Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 May 2024G&F&S SECURITY GROUP, S.L.G&F&S SECURITY GROUP, S.L. was fined by the AEPD €18,000 for failing to properly handle a data subject access request. The authority found a breach of Article 15 GDPR and non-compliance with a data protection authority resolution.ESAEPDGDPR€18,000
12 Jun 2017VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 3,300 EUR for sending commercial communications to a former customer after a request for data cancellation. The authority also noted an allegation of sharing personal data with third parties without consent.ESAEPDePrivacy€3,300
17 Dec 2024ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓNASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN was fined EUR 750 by the AEPD for failing to comply with a data protection authority resolution. The case concerns Article 58(2) of the GDPR.ESAEPDGDPR€750
21 Feb 2024SOCIEDAD CONJUNTA PARA LA EMISIÓN Y GESTIÓN DE MEDIOS DE PAGO EFC SAIberia Cards was fined by the AEPD for failing to properly delete customer data after confirming cancellation. This caused issues when a former customer reapplied for a card.ESAEPDGDPR€20,000
14 Nov 2012RED UNIVERSAL DE MARKETING Y BOOKINGS ONLINE, S.A. (RUMBO)RED UNIVERSAL DE MARKETING Y BOOKINGS ONLINE, S.A. (RUMBO) was fined by the AEPD EUR 600 for sending commercial SMS and email messages without recipient consent. The conduct breached Article 21.2 of the LSSI, which requires prior consent for such communications.ESAEPDePrivacy€600
22 Sept 2020VENU SANZ CHEF, S.L.VENU SANZ CHEF, S.L. used a client's personal data, including full name, profile photo, and health information, for advertising purposes without consent. The AEPD found this conduct to be a breach of data protection rules.ESAEPDGDPR€3,000
22 Oct 2025AXARNET COMUNICACIONES, S.L.AXARNET COMUNICACIONES, S.L. suffered a data breach caused by a vulnerability in a third-party program. The incident exposed personal data of 50,250 clients, including names, email addresses, and bank account details, leading to a fine by the AEPD.ESAEPDGDPR€20,000
25 Oct 2025MAR DEGUSTACIÓN, S.LMAR DEGUSTACIÓN, S.L was fined by the AEPD 1,000 EUR for installing a video surveillance system without proper consent and for failing to inform affected individuals. The authority cited breaches of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€1,000
16 Apr 2025SERVICIOS INMOBILIARIOS Y GESTIÓN RCL-MADRID, S.L.SERVICIOS INMOBILIARIOS Y GESTIÓN RCL-MADRID, S.L. was fined 600 EUR by the AEPD. The authority found that the company did not provide access to personal data and other information requested during the investigation. The conduct breached Article 58(1) of the GDPR.ESAEPDGDPR€600
07 Nov 2025MAJOREL SP SOLUTIONS, S.A.MAJOREL SP SOLUTIONS, S.A. was fined by the AEPD 80,000 EUR for processing personal data without a lawful basis. The authority found a breach of Article 6(1)(b) GDPR.ESAEPDGDPR€80,000
27 Oct 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD for requesting payment for services contracted without the complainant’s consent. The case concerns a data protection breach linked to processing and debt collection without a valid legal basis.ESAEPDGDPR€50,000
17 Mar 2023ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 70,000 by the AEPD for activating a call forwarding service without the user's consent. This led to unauthorized access to the user's bank accounts and transactions.ESAEPDGDPR€70,000
31 Mar 2025BAR EL ANDÉN M. ROJO, S.L.The entity was fined for recording audio and video in the establishment without proper informational signage. The authority considered this a breach of data protection requirements.ESAEPDGDPR€1,000
10 Jun 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited advertising SMS messages to a complainant. The messages were sent despite the recipient’s request not to receive such communications.ESAEPDePrivacy€10,000
01 Jan 2016AUTOPRIN, S.A.AUTOPRIN, S.A. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails despite requests to stop. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
24 Jan 2024CAJA RURAL DE ONDA, S.C.C.CAJA RURAL DE ONDA, S.C.C. was fined by the AEPD 15,000 EUR for violating data protection principles, including confidentiality and integrity. The breach resulted in unauthorized access to personal data.ESAEPDGDPR€15,000
01 Jan 2020DOUGLAS SPAIN, S.A.U.DOUGLAS SPAIN, S.A.U. was fined by the AEPD 2,700 EUR for continuing to send advertising emails to a complainant after confirming deletion of the complainant’s personal data. The authority found this breached Article 21 of the LSSI.ESAEPDePrivacy€2,700
01 Jan 2022CAIXABANK S.A.CaixaBank was fined EUR 25,000 by the AEPD for failing to update a customer's address despite repeated requests. The authority found this to be a breach of the GDPR right to rectification.ESAEPDGDPR€25,000
07 Feb 2022JIMBO NETWORKS, S.L.JIMBO NETWORKS, S.L. was fined by the AEPD for unlawful processing of personal data obtained from emails and for cookie policy violations on its website. The authority found that users were not properly informed and that valid consent was not obtained where required.ESAEPDGDPR€15,000
17 Mar 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.The AEPD fined TELEFÓNICA MÓVILES ESPAÑA, S.A. 70,000 EUR for changing a customer's mobile tariff without consent. The authority found that the action breached Article 6(1) GDPR because there was no valid legal basis for the change.ESAEPDGDPR€70,000