BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2022 | Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD EUR 15,000 for processing personal data without a legal basis. The case involved a contract fraudulently created in the complainant's name without consent. | ES | AEPD | GDPR | €15,000 | ↗ |
| 01 Jan 2022 | ANIVERSALIA NETWORKS, S.L.ANIVERSALIA NETWORKS, S.L. was fined €2,000 by the AEPD. The authority found that the website did not provide adequate contact information for individuals to exercise their data protection rights. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2022 | ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP.The company was fined by the AEPD EUR 10,000 for processing personal data without consent. The authority also found that its website privacy information was insufficient, including missing contact details and information on data subject rights. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2022 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for processing personal data without consent. The breach led to unauthorized access to personal data and fraudulent financial transactions. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | GESTERPOOL, S.L.U.The AEPD imposed a 15,000 EUR fine on GESTERPOOL, S.L.U. for unauthorized use of personal data in a commercial call and for contract processing without consent. The case concerns breaches of GDPR rules, including Articles 28 and 58(1). | ES | AEPD | GDPR | €15,000 | ↗ |
| 01 Jan 2022 | JEG'S LIFE STYLE, S.L.JEG'S LIFE STYLE, S.L. was fined by the AEPD 20,000 EUR for breaching data protection rules. The company disclosed private information about a former employee to third parties by email without consent. | ES | AEPD | GDPR | €20,000 | ↗ |
| 01 Jan 2022 | UNIQUEDESIGN & DECOR, S.L.UNIQUEDESIGN & DECOR, S.L. was fined by the AEPD 5,000 EUR for not having an accessible privacy policy on its website. The authority found a breach of Article 13 GDPR because users were not properly provided with the required information. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2022 | CosmoteThe Greek data protection authority imposed a €6 million fine on Cosmote under decision 4/2022. The sanction concerned inadequate security measures and retaining more data than permitted after a 2020 cyberattack. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €6,000,000 | ↗ |
| 01 Jan 2022 | VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD 70,000 EUR for unlawfully accessing a creditworthiness file. The company used an individual's tax ID without legitimate grounds, breaching data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | ADADE BURGOS, S.L.ADADE BURGOS, S.L. was fined by the AEPD EUR 5,000 for improper use of personal data. The company informed clients about an employee's disciplinary dismissal, which breached data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2022 | GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the AEPD for processing a broad range of delivery riders’ personal data without adequate data protection measures. The authority found breaches of GDPR Articles 25 and 32, relating to privacy by design and processing security. | ES | AEPD | GDPR | €550,000 | ↗ |
| 01 Jan 2022 | BANQUETES SANTA ANA, S.L.BANQUETES SANTA ANA, S.L. was fined EUR 5,000 by the AEPD for collecting personal data, including DNI numbers, from wedding guests without providing information about data processing. The authority found a breach of data minimization and transparency obligations. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2022 | B.B.B.B.B.B. was fined 2,000 EUR by the AEPD. The authority found that the company forwarded emails containing personal data without proper authorization, in breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2022 | MUXERS CONCEPT, S.L.MUXERS CONCEPT, S.L. was fined EUR 20,000 by the AEPD for installing an unauthorized audio recording system in employee areas. The authority found this conduct to be in breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 01 Jan 2022 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for unlawfully duplicating a customer's SIM card without consent. The incident led to unauthorized access to the customer's personal and banking data. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | RIANLU EUROPA S.L.RIANLU EUROPA S.L. was fined EUR 30,010 by the AEPD for sending commercial SMS messages without providing recipients with an opt-out mechanism. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €30,010 | ↗ |
| 01 Jan 2022 | INMOBILIARIA MESLLOC, S.L.INMOBILIARIA MESLLOC, S.L. was fined by the AEPD for unlawfully sharing tenants’ personal data with third-party companies without authorization. The authority found this conduct violated Article 6(1) of the GDPR. | ES | AEPD | GDPR | €40,000 | ↗ |
| 31 Dec 2021 | Dane anonimowe (S. Spółka z o.o. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 18,192 on the company. The sanction resulted from failing to provide access to personal data and other information necessary for the authority to perform its duties. | PL | UODO | GDPR | €3,957 | ↗ |
| 23 Dec 2021 | wyżej wymienionąAn administrative fine was imposed on an individual conducting business activity. The violation consisted of failing to provide the President of the Personal Data Protection Office with access to personal data and information necessary to perform his duties. | PL | UODO | GDPR | €983 | ↗ |
| 23 Dec 2021 | Federación Estatal de Servicios, Movilidad y Consumo de la UGT (FESMC-UGT)FESMC-UGT was fined 2,000 EUR by the AEPD for sending emails to employees’ corporate addresses without proper authorization. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |