Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jan 2024CAJA RURAL DE TERUEL, S.C.C.CAJA RURAL DE TERUEL was fined by the AEPD EUR 250,000 for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident.ESAEPDGDPR€250,000
30 Mar 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 150,000 EUR for failing to delete personal data after phone contracts ended. This led to continued SMS notifications with zero-balance invoices being sent to former customers.ESAEPDGDPR€150,000
01 Jan 2015ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 5,000 EUR for sending unsolicited advertising SMS messages. The authority also found that the company did not provide an effective opt-out mechanism for non-customers, in breach of the LSSI.ESAEPDePrivacy€5,000
08 Aug 2022CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. (CASER)CASER was fined 40,000 EUR by the AEPD for modifying insurance policy data without the policyholder’s consent. The authority found that this breached GDPR data processing principles.ESAEPDGDPR€40,000
03 Apr 2023HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined EUR 200,000 by the AEPD for insufficient security measures in its hospital information system. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational safeguards.ESAEPDGDPR€200,000
01 Jan 2015TELEFÓNICA DE ESPAÑA S.A.U.TELEFÓNICA DE ESPAÑA S.A.U. was fined by the AEPD EUR 2,900 for sending unsolicited advertising emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€2,900
19 Feb 2015VUELING AIRLINES S.A.VUELING AIRLINES S.A. was fined by the AEPD EUR 3,500 for sending unsolicited commercial emails to the complainant. The conduct breached Article 21.1 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€3,500
02 Nov 2023KOMPASS SPAIN, S.L.U.KOMPASS SPAIN, S.L.U. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited email messages. The emails were sent despite the recipient’s attempts to unsubscribe and their inclusion on the Robinson List.ESAEPDePrivacy€5,000
14 Jan 2021IDFINANCE SPAIN, S.L.IDFINANCE SPAIN, S.L. was fined by the AEPD EUR 5,000 after an incident in which a user could access another customer's personal data and loan information through a faulty email link. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality.ESAEPDGDPR€5,000
29 Jan 2022COLEGIO VILLAEUROPA, S.C.L.The school was fined by the AEPD in the amount of 5,000 EUR for recording a child's image without parental consent. The authority also found that the school failed to provide adequate information about personal data processing.ESAEPDGDPR€5,000
30 Mar 2023XCOM DIGITAL LAB, S.L.XCOM DIGITAL LAB, S.L. was fined by the AEPD EUR 800 for sending unsolicited commercial emails. The company failed to comply with Article 21 of the LSSI despite repeated requests from the recipient to unsubscribe.ESAEPDePrivacy€800
01 Jan 2013COMERCIAL POLINDUS 21, S.L.COMERCIAL POLINDUS 21, S.L. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited SMS messages. The case concerned Article 21 of the LSSI, which governs commercial communications sent without prior consent.ESAEPDePrivacy€1,200
03 Nov 2020CANARYCLICK CONSULTING SLCANARYCLICK CONSULTING SL was fined EUR 8,000 by the AEPD for improper management of its cookie policy on its websites. The authority also found that user consent was collected in a generic manner, in breach of data protection rules.ESAEPDGDPR€8,000
01 Jan 2012NIGHTBONUS, S.L.NIGHTBONUS, S.L. was fined by the AEPD EUR 1,200 for sending marketing emails without prior recipient consent. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,200
16 Jun 2020REAL SPORTING DE GIJÓN, S.A.D.REAL SPORTING DE GIJÓN, S.A.D. was fined EUR 5,000 by the AEPD for breaching GDPR Article 7 on consent requirements. The case arose from a complaint by the Ministry of Finance concerning advertising practices.ESAEPDGDPR€5,000
15 Apr 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for including personal data in a credit solvency file without proper prior notice. The authority found this to be a breach of data protection rules.ESAEPDGDPR€200,000
01 Jan 2016PROSAD CONSULTORES, S.L.PROSAD CONSULTORES, S.L. was fined by the AEPD 600 EUR for sending unsolicited commercial emails without prior consent. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€600
01 Jan 2016SYNERTEC GROUP, S.L.SYNERTEC GROUP, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails. The recipient was registered on the Robinson List, and the conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
01 Jan 2016FERIA MUESTRARIO INTERNACIONAL DE VALENCIAThe entity collected personal data from children under 14 without providing the required information or obtaining parental consent. The AEPD found this to be a breach of data protection rules.ESAEPDePrivacy€8,000
01 Jan 2024ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. was fined by the AEPD EUR 140,000 for unauthorized access to personal data. The authority found a breach of GDPR confidentiality and security principles.ESAEPDGDPR€140,000