Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Sept 2022MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD for processing personal data without a lawful basis. The company failed to respond properly to a data access request and incorrectly linked an individual to insurance policies and claims.ESAEPDGDPR€30,000
01 Jan 2019VODAFONE ESPAÑA, S.A.U.Vodafone España was fined 40,000 EUR by the AEPD for charging a customer for a Netflix service that had not been contracted. The authority found a breach of GDPR Article 6 due to the lack of a lawful basis for the charge and related processing.ESAEPDGDPR€40,000
17 Jan 2023Fusiona Soluciones Energéticas, S.A.Fusiona Soluciones Energéticas, S.A. was fined by the AEPD for unlawfully processing personal data. The company included an individual's data in a credit information system without a lawful basis.ESAEPDGDPR€50,000
01 Jan 2024CIBERSEO JAÉN, S.L.CIBERSEO JAÉN, S.L. was fined EUR 1,500 by the AEPD for publishing a photograph of an individual without consent on a job search website. The case concerned processing personal data without a lawful basis, contrary to Article 6 of the GDPR.ESAEPDGDPR€1,500
27 Apr 2022DIARIO ABC, S.L.DIARIO ABC, S.L. was fined 50,000 EUR by the AEPD for publishing audio of a victim's testimony in a high-profile court case. The authority found that the publication could identify the victim and therefore breached data protection rules.ESAEPDGDPR€50,000
02 Dec 2019CONSULTING DE SEGURIDAD E INVESTIGACION MIRA DP MADRID, S.L.The company was fined by the AEPD for collecting and processing personal data without the data subjects’ consent. The conduct also included sending unsolicited advertising, which breached Article 6 of the GDPR.ESAEPDGDPR€5,000
09 Jul 2025KAFFA KOFFEE ORGANISATION, S.L.KAFFA KOFFEE ORGANISATION, S.L. was fined EUR 900 by the AEPD for failing to implement appropriate technical and organizational measures. The deficiency led to email addresses being visible to multiple recipients, in breach of GDPR requirements.ESAEPDGDPR€900
31 Jan 2025SINDICAT CATAC-CTSCSINDICAT CATAC-CTSC was fined EUR 600 by the AEPD for failing to provide the required information. The authority found a breach of Article 58(1) of the GDPR.ESAEPDGDPR€600
14 Dec 2010EQUIPAMIENTO INTEGRAL DE OFICINAS S.L.EQUIPAMIENTO INTEGRAL DE OFICINAS S.L. was fined EUR 600 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits this type of communication without prior consent.ESAEPDePrivacy€600
01 Jan 2015BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails. The authority found this breached Article 21.1 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€5,000
08 Jan 2024VUKMAL TRADE, S.L.VUKMAL TRADE, S.L. was fined by the AEPD €2,000 for requiring an employee to use a personal mobile phone for work purposes without consent. The company also shared the employee’s personal number with other staff, breaching data protection principles.ESAEPDGDPR€2,000
01 Jan 2019ELECTRIC RENTING GROUP, S.L.ELECTRIC RENTING GROUP, S.L. was fined by the AEPD EUR 2,500 for sending a promotional email without using BCC. This exposed recipients’ email addresses and breached data protection rules.ESAEPDGDPR€2,500
12 Feb 2024MEYDIS, S.L.MEYDIS, S.L. was fined EUR 80,000 by the AEPD for failing to provide required information during an investigation. The authority found a breach of Article 58.1 of the GDPR.ESAEPDGDPR€80,000
04 Dec 2020BORJAMOTOR, S.A.BORJAMOTOR, S.A. was fined by the AEPD €8,000 for sending commercial SMS messages without explicit consent from recipients. The authority also identified improper consent practices for personal data processing on the company’s website.ESAEPDePrivacy€8,000
09 Jul 2025DISTRIBUTED ENERGY ASSETS, S.L.DISTRIBUTED ENERGY ASSETS, S.L. was fined by the AEPD 5,000 EUR for obstructing the exercise of data subject rights. The breach concerned in particular the right to erasure under Article 17 of the GDPR.ESAEPDGDPR€5,000
20 Apr 2021RIUSA II, S.ARIUSA II, S.A was fined by the AEPD 5,000 EUR for not providing users with the option to reject or configure cookies on its website. The authority treated this as a breach of data protection rules.ESAEPDePrivacy€5,000
01 Jul 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the Spanish Data Protection Agency (AEPD) for failing to provide requested information. The breach concerned cooperation obligations under data protection rules.ESAEPDGDPR€5,000
17 Aug 2021BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited SMS messages to the complainant's mobile phone. The company also failed to remove the number from its database after the request, which constituted a data protection breach.ESAEPDGDPR€100,000
02 Nov 2023ASYMECO, S.A.ASYMECO, S.A. was fined EUR 5,000 by the AEPD for sending clients’ personal data to an employee’s private WhatsApp without proper authorization. The authority found this breached GDPR Articles 6(1) and 32.ESAEPDGDPR€5,000
04 Dec 2025DIARIO DE PRENSA DIGITAL, S.L.DIARIO DE PRENSA DIGITAL, S.L. was fined by the AEPD 5,000 EUR for placing tracking and advertising cookies on its website without prior user consent. The authority found this to be a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000