BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2022 | HOSPITAL POVISA, S.A.HOSPITAL POVISA, S.A. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned the improper inclusion of private health test results in a public health system, which violated the complainant’s privacy. | ES | AEPD | GDPR | €30,000 | ↗ |
| 01 Jan 2022 | FEDERACIÓN DE SERVICIOS A LA CIUDADANÍA DE CCOOThe entity was fined by the AEPD €3,000 for breaching data protection principles. The case involved the improper disclosure of personal data related to a COVID-19 case among employees. | ES | AEPD | GDPR | €3,000 | ↗ |
| 01 Jan 2022 | UNION SINDICAL OBRERAThe labor union UNION SINDICAL OBRERA was fined by the AEPD for failing to comply with a prior decision on the complainant’s right to data deletion. Despite being notified of the obligation to stop, it continued sending emails. | ES | AEPD | GDPR | €3,000 | ↗ |
| 01 Jan 2022 | Unión de Oficiales Guardia Civil ProfesionalThe entity was fined for sending a letter containing personal data without prior consent, in breach of Article 6(1) GDPR. The case concerned unauthorized processing of personal data through the dispatch of correspondence to the data subject. | ES | AEPD | GDPR | €6,000 | ↗ |
| 01 Jan 2022 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without consent. The conduct led to unauthorized contracts and credit reporting issues. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | FUNDACIÓN CIPRI GÓMESFUNDACIÓN CIPRI GÓMES was fined EUR 4,000 by the AEPD for failing to provide information on personal data processing to athletes or their guardians. The authority also found unlawful processing of a minor's personal data after the parents had withdrawn him from the gym. | ES | AEPD | GDPR | €4,000 | ↗ |
| 01 Jan 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 70,000 by the AEPD for disclosing one client's personal address to another client. The authority found a breach of personal data confidentiality obligations under the GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD EUR 15,000 for processing personal data without a legal basis. The case involved a contract fraudulently created in the complainant's name without consent. | ES | AEPD | GDPR | €15,000 | ↗ |
| 01 Jan 2022 | ANIVERSALIA NETWORKS, S.L.ANIVERSALIA NETWORKS, S.L. was fined €2,000 by the AEPD. The authority found that the website did not provide adequate contact information for individuals to exercise their data protection rights. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2022 | ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP.The company was fined by the AEPD EUR 10,000 for processing personal data without consent. The authority also found that its website privacy information was insufficient, including missing contact details and information on data subject rights. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2022 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for processing personal data without consent. The breach led to unauthorized access to personal data and fraudulent financial transactions. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | GESTERPOOL, S.L.U.The AEPD imposed a 15,000 EUR fine on GESTERPOOL, S.L.U. for unauthorized use of personal data in a commercial call and for contract processing without consent. The case concerns breaches of GDPR rules, including Articles 28 and 58(1). | ES | AEPD | GDPR | €15,000 | ↗ |
| 01 Jan 2022 | JEG'S LIFE STYLE, S.L.JEG'S LIFE STYLE, S.L. was fined by the AEPD 20,000 EUR for breaching data protection rules. The company disclosed private information about a former employee to third parties by email without consent. | ES | AEPD | GDPR | €20,000 | ↗ |
| 01 Jan 2022 | UNIQUEDESIGN & DECOR, S.L.UNIQUEDESIGN & DECOR, S.L. was fined by the AEPD 5,000 EUR for not having an accessible privacy policy on its website. The authority found a breach of Article 13 GDPR because users were not properly provided with the required information. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2022 | CosmoteThe Greek data protection authority imposed a €6 million fine on Cosmote under decision 4/2022. The sanction concerned inadequate security measures and retaining more data than permitted after a 2020 cyberattack. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €6,000,000 | ↗ |
| 01 Jan 2022 | VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD 70,000 EUR for unlawfully accessing a creditworthiness file. The company used an individual's tax ID without legitimate grounds, breaching data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | ADADE BURGOS, S.L.ADADE BURGOS, S.L. was fined by the AEPD EUR 5,000 for improper use of personal data. The company informed clients about an employee's disciplinary dismissal, which breached data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2022 | GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the AEPD for processing a broad range of delivery riders’ personal data without adequate data protection measures. The authority found breaches of GDPR Articles 25 and 32, relating to privacy by design and processing security. | ES | AEPD | GDPR | €550,000 | ↗ |
| 01 Jan 2022 | BANQUETES SANTA ANA, S.L.BANQUETES SANTA ANA, S.L. was fined EUR 5,000 by the AEPD for collecting personal data, including DNI numbers, from wedding guests without providing information about data processing. The authority found a breach of data minimization and transparency obligations. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2022 | B.B.B.B.B.B. was fined 2,000 EUR by the AEPD. The authority found that the company forwarded emails containing personal data without proper authorization, in breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |