BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 Jul 2025 | DISTRIBUTED ENERGY ASSETS, S.L.DISTRIBUTED ENERGY ASSETS, S.L. was fined by the AEPD 5,000 EUR for obstructing the exercise of data subject rights. The breach concerned in particular the right to erasure under Article 17 of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 20 Apr 2021 | RIUSA II, S.ARIUSA II, S.A was fined by the AEPD 5,000 EUR for not providing users with the option to reject or configure cookies on its website. The authority treated this as a breach of data protection rules. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jul 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the Spanish Data Protection Agency (AEPD) for failing to provide requested information. The breach concerned cooperation obligations under data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 17 Aug 2021 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited SMS messages to the complainant's mobile phone. The company also failed to remove the number from its database after the request, which constituted a data protection breach. | ES | AEPD | GDPR | €100,000 | ↗ |
| 02 Nov 2023 | ASYMECO, S.A.ASYMECO, S.A. was fined EUR 5,000 by the AEPD for sending clients’ personal data to an employee’s private WhatsApp without proper authorization. The authority found this breached GDPR Articles 6(1) and 32. | ES | AEPD | GDPR | €5,000 | ↗ |
| 04 Dec 2025 | DIARIO DE PRENSA DIGITAL, S.L.DIARIO DE PRENSA DIGITAL, S.L. was fined by the AEPD 5,000 EUR for placing tracking and advertising cookies on its website without prior user consent. The authority found this to be a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 05 Nov 2015 | VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD for sending unsolicited commercial emails despite the recipient’s repeated attempts to unsubscribe. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 01 Mar 2022 | PREICO JURÍDICOS, S.L.PREICO JURÍDICOS, S.L. was fined EUR 2,000 by the AEPD for deficiencies in its cookie policy. The authority found that the website did not provide the required information or obtain consent for storing and accessing data, in breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 17 Apr 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 100,000 by the AEPD for processing a payment to a new account without the account holder’s explicit consent. The authority found this conduct to be a breach of GDPR Article 6. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Mar 2021 | COMUNIDAD DE PROPIETARIOS ***DIRECCIÓN.1The entity was fined EUR 2,000 by the AEPD for installing cameras without the informed consent of the property owners' association. The conduct may have affected third-party rights and data protection obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2021 | PAGE GROUP EUROPEPAGE GROUP EUROPE was fined by the AEPD 300,000 EUR for breaches of GDPR principles on data minimization and transparency. The case concerned the improper handling of a data subject access request submitted through its Dutch website. | ES | AEPD | GDPR | €300,000 | ↗ |
| 20 May 2025 | TRUEBA SPORT S.L.TRUEBA SPORT S.L. was fined by the AEPD 2,000 EUR for sending an email to more than 300 recipients without hiding their email addresses. The authority found this breached data protection principles and failed to properly inform the affected individuals about data processing. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Aug 2025 | APARELLS ORTOPEDICS CURTO, S.L.APARELLS ORTOPEDICS CURTO, S.L. did not provide complete personal data and medical records in response to an access request. The AEPD found this to be a breach of data protection rules and imposed a fine of 10,000 EUR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 05 Mar 2024 | ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. was fined 5,000 EUR by the AEPD. The authority found that the company published employees’ personal data on its website without consent, breaching Article 6(1) of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 03 Mar 2022 | AUTOMOVILES FERSAN, S.A.AUTOMOVILES FERSAN, S.A. used personal data without consent to include it in a vehicle purchase contract. The AEPD imposed a fine of EUR 5,000 for breaching data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 05 May 2022 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD EUR 70,000 for a data protection breach involving unauthorized SIM card duplication. The incident led to unauthorized bank transfers from the complainant's account. | ES | AEPD | GDPR | €70,000 | ↗ |
| 22 Feb 2021 | B.B.B.The entity was fined by the AEPD for a video surveillance system that was improperly oriented toward private areas. The authority also found that the area was not adequately signposted, breaching data protection rules. | ES | AEPD | GDPR | €3,000 | ↗ |
| 14 Jun 2024 | GESCONSULT, S.A. S.G.I.I.C.GESCONSULT, S.A. S.G.I.I.C. was fined by the AEPD 5,000 EUR for processing personal data without a legal basis. The case involved recording a meeting and sharing the recording without proper consent. | ES | AEPD | GDPR | €5,000 | ↗ |
| 22 Jun 2023 | MIFARMA TIENDA ON-LINE, S.L.MIFARMA TIENDA ON-LINE, S.L. was fined by the AEPD €2,000 for sending commercial electronic communications after the recipient had requested that they stop. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 03 Dec 2025 | AVATEL TELECOM, S.A.AVATEL TELECOM, S.A. was fined 500,000 EUR by the AEPD for unauthorized duplication of SIM cards and their fraudulent use. The case concerns breaches of data protection principles and controls over access to telecommunications services. | ES | AEPD | GDPR | €500,000 | ↗ |