BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Sept 2018 | VILAN DATAMINING SLVILAN DATAMINING SL was fined by the AEPD €800 for sending unsolicited commercial emails. The messages did not provide a way to exercise the rights of access, rectification, cancellation, or objection. | ES | AEPD | ePrivacy | €800 | ↗ |
| 28 Jul 2016 | IMPACTING EMAIL MARKETING SOLUTIONS, S.L.IMPACTING EMAIL MARKETING SOLUTIONS, S.L. was fined by the AEPD 10,000 EUR for sending unsolicited commercial communications by SMS without recipient consent. The case concerns a breach of data protection and direct marketing rules. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 13 Jan 2015 | LEROY MERLIN ESPAÑA S.L.U.LEROY MERLIN ESPAÑA S.L.U. was fined by the AEPD EUR 3,900 for sending unsolicited commercial SMS messages without recipient consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,900 | ↗ |
| 26 Apr 2011 | VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined 600 EUR by the AEPD for sending unsolicited advertising SMS messages. The authority found that the messages were sent despite the recipient’s opt-out request, which breached Article 21.2 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 16 Mar 2023 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for failing to implement adequate security measures. A SIM card duplication enabled unauthorized access to a customer’s personal data and financial accounts. | ES | AEPD | GDPR | €200,000 | ↗ |
| 24 Jun 2021 | NEXTGEN FINANCIAL SERVICES S.L.NEXTGEN FINANCIAL SERVICES S.L. failed to update the address in a loan contract and did not correct inaccurate data in a credit file. The AEPD found this to be a breach of the right to data rectification and imposed a fine of 50,000 EUR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 27 Sept 2011 | EDICIONES FINDER, S.L.EDICIONES FINDER, S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails without recipient consent. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 27 Oct 2022 | COPY COFFEE, S.L.COPY COFFEE, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails despite the recipient's prior objection. The authority found a breach of Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 29 Jan 2024 | IDFINANCE SPAIN, S.A.U.The AEPD fined IDFINANCE SPAIN, S.A.U. 70,000 EUR for including personal data in credit information systems in connection with a disputed debt. The authority found that the processing breached Article 6 GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2014 | COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD EUR 3,000 for sending unsolicited spam messages without providing an opt-out mechanism. The conduct breached Article 21 of the LSSI and failed to meet basic requirements for marketing communications. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 13 Oct 2022 | B.B.B.A tenant complained that the landlord installed a surveillance camera in the kitchen of the rented property without consent. The AEPD found a breach of data protection rules and imposed a EUR 4,000 fine. | ES | AEPD | GDPR | €4,000 | ↗ |
| 25 Jun 2024 | LOS NIÑOS DE MONTESSORI, S.L.The entity was fined for failing to provide information or obtain consent for the use of cookies on its website. This conduct breached the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jan 2013 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, SOCIEDAD ANÓNIMA OPERADORA, Sociedad UnipersonalIberia was fined by the AEPD EUR 1,200 for sending commercial emails without providing recipients with a simple and free way to opt out of further messages. The authority found a breach of Article 21.2 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 01 Mar 2013 | QUARELY INDUSTRIAL S.L.QUARELY INDUSTRIAL S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior recipient consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 23 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without proper consent. The case involved a call to a customer about a service package that the customer had not authorized. | ES | AEPD | GDPR | €70,000 | ↗ |
| 02 Dec 2019 | GARANTIZA AUTOMOCIÓN, S.L.The company was fined by the AEPD in the amount of EUR 3,000 for failing to provide information or obtain consent for the use of cookies on its website. The breach concerned LSSI requirements on transparency and user consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jan 2022 | B.B.B.B.B.B. was fined 1,000 EUR by the AEPD. The authority found that the company shared individuals’ personal data in a WhatsApp group without consent, in breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 26 May 2022 | COMUNIDAD.1The owners’ community installed a video surveillance system in common areas without informed consent from all property owners. The AEPD found this to be a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 05 Jun 2023 | HIPER STORE, S.L.HIPER STORE, S.L. was fined EUR 500 by the AEPD for not properly signposting its video surveillance system. The authority also found that the company failed to provide customers with the required data protection information under Article 13 GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 22 Oct 2025 | SPRINTER MEGACENTROS DEL DEPORTE, S.L.SPRINTER MEGACENTROS DEL DEPORTE, S.L. experienced a data breach affecting approximately 6.2 million individuals, involving unauthorized access and encryption of critical systems. The incident was intentional and involved data from multiple EU member states. | ES | AEPD | GDPR | €2,600,000 | ↗ |