Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2020XFERA MÓVILES, S.A. (MASMOVIL)XFERA MÓVILES, S.A. (MASMOVIL) was fined by the AEPD for processing personal data without a lawful basis, in breach of Article 6 GDPR. The case indicates that the company lacked a valid legal ground for the processing activity.ESAEPDGDPR€60,000
01 Jan 2020GROUPALIA COMPRA COLECTIVA, S.L.GROUPALIA COMPRA COLECTIVA, S.L. was fined by the AEPD for sending unsolicited advertising emails. The conduct infringed the complainant's rights despite the complainant being listed on the Robinson list and the company having been previously sanctioned for similar conduct.ESAEPDePrivacy€1,800
01 Jan 2020Lycamobile, S.L.Lycamobile, S.L. was fined by the AEPD 60,000 EUR for falsifying the personal data of prepaid card users. The case concerns a breach of data protection rules.ESAEPDGDPR€60,000
01 Jan 2020VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 50,000 EUR for sending unsolicited promotional SMS messages. The messages were sent despite the complainant having exercised the right to object and request deletion of their data, which breached Article 21 of the LSSI.ESAEPDePrivacy€50,000
01 Jan 2020CENTRO DE DIAGNÓSTICO ***LOCALIDAD.1, S.A.The entity was fined for breaching data confidentiality by improperly sharing medical information between different entities without consent. The case involved sensitive data processing and a lack of a valid legal basis for the disclosure.ESAEPDGDPR€10,000
01 Jan 2020GOOGLE LLCGoogle LLC was fined by the AEPD EUR 5,000,000 for the unauthorized communication of personal data to the “Lumen Project”. The authority found breaches of the right to erasure and the GDPR requirement for lawful processing.ESAEPDGDPR€5,000,000
01 Jan 2020Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined EUR 70,000 by the AEPD for unauthorized charges on a customer's account. The authority found a breach of Article 6(1) GDPR, indicating processing without a valid legal basis.ESAEPDGDPR€70,000
01 Jan 2020SIGNALLIA MARKETING DISTRIBUTION, S.A.SIGNALLIA MARKETING DISTRIBUTION, S.A. was fined by the AEPD 100,000 EUR for failing to provide access to servers and data. The authority found a breach of Article 28(3)(g) GDPR.ESAEPDGDPR€100,000
01 Jan 2020JUST LANDED, S.L.JUST LANDED, S.L. was fined EUR 3,000 by the AEPD for failing to provide a privacy policy and a cookie policy on its website. The authority cited a breach of GDPR Article 13 and LSSI Article 22.2.ESAEPDePrivacy€3,000
01 Jan 2020VOLTIMUM, S.A.VOLTIMUM, S.A. was fined EUR 2,000 by the AEPD for sending commercial emails after the recipient had opted out. The authority found this to be a breach of Article 21 of the LSSI on marketing communications.ESAEPDePrivacy€2,000
01 Jan 2020ARGAN-LET, S.L.ARGAN-LET, S.L. was fined 900 EUR by the AEPD for sending unsolicited commercial SMS messages without prior consent. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€900
01 Jan 2020DESOLASOL RESTAURACIÓN, S.L.The restaurant disclosed a customer's complaint form to other patrons, breaching data protection principles. The case involved unauthorized disclosure of personal information contained in the complaint document.ESAEPDGDPR€6,000
01 Jan 2020GROW BEATS SL.GROW BEATS SL. was fined 3,000 EUR by the AEPD for failing to provide required privacy policy information and for improper use of cookies without user consent. The case concerned website practices and indicates deficiencies in notice and consent requirements.ESAEPDePrivacy€3,000
01 Jan 2020RADIOTELEVISIÓN DEL PRINCIPADO DE ASTURIASRADIOTELEVISIÓN DEL PRINCIPADO DE ASTURIAS was fined by the AEPD 20,000 EUR for retaining and processing images without a proper legal basis. The authority found a breach of data protection principles.ESAEPDGDPR€20,000
20 Dec 2019GESTHOTEL ACTIVOS BALAGARES S.L.GESTHOTEL ACTIVOS BALAGARES S.L. was fined by the AEPD 15,000 EUR for disclosing special categories of personal data, including medical information. The authority found a breach of the integrity and confidentiality principle under GDPR Article 5(1)(f).ESAEPDGDPR€15,000
20 Dec 2019Hozzáférési jog terjedelmeThe controller did not inform the data subject about actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constitutes a GDPR breach.HUNAIHGDPR€1,515
20 Dec 2019TECSIBLE, S.L.TECSIBLE, S.L. was fined by the AEPD 5,000 EUR for a data protection breach. The case involved unsolicited contact and messages sent to an individual on the Robinson list through a third-party call center.ESAEPDGDPR€5,000
20 Dec 2019Anonymizováno (ÚOOÚ UOOU-00136/19-31)The company was fined for disseminating commercial communications without a legal basis and without proper labeling. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€4,716
18 Dec 2019GRUPO CAROLIZANGRUPO CAROLIZAN was fined EUR 3,000 by the AEPD for installing a video surveillance system that disproportionately captured public space. The authority found no sufficient justification for the scope of monitoring, which infringed the rights of third parties.ESAEPDGDPR€3,000
17 Dec 2019ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 80,000 by the AEPD for using personal data to fraudulently contract phone lines without consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€80,000