Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Jun 2023ASOCIACIÓN CANNÁBICA CLUB 26The entity installed surveillance cameras facing public spaces without prior administrative authorization. This may have infringed third-party rights and data protection rules.ESAEPDGDPR€500
27 Mar 2014ING DIRECT NV SUCURSAL EN ESPAÑAING Direct Spain was fined by the AEPD for sending commercial emails to a user after consent had been revoked. The authority found this to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
04 Oct 2021LA ÚLTIMA HORA NOTICIAS, S.L.LA ÚLTIMA HORA NOTICIAS, S.L. was fined by the AEPD EUR 2,000 for installing cookies on users’ devices without prior consent. The authority also found that the website did not provide adequate information about the cookies used.ESAEPDePrivacy€2,000
12 Nov 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for continuing to send billing emails to a complainant despite an arbitration ruling. The ruling required the company to stop all services and delete the complainant’s data, which it failed to do.ESAEPDGDPR€70,000
01 Jan 2016CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD for sending unsolicited advertising emails. The authority also found that the company did not provide an easy opt-out mechanism, in breach of Article 21 of the LSSI.ESAEPDePrivacy€7,000
12 Mar 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 45,000 EUR by the AEPD for sending continuous SMS messages to a complainant despite a prior request to cancel personal data. The authority found this conduct to be a breach of data protection principles.ESAEPDGDPR€45,000
03 Feb 2022B.B.B.The entity was fined by the AEPD 600 EUR for operating a surveillance camera system that excessively recorded private and public areas. The authority found that this infringed personal and family privacy.ESAEPDGDPR€600
20 Dec 2024FUNDACIÓN SOCIEDAD CIENTÍFICA DE ONCOLOGÍA MÉDICAFUNDACIÓN SOCIEDAD CIENTÍFICA DE ONCOLOGÍA MÉDICA was fined 70,000 EUR by the AEPD for a data breach affecting confidentiality. The authority found a violation of Article 5(1)(f) GDPR, which requires personal data to be processed securely and confidentially.ESAEPDGDPR€70,000
13 Jun 2025GRUPO BONATEL SLGRUPO BONATEL SL was fined by the AEPD after an incident in which its database was encrypted and a ransom was demanded to prevent public disclosure. The authority found a breach of Article 5(1)(f) GDPR on integrity and confidentiality of personal data.ESAEPDGDPR€30,000
28 May 2024CUI ZSQ FOOD, S.L.CUI ZSQ FOOD, S.L. was fined by the AEPD 70,000 EUR for using a video surveillance system to intimidate employees. The company shared footage of an employee’s absence in a work chat, which breached data protection rules.ESAEPDGDPR€70,000
10 Sept 2014SAMPLE GESTION S.L.U.SAMPLE GESTION S.L.U. was fined by the AEPD in the amount of 1,100 EUR for sending unsolicited commercial SMS messages despite the recipient's request to opt out. This constituted a breach of Article 21.1 of the LSSI on unsolicited marketing communications.ESAEPDePrivacy€1,100
30 Mar 2021TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 75,000 EUR for using a customer's phone number without consent. This led to numerous unsolicited calls, despite prior claims that security measures had been implemented.ESAEPDGDPR€75,000
02 Oct 2025TIGER MEDIA INC.TIGER MEDIA INC. was fined by the AEPD EUR 120,000 for processing personal data without a lawful basis. The authority also found that the company failed to appoint an EU representative, in breach of GDPR Articles 6 and 27.ESAEPDGDPR€120,000
10 Jan 2025CRUZ ROJA ESPAÑOLACRUZ ROJA ESPAÑOLA was fined EUR 50,000 by the AEPD for a personal data protection breach. The case involved the unauthorized disclosure of patient data in a communication about a change in embryo bank management.ESAEPDGDPR€50,000
23 Oct 2012B.B.B. (VELAS TLC)B.B.B. (VELAS TLC) was fined by the AEPD in the amount of EUR 1,200 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits such communications without prior consent.ESAEPDePrivacy€1,200
18 Apr 2024COMUNIDAD DE PROPIETARIOS R.R.R.The entity was fined for sending an email to all community members containing a list of individual heating consumption linked to specific apartments. The authority found this to be a breach of data protection rules.ESAEPDGDPR€600
19 Nov 2020ALTERNA OPERADOR INTEGRAL, S.L.ALTERNA OPERADOR INTEGRAL, S.L. was fined by the AEPD EUR 50,000 for changing an electricity provider without the customer's consent. The authority found that the processing lacked a valid legal basis under Article 6(1)(b) GDPR.ESAEPDGDPR€50,000
17 May 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide requested information. The case concerns a breach of obligations under data protection rules.ESAEPDGDPR€5,000
01 Jan 2024TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD for issuing a duplicate SIM card without proper consent or identity verification. The failure enabled identity theft and fraudulent transactions.ESAEPDGDPR€300,000
27 Mar 2025NOVATES ALIMENTACIÓN MADRID, S.L.NOVATES ALIMENTACIÓN MADRID, S.L. was fined by the AEPD for a personal data protection breach involving the improper handling of video surveillance footage. The footage was shared via WhatsApp without adequate security measures, increasing the risk of unauthorized access.ESAEPDGDPR€20,000