Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Oct 2014Wangjun JiWangjun Ji was fined EUR 2,400 by the Italian supervisory authority, Garante. The case concerned a failure to provide the required information to data subjects about the processing of personal data through a video surveillance system at a massage and beauty center.ITGaranteGDPR€2,400
03 Jul 2025WALLAPOP, S.L.WALLAPOP, S.L. was fined by the AEPD in the amount of 5,000 EUR for using cookies without properly informing users or obtaining their consent. The authority found this conduct to be in breach of the LSSI.ESAEPDePrivacy€5,000
01 Jan 2024WAGESTREAM SPAIN S.L.U.WAGESTREAM SPAIN S.L.U. was fined by the AEPD for processing employees’ personal data without proper consent. The case involved names, personal email addresses, bank account numbers, and salary details, in breach of Article 6(1) GDPR.ESAEPDGDPR€2,000
17 Sept 2019vzw YThe Litigation Chamber fined vzw Y for failing to respond properly to a data subject’s requests for access to and erasure of personal data. The authority found breaches of GDPR Articles 12, 15, and 17.BEAPDGDPR€2,000
28 Apr 2026vzwDecision on the merits No. 94/2026 of 28 April 2026 was issued by the Belgian Gegevensbeschermingsautoriteit. A Belgian vzw was fined EUR 1,000 for failing to respond to registered letters and failing to appear at the hearing, which was treated as a breach of the GDPR cooperation duty.BEGegevensbeschermingsautoriteit (GBA)GDPR€1,000
07 May 2015V.V.S. s.r.l. Viaggi Vacanze Soggiorni StudioV.V.S. s.r.l. was fined by the Italian data protection authority, Garante, in the amount of €2,400. The case concerned the collection of personal data through website forms without providing the required privacy notice, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
08 Jan 2024VUKMAL TRADE, S.L.VUKMAL TRADE, S.L. was fined by the AEPD €2,000 for requiring an employee to use a personal mobile phone for work purposes without consent. The company also shared the employee’s personal number with other staff, breaching data protection principles.ESAEPDGDPR€2,000
24 Sept 2019VUELING AIRLINES, S.L.VUELING AIRLINES, S.L. was fined by the AEPD 30,000 EUR for failing to comply with cookie consent requirements on its website. The authority found that the company did not provide the required information and did not properly obtain user consent.ESAEPDePrivacy€30,000
17 Jul 2015VUELING AIRLINES, S.A.VUELING AIRLINES, S.A. was fined by the AEPD 5,000 EUR for sending unsolicited commercial emails to a user who had previously unsubscribed. The authority found this breached article 21.1 of the LSSI.ESAEPDePrivacy€5,000
28 Mar 2022VUELING AIRLINES, S.A.Vueling Airlines, S.A. was fined EUR 30,000 by the AEPD for breaching data protection rules. The company required customers to accept commercial data sharing in order to purchase tickets on its website, without providing an option to refuse cookies.ESAEPDePrivacy€30,000
19 Feb 2015VUELING AIRLINES S.A.VUELING AIRLINES S.A. was fined by the AEPD EUR 3,500 for sending unsolicited commercial emails to the complainant. The conduct breached Article 21.1 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€3,500
16 Jul 2015VUELING AIRLINES S.A.VUELING AIRLINES S.A. was fined by the AEPD 5,000 EUR for sending unsolicited commercial emails to a user who had unsubscribed. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€5,000
09 Oct 2019Vreau Credit S.R.L.Vreau Credit S.R.L. was fined by ANSPDCP in the amount of 20,000 EUR for failing to notify a personal data breach without undue delay. The company had been aware of the incident since December 2018 but did not inform the supervisory authority promptly.ROANSPDCPGDPR€20,000
09 Oct 2019Vreau Credit S.R.L.Vreau Credit S.R.L. was fined by ANSPDCP for failing to notify the supervisory authority of a data breach without undue delay and for unauthorized processing of personal data. The violations resulted in a loss of data confidentiality and indicate inadequate compliance controls.ROANSPDCPGDPR€150,000
24 Mar 2020VOX ESPAÑAVOX ESPAÑA was fined by the AEPD 1,500 EUR for retaining personal data after a deletion request. The case also involved sending an email to a former member despite consent being withdrawn, which breached GDPR requirements.ESAEPDGDPR€1,500
28 Aug 2023VOX ESPAÑAVOX ESPAÑA was fined by the AEPD EUR 1,000 for failing to properly sign its surveillance cameras and for capturing an excessive area of public space. The authority found breaches of GDPR data minimisation and transparency obligations.ESAEPDGDPR€1,000
05 May 2026VOX ESPAÑAVOX ESPAÑA was fined by the AEPD 500 EUR for publishing personal data on Facebook without proper consent. The authority found that this breached Article 6 of the GDPR.ESAEPDGDPR€500
08 Jun 2020Volt munkavállaló munkavégzési célú elektronikus leveleihez való hozzáféréseThe controller unlawfully denied access to the complainant's archived personal emails from 2018. It also failed to provide transparent information about the actions taken in response to the data subject's request.HUNAIHGDPR€582
11 Dec 2019Volt munkavállaló e-mail-fiókjai archivált tartalmának tárolása és azokban történő dokumentumkeresésThe controller stored the complainant’s private correspondence without a lawful basis and searched archived email accounts for documents. The authority found a breach of data minimization and fairness principles.HUNAIHGDPR€1,510
23 Jul 2024VOLTIUM CONSULTORES 2020, S.L.VOLTIUM CONSULTORES 2020, S.L. was fined by the AEPD in the amount of EUR 600 for failing to provide access to information under Article 58(1) of the GDPR. The case concerns a breach of cooperation and transparency obligations toward the supervisory authority.ESAEPDGDPR€600