Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Sept 2025ILVA A/SVestre Landsret upheld a DKK 1.5 million GDPR fine against ILVA A/S. The case concerned retention of data on about 385,000 customers without a deletion policy, and the fine was based on the group’s total turnover.DKDatatilsynetGDPR€200,000
26 Jan 2024Allium UPI OÜEstonia’s Data Protection Inspectorate fined Allium UPI OÜ, operator of the Apotheka loyalty program, 3 million euros. The authority found that the company failed to protect customer data and used inadequate security measures, exposing the data of more than 750,000 people.EEAndmekaitse InspektsioonGDPR€3,000,000
08 Feb 2024AREIA CONSULTING, LTDAREIA CONSULTING, LTD was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial emails without prior recipient consent. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€2,000
23 Jun 2023LINKEDIN IRELAND LIMITEDThe AEPD fined LinkedIn Ireland Limited EUR 10,000 for sending advertising emails after the recipient had opted out. The authority found a breach of Article 21.1 of the LSSI governing unsolicited marketing communications.ESAEPDePrivacy€10,000
14 Apr 2010Espectáculos InterfaceEspectáculos Interface was fined EUR 1,200 by the AEPD for sending commercial emails without prior consent from recipients. The case concerned Article 21 of the LSSI, which governs unsolicited commercial communications.ESAEPDePrivacy€1,200
09 Mar 2023EASYJET AIRLINE COMPANY LIMITEDEasyJet Airline Company Limited was fined by the AEPD 10,000 EUR for failing to provide timely access to personal data requested by an individual. The authority found a breach of Article 15 GDPR, which governs the right of access.ESAEPDGDPR€10,000
12 Feb 2020AEMA HISPANICA, S.L.AEMA HISPANICA, S.L. was fined by the AEPD 6,000 EUR for sending one employee's payroll to another employee. The incident constituted a breach of data protection rules.ESAEPDGDPR€6,000
25 Jul 2021CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L.The company was fined by the AEPD for processing personal data without consent, which breaches Article 6 of the GDPR. The case indicates that no valid legal basis was in place for the processing activity.ESAEPDGDPR€5,000
01 Jan 2015LA QUINIELA INTELIGENTE S.L.LA QUINIELA INTELIGENTE S.L. was fined by the AEPD EUR 1,800 for sending unsolicited commercial emails. The messages did not provide recipients with an opt-out mechanism, which breached Article 21 of the LSSI.ESAEPDePrivacy€1,800
28 Apr 2026RESIDENCIAL ETXE-LAN, S.L.RESIDENCIAL ETXE-LAN, S.L. was fined by the AEPD for failing to provide the required information to the supervisory authority. The breach concerned Article 58(1) GDPR and hindered the authority’s supervisory powers.ESAEPDGDPR€3,000
23 Mar 2023B.B.B.B.B.B. was fined 300 EUR by the AEPD for installing surveillance cameras that could capture images of a neighboring property without prior authorization. The authority found this to be a breach of the data minimization principle under Article 5(1)(c) GDPR.ESAEPDGDPR€300
07 Mar 2012INSTITUTO TECNOLOGICO AUTESEL SLINSTITUTO TECNOLOGICO AUTESEL SL was fined by the AEPD EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€600
19 Apr 2023MULTIGAS ASESORES S.L.MULTIGAS ASESORES S.L. was fined EUR 500 by the AEPD. The company failed to provide access required under Article 58(1) GDPR, obstructing the data protection authority’s inspection function.ESAEPDGDPR€500
27 Oct 2014TRADEINN RETAIL SERVICES, S.L.TRADEINN RETAIL SERVICES, S.L. was fined EUR 60,000 by the AEPD for sending unsolicited commercial emails to a non-customer. The authority found this breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€60,000
03 Mar 2024FUNDACIÓN C.R.E.T.A. CENTRO PARA EL ESTUDIO Y REPRESENTACIÓN DEL TEATRO ANTIGUOThe organization failed to properly handle a data subject access request. AEPD imposed a fine of 1,000 EUR for non-compliance with GDPR obligations.ESAEPDGDPR€1,000
30 Jan 2021DEGOM, S.A.DEGOM, S.A. was fined EUR 3,000 by the AEPD for failing to display cookie warnings and data protection acceptance checkboxes on its website. The case concerned deficiencies in online transparency and user consent requirements.ESAEPDePrivacy€3,000
01 Jan 2020B.B.B.B.B.B. was fined by the AEPD in the amount of 1,000 EUR for sending a commercial SMS to the complainant after confirming deletion of the complainant’s personal data. The authority found this conduct to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,000
29 Nov 2019GRUPO VALSOR Y LOSAN, S.L.The real estate management company improperly disclosed personal data of third parties during a property purchase process. This constituted a breach of data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€2,500
01 Jan 2017A DOS RUEDAS EN LA RED, SLA DOS RUEDAS EN LA RED, SL was fined EUR 2,200 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€2,200
05 Jun 2020EDP Energía, S.A.U.EDP Energía, S.A.U. was fined €50,000 by the AEPD for processing personal data without consent. The authority found this conduct to be in breach of Article 6(1) of the GDPR.ESAEPDGDPR€50,000