Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Jun 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 5,000 by the AEPD for failing to provide requested information. The breach concerned the duty to cooperate with the data protection authority during its proceedings.ESAEPDGDPR€5,000
09 Aug 2022XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined 5,000 EUR by the AEPD for sending commercial SMS messages without the recipient’s consent. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
13 May 2022UNIDAD EDITORIAL INFORMACIÓN GENERAL, S.L.U.The entity published an audio recording of a victim's court testimony without consent. AEPD found this to be a breach of data protection law and imposed a 50,000 EUR fine.ESAEPDGDPR€50,000
18 Mar 2025AUTOESCUELA A.A.A.The AEPD imposed a EUR 500 fine on AUTOESCUELA A.A.A. for failing to respond to a data subject's request for access to and deletion of personal data. The authority also found that the company did not provide the required signage for its video surveillance system, breaching GDPR information duties.ESAEPDGDPR€500
07 Feb 2011EL CORTE INGLES, S.A.EL CORTE INGLES, S.A. was fined 35,000 EUR by the AEPD for sending nine commercial emails without the recipient’s consent. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€35,000
08 Jul 2024COMERCIAL GIRONA DE LLIBRES, S.L.COMERCIAL GIRONA DE LLIBRES, S.L. was fined by the AEPD 20,000 EUR for inadequate security measures. The authority cited, among other issues, the sending of credentials by email, which breached Article 32 of the GDPR.ESAEPDGDPR€20,000
10 Nov 2023VERNE INFORMATION TECHNOLOGY, S.L.VERNE INFORMATION TECHNOLOGY, S.L. was fined 2,000 EUR by the AEPD. The case concerned sending unsolicited commercial electronic communications without prior consent or an existing contractual relationship.ESAEPDePrivacy€2,000
03 Oct 2023ASOCIACIÓN DE PROFESIONALES DE LA SEGURIDAD PRIVADA DE ESPAÑAThe association was fined for sending emails from personal email addresses instead of corporate ones. The authority found that this practice breached GDPR confidentiality and security requirements.ESAEPDGDPR€1,500
26 Oct 2022FUNDACIÓN CITIZENGOFUNDACIÓN CITIZENGO was fined by the AEPD EUR 5,000 for sending unsolicited emails without recipients’ consent. The authority found a breach of Article 7 GDPR on valid consent.ESAEPDGDPR€5,000
01 Jan 2024SANTANDER CONSUMER FINANCE, S.A.Santander Consumer Finance, S.A. was fined by the AEPD 500,000 EUR for a data protection breach. The incident affected personal identification and contact data of 28,120 individuals.ESAEPDGDPR€500,000
30 Oct 2023CLÍNICA PARÍS, S.L.CLÍNICA PARÍS, S.L. was fined 1,000 EUR by the AEPD for failing to properly handle a data subject access request. The authority found a breach of GDPR obligations.ESAEPDGDPR€1,000
01 Jan 2021ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINEThe entity was fined by the AEPD 5,000 EUR for failing to comply with a data deletion request and for sending unsolicited marketing emails without consent. The case indicates non-compliance with data subject rights and rules on direct marketing communications.ESAEPDGDPR€5,000
30 May 2016UNION DISTRIBUIDORA DE EDICIONES DE ARAGON S.L.UNION DISTRIBUIDORA DE EDICIONES DE ARAGON S.L. was fined EUR 800 by the AEPD for sending unsolicited commercial emails. The authority found that the messages continued despite the recipient’s attempts to unsubscribe.ESAEPDePrivacy€800
14 Mar 2011IVY SOLUTIONS S.L.IVY SOLUTIONS S.L. was fined EUR 600 by the AEPD for sending unsolicited commercial emails without the recipient's consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€600
01 Jan 2019IKEA IBERICA, S.A.U.The AEPD fined IKEA IBERICA, S.A.U. 10,000 EUR for installing cookies on users’ devices without obtaining prior informed consent. The authority found this breached Article 22.2 of the LSSI.ESAEPDePrivacy€10,000
25 Mar 2017IMPACTING EMAIL MARKETING SOLUTIONS S.L.IMPACTING EMAIL MARKETING SOLUTIONS S.L. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent. The authority found this conduct to be in breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
25 Feb 2022B.B.B.B.B.B. was fined by the AEPD in the amount of EUR 300 for installing a surveillance camera that captured a public transit area. The footage was then disseminated without consent, which constituted a breach of data protection rules.ESAEPDGDPR€300
21 Mar 2012GROUPON SPAIN SLGROUPON SPAIN SL was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails. The messages were sent despite the recipient's requests to unsubscribe, which breached Article 21 of the LSSI.ESAEPDePrivacy€30,001
11 Apr 2023CORPORACION DE MEDIOS DE EXTREMADURA, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. The authority found a breach of the data minimization principle and imposed a 150,000 EUR fine.ESAEPDGDPR€150,000
04 Nov 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 70,000 EUR for processing a fraudulent phone number portability request without the data subject's consent. The authority found a breach of GDPR Article 6(1).ESAEPDGDPR€70,000