Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2023THE RED KIWI, S.L.THE RED KIWI, S.L. was fined 30,000 EUR by the AEPD. The breach involved adding clients’ phone numbers to a WhatsApp group without consent, which enabled unauthorized access to personal data.ESAEPDGDPR€30,000
04 May 2021CLUB GIMNASIA RÍTMICA SAN ANTONIOThe club was fined by the AEPD for publishing images of minors on social media without proper consent. The authority found a breach of GDPR Article 6 on lawful processing.ESAEPDGDPR€5,000
01 Jan 2016EASYVOYAGE SASEASYVOYAGE SAS was fined by the AEPD in the amount of 20,000 EUR for sending unsolicited commercial emails. The conduct continued despite requests for data cancellation, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€20,000
09 Mar 2023B.B.B.A camera was installed in a community garage without prior authorization and without proper signage. The AEPD found this to be a breach of Article 13 GDPR and imposed a EUR 300 fine.ESAEPDGDPR€300
01 Jan 2022ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company impersonated another energy provider and used personal data without consent.ESAEPDGDPR€10,000
06 Mar 2025SERVICIOS DE INTEGRACIÓN DE ANDALUCÍASERVICIOS DE INTEGRACIÓN DE ANDALUCÍA was fined €2,000 by the AEPD for adding an employee’s personal phone number to a work WhatsApp group without consent. The authority found a breach of the GDPR lawful-basis requirement under Article 6(1).ESAEPDGDPR€2,000
29 Aug 2025EXTRA MADRID, S.L.EXTRA MADRID, S.L. sent personalized postal advertising without the recipient’s consent. The AEPD found this to be a breach of Article 6 GDPR and imposed a fine of 1,000 EUR.ESAEPDGDPR€1,000
08 Aug 2022EUROPYMES SERVICIOS INTEGRALES S.L.EUROPYMES SERVICIOS INTEGRALES S.L. failed to comply with a data deletion request, which constitutes a breach of Article 17 GDPR. The AEPD imposed a fine of EUR 1,000, later reduced due to early payment.ESAEPDGDPR€1,000
21 Jun 2021GSMA LTD.GSMA LTD. was fined by the AEPD for requiring biometric data, including passport details and photos, for facial recognition at the Mobile World Congress without a valid legal basis. The authority found a breach of data protection rules.ESAEPDGDPR€200,000
24 Jun 2024WWPD CINVENTO INTERNATIONAL PATENT TRADING, S.L.The entity sent postal advertising to an individual without any prior commercial relationship, using data from the Official Industrial Property Bulletin. The authority found this to be a breach of data protection rules.ESAEPDGDPR€500
11 Dec 2019VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined EUR 5,000 by the Spanish Data Protection Agency (AEPD). The sanction concerned the failure to provide requested information, which breached GDPR requirements.ESAEPDGDPR€5,000
01 Jan 2013CONSIGNALIA, S.L.CONSIGNALIA, S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited promotional emails. The authority found that this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€600
06 Jun 2024WORLD 2 MEET, S.L.WORLD 2 MEET, S.L. was fined EUR 70,000 by the AEPD for requesting excessive personal data from guests during traveler registration. The company required full copies of identity documents, which breached the data minimization principle.ESAEPDGDPR€70,000
11 Mar 2025UNIÓN DE CRÉDITO PARA LA FINANC. MOB. E INMOB., CREDIFIMO, E.F.C., SAUCREDIFIMO was fined by the AEPD for unlawfully processing personal data by including an individual's data in a credit file without a lawful basis. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€200,000
20 Dec 2021B.B.B.A video recording showing an individual being assaulted was shared via WhatsApp without that person's consent. The AEPD found a breach of Article 6(1) GDPR.ESAEPDGDPR€2,000
24 Mar 2010A.A.A.A.A.A. was fined EUR 600 by the AEPD for sending unsolicited commercial emails without recipient consent. The company also failed to provide information on how to exercise the right of cancellation, breaching Article 21 of the LSSI.ESAEPDePrivacy€600
18 Apr 2023VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 140,000 EUR for a data protection breach involving incorrect billing information. A customer's mobile line was charged under another person's name, indicating an error in the processing of personal data.ESAEPDGDPR€140,000
13 Jun 2023JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SATThe entity was fined by the AEPD for installing a video surveillance system with inadequate signage. The notices did not identify the data controller or provide contact details for exercising data subject rights, breaching Article 13 GDPR.ESAEPDGDPR€500
13 Oct 2025BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 400,000 EUR for failing to implement adequate technical and organizational measures to ensure data integrity and confidentiality. The deficiency resulted in unauthorized access to personal data.ESAEPDGDPR€400,000
19 Mar 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for failing to verify the identity of a person who obtained a SIM duplicate. This omission led to unauthorized transactions and was treated as a breach of Article 6(1) GDPR.ESAEPDGDPR€200,000