Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 May 2023B.B.B.The entity was fined by the AEPD for installing a video surveillance system that captured public areas without authorization. The footage was then used for dissemination via WhatsApp, which breached Article 5(1)(c) GDPR.ESAEPDGDPR€300
26 Apr 2010LA OFERTA DE LA SEMANA, S.L.LA OFERTA DE LA SEMANA, S.L. was fined by the AEPD 600 EUR for sending an unsolicited commercial email on 4 September 2009. The message was sent without the recipient’s prior and explicit consent, breaching Article 21.1 of the LSSI.ESAEPDePrivacy€600
04 Jun 2021FINCAS MIGUEL GARCÍA, S.LFINCAS MIGUEL GARCÍA, S.L was fined 2,000 EUR by the AEPD for failing to provide the complainant with its privacy policy before collecting personal data. The authority found this to be a breach of the information duty under Article 13 GDPR.ESAEPDGDPR€2,000
17 Dec 2019ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 80,000 by the AEPD for using personal data to fraudulently contract phone lines without consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€80,000
01 Jan 2015ENDESA ENERGÍA S.A.ENDESA ENERGÍA S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial SMS messages to a complainant who had previously opted out of such communications. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€5,000
01 Jan 2023MAKING SOLUTIONS, S.L. (MY PERFECT WEDDING)MY PERFECT WEDDING was fined by the AEPD EUR 1,000 for failing to properly provide personal data in response to the complainant’s request. The authority found a breach of Article 15 GDPR, which governs the right of access.ESAEPDGDPR€1,000
13 Jun 2022AMADEUS IT GROUP, S.A.AMADEUS IT GROUP, S.A. was fined by the AEPD EUR 5,000 for failing to properly handle a data subject's requests to access and delete personal data. The authority found a breach of Article 12 GDPR because the company did not provide an adequate response.ESAEPDGDPR€5,000
01 Jul 2020ANMAVAS 61, S.L. (LA CUEVA SEX CLUB)ANMAVAS 61, S.L. did not respond to a data subject’s request for erasure. The AEPD imposed a fine of EUR 2,000 for breaching GDPR obligations.ESAEPDGDPR€2,000
01 Jan 2024VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 200,000 EUR by the AEPD for issuing a duplicate SIM card without the customer’s consent. The incident led to unauthorized financial transactions, indicating significant failures in authorization and security controls.ESAEPDGDPR€200,000
09 Oct 2015DESIGN MASTER DIMA, S.L.DESIGN MASTER DIMA, S.L. was fined by the AEPD EUR 1,400 for sending unsolicited commercial emails to an individual who had requested that such communications stop. The conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,400
31 Mar 2023LODEJU, S.L.LODEJU, S.L. was fined by the AEPD EUR 3,000 for improperly directing surveillance cameras toward public spaces without authorization. The authority also found inadequate informational signage, in breach of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€3,000
11 Mar 2022SHOPERY NETWORKS SPAIN, S.L.SHOPERY NETWORKS SPAIN, S.L. was fined 3,000 EUR by the AEPD for a security breach. The authority found a violation of Article 32 GDPR, which requires appropriate technical and organizational measures.ESAEPDGDPR€3,000
01 Jan 2023INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L.INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L. was fined by the AEPD EUR 7,000 for unlawfully disclosing personal data, including health information, in response to a Google review. The authority found a breach of confidentiality and of the security obligations under the GDPR.ESAEPDGDPR€7,000
01 Jan 2012IDEAS CREATIVAS DE OPERACION S.L.IDEAS CREATIVAS DE OPERACION S.L. was fined EUR 33,001 by the AEPD for sending unsolicited commercial emails despite requests for data cancellation. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€33,001
31 Jul 2023DOÑA B.B.B.The sanctioned individual created a WhatsApp group with 255 participants without prior consent. As a result, the names and phone numbers of the participants were disclosed, constituting a breach of personal data protection rules.ESAEPDGDPR€2,000
15 Mar 2023BANKINTER CONSUMER FINANCE E.F.C., S.A.Bankinter Consumer Finance issued a duplicate card without the customer's consent and sent it to an incorrect address. This led to unauthorized transactions and indicated a failure in data protection and payment security controls.ESAEPDGDPR€70,000
25 Jul 2023EDICIONES PERIÓDICAS DEL NOROESTE, S.L.The entity published a private video on Twitter without the data subject’s consent. The authority found a breach of data minimization because excessive data were processed beyond what was necessary for the intended purpose.ESAEPDGDPR€10,000
18 Apr 2024DELPASO CAR HIRE, S.L.U.DELPASO CAR HIRE, S.L.U. was fined by the AEPD EUR 2,000 for failing to provide a customer with access to their personal data. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€2,000
29 May 2025IMMUCURA MED, S.L.IMMUCURA MED, S.L. was fined EUR 20,000 by the AEPD for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR.ESAEPDGDPR€20,000
17 Feb 2022VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined EUR 70,000 by the AEPD for issuing a duplicate SIM card to a third party without the customer's consent. This enabled unauthorized access to the customer's bank account.ESAEPDGDPR€70,000