Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Apr 2023CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 200,000 for failing to remove personal data from a credit information system after the debt was sold. The authority found that the continued processing of the data was not compliant with data protection rules.ESAEPDGDPR€200,000
17 Jan 2022SERVICIOS FINANCIEROS CARREFOUR, EFC., S.A.SERVICIOS FINANCIEROS CARREFOUR, EFC., S.A. was fined 20,000 EUR by the AEPD. The authority found that the company failed to properly handle a data subject’s request for erasure, which led to continued processing of personal data despite the prior deletion request.ESAEPDGDPR€20,000
05 Nov 2020B.B.B.The entity was fined by the AEPD EUR 2,000 for using security cameras that recorded public spaces extensively without justification. The authority found that this breached data protection principles.ESAEPDGDPR€2,000
01 Jan 2013FLAYBOX S.L.FLAYBOX S.L. was fined by the AEPD in the amount of EUR 3,100 for sending unsolicited promotional emails despite the recipient's request to unsubscribe. The authority found a breach of Articles 21.1 and 21.2 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€3,100
14 Mar 2022RAMONA FILMS, S.LRAMONA FILMS, S.L was fined by the AEPD for failing to provide requested information to the Spanish Data Protection Agency. The breach concerned the duty to cooperate under GDPR Article 58(1).ESAEPDGDPR€30,000
29 Aug 2025FIATC MUTUA DE SEGUROS Y REASEGUROSFIATC Mutua de Seguros y Reaseguros was fined €40,000 by the AEPD after unauthorized access to its systems. The incident may have exposed personal data, including DNI/CIF, and the authority found inadequate security measures and a breach of Article 5(1)(f) GDPR.ESAEPDGDPR€40,000
08 Aug 2024ASOCIACIÓN SOCIO CULTURAL Y HUMANITARIA VIRGEN DE COROMOTOThe organization was fined 600 EUR by the AEPD for failing to provide access to personal data and information requested by the data protection authority. The case concerned non-compliance with the authority’s powers under Article 58.1 of the GDPR.ESAEPDGDPR€600
10 Jan 2020AUTOMOCION X.X.X. S.L.The company was fined EUR 1,000 by the AEPD for placing an individual's photo, name, and phone number on an adult contact website without consent. The disclosure led to unwanted calls and constituted a breach of personal data protection rules.ESAEPDGDPR€1,000
18 Jun 2021DESPACHO TEJEDOR INFANTES CONSULTORES ASESORES, S.L.The entity unlawfully disclosed personal data to a third party, breaching the confidentiality principle under GDPR. The AEPD imposed a fine of 2,000 EUR.ESAEPDGDPR€2,000
16 Sept 2022B.B.B.B.B.B. was fined EUR 300 by the AEPD for installing a surveillance camera. The authority found that the device may have recorded images of a neighboring property without consent, potentially breaching data protection rules.ESAEPDGDPR€300
12 Dec 2024BREOGAN AUTOLUX, S.L.BREOGAN AUTOLUX, S.L. was fined EUR 10,000 by the AEPD for sending unsolicited SMS advertisements without prior consent from recipients. The authority also found that the messages did not provide an opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€10,000
05 Jul 2019VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined €120,000 by the AEPD for failing to exercise due diligence in response to a fraudulent situation involving unauthorized service contracts. The authority found a breach of Article 6 GDPR.ESAEPDGDPR€120,000
01 Jan 2024IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined by the AEPD for failing to ensure the integrity and confidentiality of personal data and for conducting an inadequate risk analysis and impact assessment. The deficiencies led to data breaches involving third-party systems, indicating weaknesses in operational and oversight controls.ESAEPDGDPR€1,040,000
23 Jan 2024CAIXA RURAL BENICARLÓ, S.C.C.VCAIXA RURAL BENICARLÓ was fined by the AEPD 10,000 EUR for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident.ESAEPDGDPR€10,000
19 Apr 2022INGENIERÍA Y TELECOM JAÉN, S.L.INGENIERÍA Y TELECOM JAÉN, S.L. was fined 10,000 EUR by the AEPD. The authority found that the company renewed a customer's service promotion without consent, in breach of Article 6 GDPR.ESAEPDGDPR€10,000
01 Oct 2024TRIVE CREDIT SPAIN, S.L.TRIVE CREDIT SPAIN, S.L. failed to properly handle a data subject access request, which constitutes a breach of Article 15 GDPR. The AEPD imposed a fine for non-compliance with a prior resolution.ESAEPDGDPR€450,000
26 Nov 2010LA COLINA 2006LA COLINA 2006 was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior recipient consent.ESAEPDePrivacy€600
18 Jun 2020CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD for using pre-marked consents for data processing and charging customers a fee if they refused data sharing with third parties. The authority found that these practices breached GDPR requirements on valid consent and lawful processing.ESAEPDGDPR€2,100,000
06 Oct 2016ESPACIO DOCENTE, S.L.ESPACIO DOCENTE, S.L. was fined EUR 1,000 by the AEPD for sending unsolicited commercial emails without prior consent. The company also failed to stop communications after being asked to do so, breaching Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
12 Jan 2021ASOCIACIÓN CULTURAL ***ASOCIACIÓN.1The association was fined for sharing images of a minor in WeChat groups without parental consent. The authority found a breach of GDPR Article 6(1)(a).ESAEPDGDPR€3,000