIM cards in the names of 31 people without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€93,000
15 Dec 2016Ordinanza ingiunzione - 15 dicembre 2016 [6526145]The Garante imposed a EUR 72,000 fine for sending promotional SMS messages without the recipients’ consent. The contact data came from a database obtained through agreements with a German company, which involved the transfer of personal data abroad.ITGaranteGDPR€72,000
15 Apr 2021Ordinanza ingiunzione - 15 aprile 2021The case concerned a breach of data protection rules by a healthcare entity. Consent for processing personal data for epidemiological research was obtained improperly.ITGaranteGDPR€5,000
14 Feb 2019Ordinanza ingiunzione - 14 febbraio 2019 [9106367]A doctor used the email addresses of former patients to send electoral propaganda without first informing them or obtaining consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€16,000
13 Dec 2018Ordinanza ingiunzione - 13 dicembre 2018 [9124641]The sole proprietorship acting as an agent for Western Union carried out unauthorized money transfers using personal data without consent. The authority found a breach of data protection rules and imposed a EUR 8,000 fine.ITGaranteGDPR€8,000
17 Dec 2015Orange s.r.l.Orange s.r.l. was fined by the Garante in the amount of 8,800 EUR for processing personal data without the required information and consent. The authority also found that the company used a video surveillance system without providing adequate simplified information.ITGaranteGDPR€8,800
27 Jan 2025Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€20,000
01 Dec 2024Orange România SAThe Romanian data protection authority completed an investigation in December 2024 into Orange România SA and found a breach of Article 12(3) GDPR. The case concerned failure to meet the deadline for responding to a data subject access request, resulting in a EUR 40,000 fine.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€40,000
27 Jan 2025Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements, creating regulatory risk for organizations processing data in Romania.ROANSPDCPGDPR€20,000
01 Feb 2025Orange RomaniaThe Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) fined Orange Romania EUR 40,000 for GDPR violations. The authority found improper handling of personal data deletion requests and excessive collection of identity document copies.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€40,000
01 Jan 2021ORANGE ESPAÑA VIRTUAL, S.L.SIMYO was fined for failing to adequately protect personal data, which enabled unauthorized SIM card duplication. The incident led to fraudulent bank transactions and indicates significant security shortcomings.ESAEPDGDPR€70,000
01 Jan 2015ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 5,000 EUR for sending unsolicited advertising SMS messages. The authority also found that the company did not provide an effective opt-out mechanism for non-customers, in breach of the LSSI.ESAEPDePrivacy€5,000
17 Dec 2019ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 80,000 by the AEPD for using personal data to fraudulently contract phone lines without consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€80,000
17 Mar 2023ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 70,000 by the AEPD for activating a call forwarding service without the user's consent. This led to unauthorized access to the user's bank accounts and transactions.ESAEPDGDPR€70,000
01 Jan 2021ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 800,000 EUR by the AEPD for failing to adequately protect personal data. The breach enabled identity fraud and unauthorized access to banking information through SIM card duplication.ESAEPDGDPR€800,000
31 Mar 2021ORANGE ESPAGNE, S.A.U.Orange Espagne, S.A.U. was fined by the AEPD 150,000 EUR for violations related to direct marketing communications. The case concerned conduct that may have breached data protection rules.ESAEPDePrivacy€150,000
01 Jan 2015ORANGE ESPAGNE, S.A.U.JAZZ TELECOM S.A.U. was fined for sending unsolicited SMS advertising to a non-customer. The authority found that the conduct breached the LSSI rules on marketing communications.ESAEPDePrivacy€10,000