Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 May 2023D.D.D.The entity installed surveillance cameras without authorization, breaching Article 5(1)(c) of the GDPR. The AEPD imposed a fine of EUR 500.ESAEPDGDPR€500
31 May 2024CUMACA MOTOR, S.L.CUMACA MOTOR, S.L. was fined EUR 7,500 by the AEPD for requiring customers to provide a copy of their identity document without a valid justification. The authority found that this breached the GDPR data minimization principle.ESAEPDGDPR€7,500
11 Oct 2023CONSULTORÍA PERITACIONES ALMERIENSES, S.L.The company was fined by the AEPD 1,000 EUR for not having a privacy policy on its website. The issue arose because it collected personal data through a contact form, triggering the information duties under GDPR Article 13.ESAEPDGDPR€1,000
28 Feb 2025DYNAMIC EXPRESS COURIER S.LDYNAMIC EXPRESS COURIER S.L was fined 15,000 EUR by the AEPD for subcontracting without prior authorization and for failing to put proper contracts in place with subcontractors. The authority found this conduct breached GDPR Article 28 on processor arrangements.ESAEPDGDPR€15,000
01 Jan 2022BOOKSY INTERNATIONAL SPOLKA, S.L.BOOKSY INTERNATIONAL SPOLKA, S.L. was fined by the AEPD €500 for sending unsolicited commercial SMS messages. The recipient was registered on the Robinson List, which constituted a breach of Article 21 of the LSSI.ESAEPDePrivacy€500
27 Jul 2016MUDICOM IMPORT S.L.MUDICOM IMPORT S.L. was fined by the AEPD EUR 1,000 for sending unsolicited commercial emails without the recipient's consent. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
21 Oct 2020HEREDAD DE UREÑA, S.L.HEREDAD DE UREÑA, S.L. was fined by the AEPD EUR 4,000 for not having a privacy policy on its website, lacking a cookies policy, and sending unsolicited marketing emails without consent. The case indicates failures in basic transparency obligations and consent requirements for electronic communications.ESAEPDGDPR€4,000
25 Mar 2024KUR KLINIKUM, S.L.KUR KLINIKUM, S.L. was fined EUR 1,000 by the AEPD for failing to comply with a data protection authority resolution. The case concerned the right of access to personal data.ESAEPDGDPR€1,000
08 Mar 2023RING RING CLIN S.L.RING RING CLIN S.L. was fined 500 EUR by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information, which breaches Article 58.1 of the GDPR.ESAEPDGDPR€500
19 Feb 2018AVIS ALQUILE UN COCHE S.A.AVIS ALQUILE UN COCHE S.A. was fined by the AEPD 10,000 EUR for improper handling of personal data. This led to the wrongful publication of an individual's details in the Official State Gazette as the responsible party for a traffic violation they did not commit.ESAEPDGDPR€10,000
09 Mar 2020OLIVEROS USTRELL, S.L.OLIVEROS USTRELL, S.L. was fined 10,000 EUR by the AEPD for unauthorized processing of a customer's personal and banking data. The case involved a fraudulent mobile contract and number portability carried out without a valid legal basis.ESAEPDGDPR€10,000
01 Jan 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for breaching data protection rules. The case concerned deficiencies in the security and integrity of data processing.ESAEPDGDPR€50,000
11 Jun 2024APARTAMENTOS BUENAVISTA HOMEAPARTAMENTOS BUENAVISTA HOME was fined EUR 1,000 by the AEPD for requesting guests to submit electronic images of their ID documents. The authority found that this practice breached the GDPR data minimization principle.ESAEPDGDPR€1,000
01 Jan 2019AVON COSMETICS SAUAVON COSMETICS SAU was fined by the AEPD 60,000 EUR for improper processing of personal data. The company included an individual in a creditworthiness file without first verifying the person’s identity.ESAEPDGDPR€60,000
01 Jan 2024B.B.B.B.B.B. was fined by the AEPD in the amount of 10,000 EUR for publishing a patient's medical photos on social media without consent. The conduct breached GDPR Articles 6(1) and 9, which govern lawful processing and special categories of personal data.ESAEPDGDPR€10,000
07 Sept 2021B.B.B.The entity was fined by the AEPD 5,000 EUR for publicly disseminating surveillance footage without justification. The authority found that this conduct breached data protection principles.ESAEPDGDPR€5,000
01 Jan 2019VIAQUA XESTIÓN INTEGRAL DE AUGAS DE GALICIA, S.A.The company changed contract data without authorization, which constituted a breach of Article 6 of the GDPR. The AEPD imposed a fine of 60,000 EUR.ESAEPDGDPR€60,000
14 Sept 2011BONANZA DIGITAL SERVICES S.L.BONANZA DIGITAL SERVICES S.L. was fined by the AEPD €1,800 for sending unsolicited SMS messages with sexual content. The authority found this breached Article 21 of the LSSI on commercial communications sent without recipient consent.ESAEPDePrivacy€1,800
01 Mar 2017CGPN, SARLCGPN, SARL was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails without prior consent. This conduct breached Spanish data protection rules.ESAEPDePrivacy€2,000
01 Jan 2020Caja Rural San José de Nules S. Cooperativa de Crédito de la Comunidad ValencianaCaja Rural San José de Nules was fined by the AEPD 5,000 EUR for publicly displaying individuals’ personal data on a notice board. The conduct breached data protection principles by exposing their economic status.ESAEPDGDPR€5,000