BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2019 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALIberia was fined by the AEPD 20,000 EUR for continuing to send emails to a customer who had requested removal from the loyalty program and deletion of personal data. The authority found this conduct to be a breach of GDPR Article 6. | ES | AEPD | GDPR | €20,000 | ↗ |
| 01 Jan 2018 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALThe AEPD fined Iberia 5,700 EUR for sending unsolicited commercial emails to a complainant. The company had previously confirmed the cancellation of the complainant’s personal data, yet it continued marketing communications, breaching Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €5,700 | ↗ |
| 03 Jul 2020 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALIberia was fined by the AEPD 40,000 EUR for failing to provide the complainant access to their personal data, including telephone recordings. The authority found a breach of the right of access to personal data. | ES | AEPD | GDPR | €40,000 | ↗ |
| 24 Jul 2020 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALThe AEPD fined Iberia Líneas Aéreas de España, S.A. Operadora Unipersonal 30,000 EUR. The authority found that the website did not provide users with an option to reject cookies in line with consent requirements. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 21 Nov 2017 | IBERIA LINEAS AEREAS DE ESPAÑA, S.A. OPERADORA, SOCIEDAD UNIPERSONALIberia was fined by the AEPD in the amount of 3,300 EUR for sending commercial emails without the recipient's consent. The authority found a breach of Article 21.1 of the LSSI on unsolicited electronic communications. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 07 Sept 2023 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORAIberia was fined by the AEPD EUR 50,000 for a breach related to personal data handling during a flight from Quito to Dublin. Passengers were asked to provide identity documents and marriage certificates to justify travel during COVID-19 restrictions. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2024 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined by the AEPD for failing to ensure the integrity and confidentiality of personal data and for conducting an inadequate risk analysis and impact assessment. The deficiencies led to data breaches involving third-party systems, indicating weaknesses in operational and oversight controls. | ES | AEPD | GDPR | €1,040,000 | ↗ |
| 07 Feb 2022 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined €30,000 by the AEPD for using non-essential cookies on its website without obtaining prior user consent. The case concerns non-compliance with cookie consent rules and related user information requirements. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 01 Jan 2012 | IBEREXPERT GRUPO CONSULTOR INFORMATICO, S.L.IBEREXPERT GRUPO CONSULTOR INFORMATICO, S.L. was fined by the AEPD in the amount of 6,000 EUR for sending unsolicited commercial communications after a request to stop. The conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 22 Oct 2019 | IBERDROLA COMERCIALIZACIÓN DE ÚLTIMO RECURSO, S.A.U. (CURENERGIA COMERCIALIZADORA DE ULTIMO RECURSO, S.A.U.)CURENERGIA was fined EUR 75,000 by the AEPD for using a former client's personal data without consent. The data was used to carry out a fraudulent contract registration. The case indicates a breach of lawful processing and personal data protection requirements. | ES | AEPD | GDPR | €75,000 | ↗ |
| 13 Jan 2022 | IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 70,000 by the AEPD for changing an electricity supply contract without the customer's knowledge or consent. The authority found that this conduct breached data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 08 Apr 2024 | IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including personal data in a credit information system without proper notification. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 29 Apr 2026 | IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 1,000,000 by the AEPD for failing to implement adequate technical and organizational security measures. The authority found that the company did not properly verify customer identity, which constitutes a breach of Article 32 GDPR. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 24 Mar 2021 | IBERDROLA CLIENTES, SAUIberdrola Clientes, SAU was fined EUR 70,000 by the AEPD for changing the contracted power in a supply agreement without the consent of the contract holder. The authority found that this conduct breached data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 19 Jun 2020 | IBERDROLA CLIENTES, SAUThe AEPD fined IBERDROLA CLIENTES, SAU EUR 40,000 for emailing a customer's electricity bill, which contained sensitive personal data, to an unrelated third party. The incident indicates a breach of confidentiality and personal data protection obligations. | ES | AEPD | GDPR | €40,000 | ↗ |
| 06 Mar 2020 | IBERDROLA CLIENTES, SAUIBERDROLA CLIENTES, SAU was fined by the AEPD in the amount of EUR 5,000 for failing to provide requested information to the data protection authority. The conduct breached Article 58(1) of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 20 Sept 2019 | IBERDROLA CLIENTES, SAUIBERDROLA CLIENTES, SAU was fined by the AEPD 10,000 EUR for including personal data in the SOLCENT file without the required authorization. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 28 Jan 2022 | IBERCAJA BANCO, S.A.IBERCAJA BANCO, S.A. was fined by the AEPD EUR 100,000 for unlawfully processing personal data linked to a family inheritance matter. The breach included opening a bank account for a minor without consent and disclosing personal data to third parties without authorization. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Oct 2024 | IBERCAJA BANCO, S.A.Ibercaja Banco, S.A. accessed personal data in the BADEXCUG EXPERIAN file 47 times without consent after the contractual relationship ended. The AEPD found this to be a breach of data protection rules and imposed a 300,000 EUR fine. | ES | AEPD | GDPR | €300,000 | ↗ |
| 24 Jan 2026 | IBERANUNCIOS SLIBERANUNCIOS SL was fined by the AEPD EUR 15,000 for a data protection breach. The incident allowed unauthorized access to personal data, breaching the confidentiality principle under GDPR. | ES | AEPD | GDPR | €15,000 | ↗ |