Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Sept 2024Top Quality Corporation S.r.l.s.Top Quality Corporation S.r.l.s. was fined by the Garante 5,000 EUR for failing to respond to a data subject’s request to access personal data related to employment. The authority found a breach of GDPR Articles 12 and 15.ITGaranteGDPR€5,000
09 Sept 2025EVELB TÉCNICAS Y SISTEMAS, S.LEVELB TÉCNICAS Y SISTEMAS, S.L was fined by the AEPD 5,000 EUR for breaching Article 5(1)(f) GDPR. The case concerned inadequate data security measures that caused a temporary loss of data availability.ESAEPDGDPR€5,000
21 May 2025SILVANERGIA 2022, S.L.SILVANERGIA 2022, S.L. was fined by the AEPD EUR 5,000 for processing personal data without a legal basis, in breach of Article 6(1) GDPR. The case involved misleading a customer into confirming personal data over the phone.ESAEPDGDPR€5,000
28 Oct 2024Vodafone România S.A.Vodafone România S.A. was fined by ANSPDCP EUR 5,000 for the unauthorized disclosure of email addresses. The breach resulted from failing to use the “BCC” option, which exposed recipients’ data and violated GDPR obligations.ROANSPDCPGDPR€5,000
19 Feb 2024DHL PARCEL IBERIA, S.L.U.DHL Parcel Iberia, S.L.U. was fined by the AEPD 5,000 EUR for failing to implement appropriate technical and organizational measures to ensure security appropriate to the risk, as required by Article 32 GDPR. As a result, personal data, including phone numbers, were exposed on shipping labels.ESAEPDGDPR€5,000
17 May 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide requested information. The case concerns a breach of obligations under data protection rules.ESAEPDGDPR€5,000
16 Jun 2015Eurobank Ergasias AEA fine was imposed for failing to maintain appropriate organizational and technical security measures. This led to unauthorized employee access to the complainant's personal data.GRHDPAGDPR€5,000
01 Jan 2015ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 5,000 EUR for sending unsolicited advertising SMS messages. The authority also found that the company did not provide an effective opt-out mechanism for non-customers, in breach of the LSSI.ESAEPDePrivacy€5,000
02 Nov 2023KOMPASS SPAIN, S.L.U.KOMPASS SPAIN, S.L.U. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited email messages. The emails were sent despite the recipient’s attempts to unsubscribe and their inclusion on the Robinson List.ESAEPDePrivacy€5,000
14 Jan 2021IDFINANCE SPAIN, S.L.IDFINANCE SPAIN, S.L. was fined by the AEPD EUR 5,000 after an incident in which a user could access another customer's personal data and loan information through a faulty email link. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality.ESAEPDGDPR€5,000
29 Jan 2022COLEGIO VILLAEUROPA, S.C.L.The school was fined by the AEPD in the amount of 5,000 EUR for recording a child's image without parental consent. The authority also found that the school failed to provide adequate information about personal data processing.ESAEPDGDPR€5,000
04 Dec 2025PARTI POLITIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on PARTI POLITIQUE under a simplified procedure and issued an injunction. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€5,000
16 Jun 2020REAL SPORTING DE GIJÓN, S.A.D.REAL SPORTING DE GIJÓN, S.A.D. was fined EUR 5,000 by the AEPD for breaching GDPR Article 7 on consent requirements. The case arose from a complaint by the Ministry of Finance concerning advertising practices.ESAEPDGDPR€5,000
01 Jan 2016SYNERTEC GROUP, S.L.SYNERTEC GROUP, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails. The recipient was registered on the Robinson List, and the conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
12 Nov 2019CONFEDERACION GENERAL DEL TRABAJOCONFEDERACION GENERAL DEL TRABAJO was fined by the AEPD €5,000 for disclosing the complainant’s personal data without consent. The disclosure included details of a verbal abuse and harassment case, family relations, pregnancy status, and home address, shared with about 400 union members.ESAEPDGDPR€5,000
04 Apr 2022Anonymised (HDPA 15/2022)The former mayor disclosed a municipal employee’s personal data without consent or a lawful basis. The authority found this to be a breach of GDPR principles of lawfulness and purpose limitation.GRHDPAGDPR€5,000
24 May 2024B.B.B.B.B.B. was fined by the AEPD in the amount of 5,000 EUR for publishing personal data, including images and documents, on a public channel. The authority found a breach of the data minimization principle under GDPR Article 5(1)(c).ESAEPDGDPR€5,000
02 Jan 2024FEDERACIÓN DE SERVICIOS PÚBLICOS DE LA UGT (FSP-UGT)The entity sent emails that disclosed personal data of multiple recipients. The AEPD found a breach of the confidentiality principle under Article 5(1)(f) GDPR.ESAEPDGDPR€5,000
08 Jun 2023AziendaThe company was fined for failing to process personal data in a lawful, fair, and transparent manner. The authority also found breaches of data minimization and inadequate security measures.ITGaranteGDPR€5,000
20 Jun 2022Asociația de Proprietari Aviației ParkAsociația de Proprietari Aviației Park was fined EUR 5,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000