BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Sept 2025 | ILVA A/SVestre Landsret upheld a DKK 1.5 million GDPR fine against ILVA A/S. The case concerned retention of data on about 385,000 customers without a deletion policy, and the fine was based on the group’s total turnover. | DK | Datatilsynet | GDPR | €200,000 | ↗ |
| 26 Jan 2024 | Allium UPI OÜEstonia’s Data Protection Inspectorate fined Allium UPI OÜ, operator of the Apotheka loyalty program, 3 million euros. The authority found that the company failed to protect customer data and used inadequate security measures, exposing the data of more than 750,000 people. | EE | Andmekaitse Inspektsioon | GDPR | €3,000,000 | ↗ |
| 08 Feb 2024 | AREIA CONSULTING, LTDAREIA CONSULTING, LTD was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial emails without prior recipient consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 23 Jun 2023 | LINKEDIN IRELAND LIMITEDThe AEPD fined LinkedIn Ireland Limited EUR 10,000 for sending advertising emails after the recipient had opted out. The authority found a breach of Article 21.1 of the LSSI governing unsolicited marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 14 Apr 2010 | Espectáculos InterfaceEspectáculos Interface was fined EUR 1,200 by the AEPD for sending commercial emails without prior consent from recipients. The case concerned Article 21 of the LSSI, which governs unsolicited commercial communications. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 09 Mar 2023 | EASYJET AIRLINE COMPANY LIMITEDEasyJet Airline Company Limited was fined by the AEPD 10,000 EUR for failing to provide timely access to personal data requested by an individual. The authority found a breach of Article 15 GDPR, which governs the right of access. | ES | AEPD | GDPR | €10,000 | ↗ |
| 12 Feb 2020 | AEMA HISPANICA, S.L.AEMA HISPANICA, S.L. was fined by the AEPD 6,000 EUR for sending one employee's payroll to another employee. The incident constituted a breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 25 Jul 2021 | CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L.The company was fined by the AEPD for processing personal data without consent, which breaches Article 6 of the GDPR. The case indicates that no valid legal basis was in place for the processing activity. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2015 | LA QUINIELA INTELIGENTE S.L.LA QUINIELA INTELIGENTE S.L. was fined by the AEPD EUR 1,800 for sending unsolicited commercial emails. The messages did not provide recipients with an opt-out mechanism, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,800 | ↗ |
| 28 Apr 2026 | RESIDENCIAL ETXE-LAN, S.L.RESIDENCIAL ETXE-LAN, S.L. was fined by the AEPD for failing to provide the required information to the supervisory authority. The breach concerned Article 58(1) GDPR and hindered the authority’s supervisory powers. | ES | AEPD | GDPR | €3,000 | ↗ |
| 23 Mar 2023 | B.B.B.B.B.B. was fined 300 EUR by the AEPD for installing surveillance cameras that could capture images of a neighboring property without prior authorization. The authority found this to be a breach of the data minimization principle under Article 5(1)(c) GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 07 Mar 2012 | INSTITUTO TECNOLOGICO AUTESEL SLINSTITUTO TECNOLOGICO AUTESEL SL was fined by the AEPD EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 19 Apr 2023 | MULTIGAS ASESORES S.L.MULTIGAS ASESORES S.L. was fined EUR 500 by the AEPD. The company failed to provide access required under Article 58(1) GDPR, obstructing the data protection authority’s inspection function. | ES | AEPD | GDPR | €500 | ↗ |
| 27 Oct 2014 | TRADEINN RETAIL SERVICES, S.L.TRADEINN RETAIL SERVICES, S.L. was fined EUR 60,000 by the AEPD for sending unsolicited commercial emails to a non-customer. The authority found this breached Article 21 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €60,000 | ↗ |
| 03 Mar 2024 | FUNDACIÓN C.R.E.T.A. CENTRO PARA EL ESTUDIO Y REPRESENTACIÓN DEL TEATRO ANTIGUOThe organization failed to properly handle a data subject access request. AEPD imposed a fine of 1,000 EUR for non-compliance with GDPR obligations. | ES | AEPD | GDPR | €1,000 | ↗ |
| 30 Jan 2021 | DEGOM, S.A.DEGOM, S.A. was fined EUR 3,000 by the AEPD for failing to display cookie warnings and data protection acceptance checkboxes on its website. The case concerned deficiencies in online transparency and user consent requirements. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jan 2020 | B.B.B.B.B.B. was fined by the AEPD in the amount of 1,000 EUR for sending a commercial SMS to the complainant after confirming deletion of the complainant’s personal data. The authority found this conduct to be a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 29 Nov 2019 | GRUPO VALSOR Y LOSAN, S.L.The real estate management company improperly disclosed personal data of third parties during a property purchase process. This constituted a breach of data protection rules and led to a fine imposed by the AEPD. | ES | AEPD | GDPR | €2,500 | ↗ |
| 01 Jan 2017 | A DOS RUEDAS EN LA RED, SLA DOS RUEDAS EN LA RED, SL was fined EUR 2,200 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent. | ES | AEPD | ePrivacy | €2,200 | ↗ |
| 05 Jun 2020 | EDP Energía, S.A.U.EDP Energía, S.A.U. was fined €50,000 by the AEPD for processing personal data without consent. The authority found this conduct to be in breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |