Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2019IKEA IBERICA, S.A.U.The AEPD fined IKEA IBERICA, S.A.U. 10,000 EUR for installing cookies on users’ devices without obtaining prior informed consent. The authority found this breached Article 22.2 of the LSSI.ESAEPDePrivacy€10,000
25 Mar 2017IMPACTING EMAIL MARKETING SOLUTIONS S.L.IMPACTING EMAIL MARKETING SOLUTIONS S.L. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent. The authority found this conduct to be in breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
25 Feb 2022B.B.B.B.B.B. was fined by the AEPD in the amount of EUR 300 for installing a surveillance camera that captured a public transit area. The footage was then disseminated without consent, which constituted a breach of data protection rules.ESAEPDGDPR€300
21 Mar 2012GROUPON SPAIN SLGROUPON SPAIN SL was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails. The messages were sent despite the recipient's requests to unsubscribe, which breached Article 21 of the LSSI.ESAEPDePrivacy€30,001
11 Apr 2023CORPORACION DE MEDIOS DE EXTREMADURA, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. The authority found a breach of the data minimization principle and imposed a 150,000 EUR fine.ESAEPDGDPR€150,000
04 Nov 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 70,000 EUR for processing a fraudulent phone number portability request without the data subject's consent. The authority found a breach of GDPR Article 6(1).ESAEPDGDPR€70,000
11 Feb 2020AMALFI SERVICIOS DE RESTAURACIÓN S.L.AMALFI SERVICIOS DE RESTAURACIÓN S.L. was fined by the AEPD 6,000 EUR for installing surveillance cameras without proper consent. The authority also found that the cameras captured images of public spaces without sufficient justification, breaching data protection rules.ESAEPDGDPR€6,000
28 May 2024B.B.B.B.B.B., a councilor, unlawfully published the personal data of a complainant and their spouse in a municipal meeting note. The information was shared with a group of about 400 people, causing reputational harm.ESAEPDGDPR€1,000
24 Sept 2021B.B.B.The entity was fined for operating a video surveillance system aimed at public and private spaces without sufficient justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€2,500
24 Feb 2011B.B.B.B.B.B. was fined EUR 600 by the AEPD for sending an unsolicited commercial email to the complainant without meeting the required legal conditions. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications.ESAEPDePrivacy€600
12 Jan 2023ORANGEORANGE was fined EUR 1,000,000 by the AEPD for breaching data protection principles. The authority found failures to implement privacy by design and privacy by default in connection with SIM swapping incidents.ESAEPDGDPR€1,000,000
08 Apr 2022B.B.B.The entity was fined for installing security cameras that recorded audio and covered areas such as the restroom without proper notice to employees or customers. The authority found this breached GDPR rules on data processing and transparency of information.ESAEPDGDPR€3,000
01 Jan 2018VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 20,000 EUR by the AEPD for sending unsolicited marketing emails. The authority found that recipients were not given an effective unsubscribe option, despite a request to be removed from the mailing list.ESAEPDePrivacy€20,000
01 Jan 2020BANCO DE SABADELL, S.A.Banco de Sabadell was fined for sending a commercial email to a customer who had previously opted out of such communications. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications.ESAEPDePrivacy€5,000
01 Mar 2017CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD €10,000 for sending commercial emails without a valid unsubscribe link. The case concerned non-compliance with electronic communications rules and recipients’ right to opt out easily.ESAEPDePrivacy€10,000
01 Jan 2021LA MAISON DU BAMBOULA MAISON DU BAMBOU was fined EUR 3,000 by the AEPD for sending commercial emails without the recipient's consent. The conduct breached Article 21 of the LSSI.ESAEPDePrivacy€3,000
20 Dec 2019GESTHOTEL ACTIVOS BALAGARES S.L.GESTHOTEL ACTIVOS BALAGARES S.L. was fined by the AEPD 15,000 EUR for disclosing special categories of personal data, including medical information. The authority found a breach of the integrity and confidentiality principle under GDPR Article 5(1)(f).ESAEPDGDPR€15,000
24 Jan 2024CAIXA RURAL LA VALL SAN ISIDRO, S.C.C.CAIXA RURAL LA VALL SAN ISIDRO was fined by the AEPD 15,000 EUR for a personal data breach. The incident allowed unauthorized third-party access and affected the confidentiality and integrity of the data.ESAEPDGDPR€15,000
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the original user's consent. The incident led to unauthorized access to personal and banking data.ESAEPDGDPR€200,000
23 Jul 2022GESTIONES AUTO LOW COST S. LThe entity was fined for not having a privacy policy on its website. The breach concerned Article 13 of the GDPR, which requires specific information to be provided to data subjects.ESAEPDGDPR€1,000