Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Aug 2025EXTRA MADRID, S.L.EXTRA MADRID, S.L. sent personalized postal advertising without the recipient’s consent. The AEPD found this to be a breach of Article 6 GDPR and imposed a fine of 1,000 EUR.ESAEPDGDPR€1,000
08 Aug 2022EUROPYMES SERVICIOS INTEGRALES S.L.EUROPYMES SERVICIOS INTEGRALES S.L. failed to comply with a data deletion request, which constitutes a breach of Article 17 GDPR. The AEPD imposed a fine of EUR 1,000, later reduced due to early payment.ESAEPDGDPR€1,000
21 Jun 2021GSMA LTD.GSMA LTD. was fined by the AEPD for requiring biometric data, including passport details and photos, for facial recognition at the Mobile World Congress without a valid legal basis. The authority found a breach of data protection rules.ESAEPDGDPR€200,000
24 Jun 2024WWPD CINVENTO INTERNATIONAL PATENT TRADING, S.L.The entity sent postal advertising to an individual without any prior commercial relationship, using data from the Official Industrial Property Bulletin. The authority found this to be a breach of data protection rules.ESAEPDGDPR€500
11 Dec 2019VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined EUR 5,000 by the Spanish Data Protection Agency (AEPD). The sanction concerned the failure to provide requested information, which breached GDPR requirements.ESAEPDGDPR€5,000
01 Jan 2013CONSIGNALIA, S.L.CONSIGNALIA, S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited promotional emails. The authority found that this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€600
06 Jun 2024WORLD 2 MEET, S.L.WORLD 2 MEET, S.L. was fined EUR 70,000 by the AEPD for requesting excessive personal data from guests during traveler registration. The company required full copies of identity documents, which breached the data minimization principle.ESAEPDGDPR€70,000
11 Mar 2025UNIÓN DE CRÉDITO PARA LA FINANC. MOB. E INMOB., CREDIFIMO, E.F.C., SAUCREDIFIMO was fined by the AEPD for unlawfully processing personal data by including an individual's data in a credit file without a lawful basis. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€200,000
20 Dec 2021B.B.B.A video recording showing an individual being assaulted was shared via WhatsApp without that person's consent. The AEPD found a breach of Article 6(1) GDPR.ESAEPDGDPR€2,000
24 Mar 2010A.A.A.A.A.A. was fined EUR 600 by the AEPD for sending unsolicited commercial emails without recipient consent. The company also failed to provide information on how to exercise the right of cancellation, breaching Article 21 of the LSSI.ESAEPDePrivacy€600
18 Apr 2023VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 140,000 EUR for a data protection breach involving incorrect billing information. A customer's mobile line was charged under another person's name, indicating an error in the processing of personal data.ESAEPDGDPR€140,000
13 Jun 2023JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SATThe entity was fined by the AEPD for installing a video surveillance system with inadequate signage. The notices did not identify the data controller or provide contact details for exercising data subject rights, breaching Article 13 GDPR.ESAEPDGDPR€500
13 Oct 2025BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 400,000 EUR for failing to implement adequate technical and organizational measures to ensure data integrity and confidentiality. The deficiency resulted in unauthorized access to personal data.ESAEPDGDPR€400,000
19 Mar 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for failing to verify the identity of a person who obtained a SIM duplicate. This omission led to unauthorized transactions and was treated as a breach of Article 6(1) GDPR.ESAEPDGDPR€200,000
18 Apr 2022SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.The company changed the electricity and gas supplier without the customer's consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€30,000
14 Mar 2022LISMARTSA, S.L.LISMARTSA, S.L. was fined EUR 3,000 by the AEPD for improperly sending the personal data of 74 employees by email. The authority found a breach of data protection rules.ESAEPDGDPR€3,000
01 Jan 2013SPAIN ON LINE, S.L.SPAIN ON LINE, S.L. was fined €30,001 by the AEPD for sending unsolicited promotional emails despite requests to stop. The conduct breached Article 21 of the LSSI on marketing communications without consent.ESAEPDePrivacy€30,001
01 Jan 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined €3,000 by the AEPD for failing to comply with information requests. The case concerned Article 58(1) GDPR and the duty to cooperate with the supervisory authority.ESAEPDGDPR€3,000
17 Jan 2023B.B.B.The entity installed surveillance cameras in the common areas of a residential community without proper authorization or the required informational signage. AEPD found a breach of GDPR Articles 6 and 13 and imposed a EUR 1,500 fine.ESAEPDGDPR€1,500
26 Sept 2022FONTANORTE, S.L.FONTANORTE, S.L. was fined 2,000 EUR by the AEPD for breaching Article 32 GDPR. The company improperly disposed of documents containing personal data in public waste containers, making them accessible to third parties.ESAEPDGDPR€2,000