BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2020 | XFERA MÓVILES, S.A. (MASMOVIL)XFERA MÓVILES, S.A. (MASMOVIL) was fined by the AEPD for processing personal data without a lawful basis, in breach of Article 6 GDPR. The case indicates that the company lacked a valid legal ground for the processing activity. | ES | AEPD | GDPR | €60,000 | ↗ |
| 01 Jan 2020 | GROUPALIA COMPRA COLECTIVA, S.L.GROUPALIA COMPRA COLECTIVA, S.L. was fined by the AEPD for sending unsolicited advertising emails. The conduct infringed the complainant's rights despite the complainant being listed on the Robinson list and the company having been previously sanctioned for similar conduct. | ES | AEPD | ePrivacy | €1,800 | ↗ |
| 01 Jan 2020 | Lycamobile, S.L.Lycamobile, S.L. was fined by the AEPD 60,000 EUR for falsifying the personal data of prepaid card users. The case concerns a breach of data protection rules. | ES | AEPD | GDPR | €60,000 | ↗ |
| 01 Jan 2020 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 50,000 EUR for sending unsolicited promotional SMS messages. The messages were sent despite the complainant having exercised the right to object and request deletion of their data, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €50,000 | ↗ |
| 01 Jan 2020 | CENTRO DE DIAGNÓSTICO ***LOCALIDAD.1, S.A.The entity was fined for breaching data confidentiality by improperly sharing medical information between different entities without consent. The case involved sensitive data processing and a lack of a valid legal basis for the disclosure. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2020 | GOOGLE LLCGoogle LLC was fined by the AEPD EUR 5,000,000 for the unauthorized communication of personal data to the “Lumen Project”. The authority found breaches of the right to erasure and the GDPR requirement for lawful processing. | ES | AEPD | GDPR | €5,000,000 | ↗ |
| 01 Jan 2020 | Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined EUR 70,000 by the AEPD for unauthorized charges on a customer's account. The authority found a breach of Article 6(1) GDPR, indicating processing without a valid legal basis. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2020 | SIGNALLIA MARKETING DISTRIBUTION, S.A.SIGNALLIA MARKETING DISTRIBUTION, S.A. was fined by the AEPD 100,000 EUR for failing to provide access to servers and data. The authority found a breach of Article 28(3)(g) GDPR. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Jan 2020 | JUST LANDED, S.L.JUST LANDED, S.L. was fined EUR 3,000 by the AEPD for failing to provide a privacy policy and a cookie policy on its website. The authority cited a breach of GDPR Article 13 and LSSI Article 22.2. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jan 2020 | VOLTIMUM, S.A.VOLTIMUM, S.A. was fined EUR 2,000 by the AEPD for sending commercial emails after the recipient had opted out. The authority found this to be a breach of Article 21 of the LSSI on marketing communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 01 Jan 2020 | ARGAN-LET, S.L.ARGAN-LET, S.L. was fined 900 EUR by the AEPD for sending unsolicited commercial SMS messages without prior consent. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €900 | ↗ |
| 01 Jan 2020 | DESOLASOL RESTAURACIÓN, S.L.The restaurant disclosed a customer's complaint form to other patrons, breaching data protection principles. The case involved unauthorized disclosure of personal information contained in the complaint document. | ES | AEPD | GDPR | €6,000 | ↗ |
| 01 Jan 2020 | GROW BEATS SL.GROW BEATS SL. was fined 3,000 EUR by the AEPD for failing to provide required privacy policy information and for improper use of cookies without user consent. The case concerned website practices and indicates deficiencies in notice and consent requirements. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jan 2020 | RADIOTELEVISIÓN DEL PRINCIPADO DE ASTURIASRADIOTELEVISIÓN DEL PRINCIPADO DE ASTURIAS was fined by the AEPD 20,000 EUR for retaining and processing images without a proper legal basis. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €20,000 | ↗ |
| 20 Dec 2019 | GESTHOTEL ACTIVOS BALAGARES S.L.GESTHOTEL ACTIVOS BALAGARES S.L. was fined by the AEPD 15,000 EUR for disclosing special categories of personal data, including medical information. The authority found a breach of the integrity and confidentiality principle under GDPR Article 5(1)(f). | ES | AEPD | GDPR | €15,000 | ↗ |
| 20 Dec 2019 | Hozzáférési jog terjedelmeThe controller did not inform the data subject about actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constitutes a GDPR breach. | HU | NAIH | GDPR | €1,515 | ↗ |
| 20 Dec 2019 | TECSIBLE, S.L.TECSIBLE, S.L. was fined by the AEPD 5,000 EUR for a data protection breach. The case involved unsolicited contact and messages sent to an individual on the Robinson list through a third-party call center. | ES | AEPD | GDPR | €5,000 | ↗ |
| 20 Dec 2019 | Anonymizováno (ÚOOÚ UOOU-00136/19-31)The company was fined for disseminating commercial communications without a legal basis and without proper labeling. The authority found a breach of Czech rules on information society services. | CZ | UOOU | ePrivacy | €4,716 | ↗ |
| 18 Dec 2019 | GRUPO CAROLIZANGRUPO CAROLIZAN was fined EUR 3,000 by the AEPD for installing a video surveillance system that disproportionately captured public space. The authority found no sufficient justification for the scope of monitoring, which infringed the rights of third parties. | ES | AEPD | GDPR | €3,000 | ↗ |
| 17 Dec 2019 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 80,000 by the AEPD for using personal data to fraudulently contract phone lines without consent. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €80,000 | ↗ |