Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2023CARSO TRADING, S.L.CARSO TRADING, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails. The company also failed to respond to a data access request, which constitutes a breach of Article 15 GDPR.ESAEPDGDPR€1,000
01 Jan 2023ISA MADRID SERVICIOS, S.L.ISA MADRID SERVICIOS, S.L. was fined EUR 900 by the AEPD for improperly positioning a surveillance camera that captured public areas. The authority also found that adequate signage informing individuals about the surveillance was not provided, in breach of data protection rules.ESAEPDGDPR€900
01 Jan 2023BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for a data breach after an employee accessed a customer's banking information and shared it without consent. The authority found that data security measures were violated.ESAEPDGDPR€70,000
01 Jan 2023MASLUZ ENERGY POWER, S.L.MASLUZ ENERGY POWER, S.L. was fined EUR 90,000 by the AEPD for changing a customer's energy provider without authorization. The authority also found a failure to provide the required information, constituting breaches of GDPR Articles 13 and 6(1).ESAEPDGDPR€90,000
01 Jan 2023B.B.B.The entity installed a video surveillance system in a garage without the required authorization and without informing the affected individuals. This constituted a breach of data protection rules and resulted in a EUR 600 fine imposed by the AEPD.ESAEPDGDPR€600
01 Jan 2023CIUDAD RESIDENCIAL H.H.H.CIUDAD RESIDENCIAL H.H.H. was fined by the AEPD EUR 2,000 for breaching the data minimization principle. The case concerned capturing and storing photographs of residents collecting packages without informing them about this processing.ESAEPDGDPR€2,000
01 Jan 2023B.B.B.The entity was fined EUR 600 by the AEPD for improperly directing surveillance cameras toward a neighbor's property. This conduct breached data protection rules and affected the privacy of third parties.ESAEPDGDPR€600
01 Jan 2023OPEN BANK, S.A.Openbank was fined by the AEPD for opening a bank account without the individual's authorization. The account was later used for fraudulent activities, indicating failures in verification and data protection controls.ESAEPDGDPR€70,000
01 Jan 2023DEH NOTIFICACION ELECTRONICA HABILITADA S.L.DEH NOTIFICACION ELECTRONICA HABILITADA S.L. was fined by the AEPD €30,000 for sending unencrypted passwords for digital certificates. The authority considered this a potential data security risk. The procedure concerning Article 6(1) GDPR was archived due to no infringement.ESAEPDGDPR€30,000
01 Jan 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD 200,000 EUR for making commercial calls to a complainant despite the numbers being on the Robinson list. The case indicates a breach of data protection rules governing direct marketing.ESAEPDGDPR€200,000
01 Jan 2023B.B.B.The entity was fined by the AEPD 300 EUR for operating a surveillance camera that captured public areas without proper signage. This conduct breached data protection requirements.ESAEPDGDPR€300
01 Jan 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD 70,000 EUR for changing the ownership of a mobile line without proper verification. The failure enabled unauthorized access to the complainant’s bank data and fraudulent transactions.ESAEPDGDPR€70,000
01 Jan 2023B.B.B.The entity used a video from a training session containing the complainant’s personal statements without consent. The material was used for marketing purposes to attract new clients, which constituted a breach of data protection rules.ESAEPDGDPR€10,000
01 Jan 2023VACACIONES EDREAMS, S.L.VACACIONES EDREAMS, S.L. was fined by the AEPD in the amount of 10,000 EUR for failing to provide access to personal data upon a customer request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€10,000
01 Jan 2023Suministrador Ibérico de Energía, S.L.Suministrador Ibérico de Energía, S.L. was fined by the AEPD €70,000 for switching a customer's electricity provider without consent. The authority found that the processing lacked a valid legal basis under Article 6(1) GDPR.ESAEPDGDPR€70,000
01 Jan 2023UNIQUE HOTEL APARTMENT. S.LThe hotel improperly managed guest registration records, breaching data protection principles. It failed to maintain numerical order and did not communicate the records to the competent security forces.ESAEPDGDPR€2,000
01 Jan 2023INMARAN ASESORES S.L.INMARAN ASESORES S.L. was fined by the AEPD in the amount of 2,000 EUR for failing to comply with a data protection authority resolution. The company did not implement the required measures to inform data subjects under Article 13 GDPR.ESAEPDGDPR€2,000
01 Jan 2023KUGELCHEN PROPIERTIES, S.L.KUGELCHEN PROPIERTIES, S.L. was fined by the AEPD EUR 2,000 for processing personal data without consent. The company continued charging a customer despite requests to delete personal data and stop transactions.ESAEPDGDPR€2,000
01 Jan 2023D. ***NIF.1The entity operating https://www.dmerka.com was fined EUR 600 by the AEPD. The authority found that the controller was not identified and that required information on personal data processing was not provided, in breach of Article 13 GDPR.ESAEPDGDPR€600
01 Jan 2023ENERGÍA COLECTIVA, S.L.ENERGÍA COLECTIVA, S.L. was fined by the AEPD for inaccurately processing personal data. The issue led to incorrect billing and an intrusion into individuals’ privacy.ESAEPDGDPR€70,000