Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2021RODALI GESTIÓN INMOBILIARIA, S.L.RODALI GESTIÓN INMOBILIARIA, S.L. was fined by the AEPD 5,000 EUR for failing to provide clients with information about the processing of their personal data. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€5,000
24 May 2022MEDLIFE S.A.In April 2022, ANSPDCP completed an investigation into MEDLIFE S.A. and found a breach of GDPR provisions. As a result, a fine of EUR 5,000 was imposed.ROANSPDCPGDPR€5,000
03 Jun 2025Dane anonimowe (Gminny Ośrodek Pomocy Społecznej w K.)UODO imposed an administrative fine of 5,000 PLN on Gminny Ośrodek Pomocy Społecznej w K. The authority found insufficient technical and organizational measures to secure personal data processing, as well as a failure to regularly test and assess the effectiveness of those safeguards.PLUODOGDPR€1,168
04 Dec 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide requested information. The case concerns a breach of obligations under data protection rules.ESAEPDGDPR€5,000
03 Apr 2025SOCIETE SPECIALISEE DANS LE SECTEUR D'ACTIVITE DES SUPERETTES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on SOCIETE SPECIALISEE DANS LE SECTEUR D'ACTIVITE DES SUPERETTES and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€5,000
01 Jan 2021ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINEThe entity was fined by the AEPD for sending advertising emails without the recipients’ consent. It also failed to comply with a request to delete personal data from its databases.ESAEPDePrivacy€5,000
14 Feb 2024PRENSA IBÉRICA MEDIA S.L.PRENSA IBÉRICA MEDIA S.L. was fined by the AEPD in the amount of 5,000 EUR for failing to obtain proper user consent for cookies on its website. The authority found that this practice breached the LSSI requirements on cookies.ESAEPDePrivacy€5,000
16 Jul 2015VUELING AIRLINES S.A.VUELING AIRLINES S.A. was fined by the AEPD 5,000 EUR for sending unsolicited commercial emails to a user who had unsubscribed. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€5,000
07 Oct 2014CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial communications by email. The conduct breached Article 21 of the LSSI, which restricts unwanted marketing messages.ESAEPDePrivacy€5,000
01 Jan 2022ADADE BURGOS, S.L.ADADE BURGOS, S.L. was fined by the AEPD EUR 5,000 for improper use of personal data. The company informed clients about an employee's disciplinary dismissal, which breached data protection rules.ESAEPDGDPR€5,000
02 Apr 2021PAGAMASTARDE, S.L.PAGAMASTARDE, S.L. was fined EUR 5,000 by the AEPD for sending advertising emails after a request for data cancellation had already been confirmed as processed. The authority treated this as a breach of data protection rules.ESAEPDePrivacy€5,000
19 Dec 2024STOMATOLOGUE (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on STOMATOLOGUE under a simplified procedure. The case concerned a breach that resulted in an administrative sanction.FRCNILGDPR€5,000
12 Dec 2024DEUX SOCIETES EXERCANT DES ACTIVITES D'AGENCES DE PRESSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on DEUX SOCIETES EXERCANT DES ACTIVITES D'AGENCES DE PRESSE. Available information indicates a simplified procedure and two fines of EUR 5,000 each.FRCNILGDPR€5,000
14 Jul 2023PARTIDO POPULARPARTIDO POPULAR was fined by the AEPD 5,000 EUR for using an individual's image without consent in its electoral program. The case concerns a breach of data protection rules.ESAEPDGDPR€5,000
08 Feb 2024ADADE BURGOS, S.L.ADADE BURGOS, S.L. was fined by the AEPD 5,000 EUR for improper use of personal data. The company informed clients about an employee’s disciplinary dismissal in a manner that breached data protection rules.ESAEPDGDPR€5,000
07 Dec 2023B.B.B.The educational institution did not inform parents about data processing on Chromebooks used by students. It also failed to have a contract with the data processor, which breaches GDPR Articles 13 and 28.ESAEPDGDPR€5,000
03 Oct 2025INTEGRAL DE VIGILANCIA Y CONTROL, S.L.INTEGRAL DE VIGILANCIA Y CONTROL, S.L. was fined by the AEPD 5,000 EUR for sending emails to a personal email address without a proper legal basis. The authority treated this as a breach of data protection rules.ESAEPDGDPR€5,000
02 Mar 2023Flowers R di Malalan MitjaMalalan Mitja was fined by the Garante in the amount of 5,000 EUR for sending unsolicited promotional emails. The messages were sent to randomly generated email addresses, which constituted a breach of GDPR requirements.ITGaranteGDPR€5,000
05 Jun 2025SOCIETE AYANT POUR ACTIVITE LA FABRICATION ET LE COMMERCE DE PRODUITS PHARMACEUTIQUES DESTINES AU SECTEUR ALIMENTAIRE (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on the company. The decision was issued under a simplified procedure.FRCNILGDPR€5,000
23 Mar 2021ABANCA CORPORACIÓN BANCARIA, S.A.ABANCA CORPORACIÓN BANCARIA, S.A. was fined EUR 5,000 by the AEPD for using cookies on its website without providing the required information to users or obtaining their consent. The case concerns failures to meet legal notice and consent requirements.ESAEPDePrivacy€5,000