Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD for sending unsolicited commercial emails despite the recipient’s repeated attempts to unsubscribe. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€15,000
01 Mar 2022PREICO JURÍDICOS, S.L.PREICO JURÍDICOS, S.L. was fined EUR 2,000 by the AEPD for deficiencies in its cookie policy. The authority found that the website did not provide the required information or obtain consent for storing and accessing data, in breach of Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
17 Apr 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 100,000 by the AEPD for processing a payment to a new account without the account holder’s explicit consent. The authority found this conduct to be a breach of GDPR Article 6.ESAEPDGDPR€100,000
01 Mar 2021COMUNIDAD DE PROPIETARIOS ***DIRECCIÓN.1The entity was fined EUR 2,000 by the AEPD for installing cameras without the informed consent of the property owners' association. The conduct may have affected third-party rights and data protection obligations.ESAEPDGDPR€2,000
01 Jan 2021PAGE GROUP EUROPEPAGE GROUP EUROPE was fined by the AEPD 300,000 EUR for breaches of GDPR principles on data minimization and transparency. The case concerned the improper handling of a data subject access request submitted through its Dutch website.ESAEPDGDPR€300,000
20 May 2025TRUEBA SPORT S.L.TRUEBA SPORT S.L. was fined by the AEPD 2,000 EUR for sending an email to more than 300 recipients without hiding their email addresses. The authority found this breached data protection principles and failed to properly inform the affected individuals about data processing.ESAEPDGDPR€2,000
11 Aug 2025APARELLS ORTOPEDICS CURTO, S.L.APARELLS ORTOPEDICS CURTO, S.L. did not provide complete personal data and medical records in response to an access request. The AEPD found this to be a breach of data protection rules and imposed a fine of 10,000 EUR.ESAEPDGDPR€10,000
05 Mar 2024ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. was fined 5,000 EUR by the AEPD. The authority found that the company published employees’ personal data on its website without consent, breaching Article 6(1) of the GDPR.ESAEPDGDPR€5,000
03 Mar 2022AUTOMOVILES FERSAN, S.A.AUTOMOVILES FERSAN, S.A. used personal data without consent to include it in a vehicle purchase contract. The AEPD imposed a fine of EUR 5,000 for breaching data protection rules.ESAEPDGDPR€5,000
05 May 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD EUR 70,000 for a data protection breach involving unauthorized SIM card duplication. The incident led to unauthorized bank transfers from the complainant's account.ESAEPDGDPR€70,000
22 Feb 2021B.B.B.The entity was fined by the AEPD for a video surveillance system that was improperly oriented toward private areas. The authority also found that the area was not adequately signposted, breaching data protection rules.ESAEPDGDPR€3,000
14 Jun 2024GESCONSULT, S.A. S.G.I.I.C.GESCONSULT, S.A. S.G.I.I.C. was fined by the AEPD 5,000 EUR for processing personal data without a legal basis. The case involved recording a meeting and sharing the recording without proper consent.ESAEPDGDPR€5,000
22 Jun 2023MIFARMA TIENDA ON-LINE, S.L.MIFARMA TIENDA ON-LINE, S.L. was fined by the AEPD €2,000 for sending commercial electronic communications after the recipient had requested that they stop. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€2,000
03 Dec 2025AVATEL TELECOM, S.A.AVATEL TELECOM, S.A. was fined 500,000 EUR by the AEPD for unauthorized duplication of SIM cards and their fraudulent use. The case concerns breaches of data protection principles and controls over access to telecommunications services.ESAEPDGDPR€500,000
14 Jul 2021LABORATORIOS GONZÁLEZ, S.L.LABORATORIOS GONZÁLEZ, S.L. was fined by the AEPD 20,000 EUR for sharing an employee’s COVID-19 antibody test result with the employee’s superior without consent. The authority found this to be a breach of data protection rules.ESAEPDGDPR€20,000
29 Jul 2020CALLESGARCIA S.C.CALLESGARCIA S.C. was fined by the AEPD €4,000 for using a wedding photo in business advertising without authorization. The authority found a breach of Article 6 GDPR on lawful processing of personal data.ESAEPDGDPR€4,000
13 Aug 2025TELECONTACT LIST S.L.TELECONTACT LIST S.L. was fined by the AEPD €1,000 for failing to respond to a data subject’s requests to exercise the rights of access and erasure. The authority found a breach of GDPR obligations, including Article 17.ESAEPDGDPR€1,000
01 Jan 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD EUR 60,000 for incorrectly including personal data in a creditworthiness file. The authority found a breach of the GDPR accuracy principle under Article 5(1)(d).ESAEPDGDPR€60,000
01 Jan 2025MONUMENTAL FORMA SPORT, S.L.MONUMENTAL FORMA SPORT, S.L. was fined by the AEPD EUR 3,000 for requesting excessive personal data, including banking information, in connection with a free gym access promotion. The authority found that the data requested breached the GDPR data minimisation principle under Article 5(1)(c).ESAEPDGDPR€3,000
18 Jul 2025***COMUNIDAD.1The entity was fined for including personal data in community meeting minutes distributed to residents and for inadequate security measures on its community website. The authority found that these failures breached Article 32 of the GDPR on processing security.ESAEPDGDPR€1,000