BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Jan 2024 | CAJA RURAL DE TERUEL, S.C.C.CAJA RURAL DE TERUEL was fined by the AEPD EUR 250,000 for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident. | ES | AEPD | GDPR | €250,000 | ↗ |
| 30 Mar 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 150,000 EUR for failing to delete personal data after phone contracts ended. This led to continued SMS notifications with zero-balance invoices being sent to former customers. | ES | AEPD | GDPR | €150,000 | ↗ |
| 01 Jan 2015 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 5,000 EUR for sending unsolicited advertising SMS messages. The authority also found that the company did not provide an effective opt-out mechanism for non-customers, in breach of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 08 Aug 2022 | CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. (CASER)CASER was fined 40,000 EUR by the AEPD for modifying insurance policy data without the policyholder’s consent. The authority found that this breached GDPR data processing principles. | ES | AEPD | GDPR | €40,000 | ↗ |
| 03 Apr 2023 | HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined EUR 200,000 by the AEPD for insufficient security measures in its hospital information system. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational safeguards. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2015 | TELEFÓNICA DE ESPAÑA S.A.U.TELEFÓNICA DE ESPAÑA S.A.U. was fined by the AEPD EUR 2,900 for sending unsolicited advertising emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent. | ES | AEPD | ePrivacy | €2,900 | ↗ |
| 19 Feb 2015 | VUELING AIRLINES S.A.VUELING AIRLINES S.A. was fined by the AEPD EUR 3,500 for sending unsolicited commercial emails to the complainant. The conduct breached Article 21.1 of the LSSI on marketing communications without prior consent. | ES | AEPD | ePrivacy | €3,500 | ↗ |
| 02 Nov 2023 | KOMPASS SPAIN, S.L.U.KOMPASS SPAIN, S.L.U. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited email messages. The emails were sent despite the recipient’s attempts to unsubscribe and their inclusion on the Robinson List. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 14 Jan 2021 | IDFINANCE SPAIN, S.L.IDFINANCE SPAIN, S.L. was fined by the AEPD EUR 5,000 after an incident in which a user could access another customer's personal data and loan information through a faulty email link. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality. | ES | AEPD | GDPR | €5,000 | ↗ |
| 29 Jan 2022 | COLEGIO VILLAEUROPA, S.C.L.The school was fined by the AEPD in the amount of 5,000 EUR for recording a child's image without parental consent. The authority also found that the school failed to provide adequate information about personal data processing. | ES | AEPD | GDPR | €5,000 | ↗ |
| 30 Mar 2023 | XCOM DIGITAL LAB, S.L.XCOM DIGITAL LAB, S.L. was fined by the AEPD EUR 800 for sending unsolicited commercial emails. The company failed to comply with Article 21 of the LSSI despite repeated requests from the recipient to unsubscribe. | ES | AEPD | ePrivacy | €800 | ↗ |
| 01 Jan 2013 | COMERCIAL POLINDUS 21, S.L.COMERCIAL POLINDUS 21, S.L. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited SMS messages. The case concerned Article 21 of the LSSI, which governs commercial communications sent without prior consent. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 03 Nov 2020 | CANARYCLICK CONSULTING SLCANARYCLICK CONSULTING SL was fined EUR 8,000 by the AEPD for improper management of its cookie policy on its websites. The authority also found that user consent was collected in a generic manner, in breach of data protection rules. | ES | AEPD | GDPR | €8,000 | ↗ |
| 01 Jan 2012 | NIGHTBONUS, S.L.NIGHTBONUS, S.L. was fined by the AEPD EUR 1,200 for sending marketing emails without prior recipient consent. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 16 Jun 2020 | REAL SPORTING DE GIJÓN, S.A.D.REAL SPORTING DE GIJÓN, S.A.D. was fined EUR 5,000 by the AEPD for breaching GDPR Article 7 on consent requirements. The case arose from a complaint by the Ministry of Finance concerning advertising practices. | ES | AEPD | GDPR | €5,000 | ↗ |
| 15 Apr 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for including personal data in a credit solvency file without proper prior notice. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2016 | PROSAD CONSULTORES, S.L.PROSAD CONSULTORES, S.L. was fined by the AEPD 600 EUR for sending unsolicited commercial emails without prior consent. This conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 01 Jan 2016 | SYNERTEC GROUP, S.L.SYNERTEC GROUP, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails. The recipient was registered on the Robinson List, and the conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jan 2016 | FERIA MUESTRARIO INTERNACIONAL DE VALENCIAThe entity collected personal data from children under 14 without providing the required information or obtaining parental consent. The AEPD found this to be a breach of data protection rules. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 01 Jan 2024 | ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. was fined by the AEPD EUR 140,000 for unauthorized access to personal data. The authority found a breach of GDPR confidentiality and security principles. | ES | AEPD | GDPR | €140,000 | ↗ |