BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 25 May 2018 | Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the AEPD for sending unsolicited commercial SMS messages to a non-customer without consent. The case concerns a breach of direct marketing rules and the requirement to obtain prior consent. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 12 Jun 2017 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 3,300 EUR for sending commercial communications to a former customer after a request for data cancellation. The authority also noted an allegation of sharing personal data with third parties without consent. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 19 Sept 2017 | CEPSA COMERCIAL PETRÓLEO, S.A.U.CEPSA was fined by the AEPD 3,300 EUR for sending two unsolicited commercial emails without prior consent from the recipients. The authority found this breached Article 21 of the LSSI on commercial communications. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 01 Jan 2019 | VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España, S.A.U. 3,300 EUR for sending unsolicited commercial SMS messages despite the recipient's objection. This conduct breached Article 21 of the LSSI on commercial communications. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 23 Jan 2017 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 21 Nov 2017 | IBERIA LINEAS AEREAS DE ESPAÑA, S.A. OPERADORA, SOCIEDAD UNIPERSONALIberia was fined by the AEPD in the amount of 3,300 EUR for sending commercial emails without the recipient's consent. The authority found a breach of Article 21.1 of the LSSI on unsolicited electronic communications. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 01 Jan 2015 | CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD in the amount of EUR 3,300. The authority found that the company sent unsolicited advertising emails and failed to properly handle unsubscribe requests, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 03 Feb 2023 | Epic LtdEpic Ltd was fined by the CyDPC in the amount of 3,250 EUR for making unsolicited calls to former customers without a legal basis. The authority also found insufficient technical and organizational measures to ensure compliant data processing and inadequate data security controls. | CY | CyDPC | GDPR | €3,250 | ↗ |
| 01 Jan 2015 | SOTO GLOBAL SERVICE, S.L.SOTO GLOBAL SERVICE, S.L. was fined by the AEPD €3,200 for sending nine unsolicited commercial emails without prior consent. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,200 | ↗ |
| 01 Jan 2013 | FLAYBOX S.L.FLAYBOX S.L. was fined by the AEPD in the amount of EUR 3,100 for sending unsolicited promotional emails despite the recipient's request to unsubscribe. The authority found a breach of Articles 21.1 and 21.2 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €3,100 | ↗ |
| 16 Feb 2022 | Anonymisé (CNPD decision-04-fr-2022)The CNPD found that the companies failed to meet the Article 13 GDPR information obligation toward data subjects, including employees and third parties. The breach concerned the lack of proper notice about data processing activities. | LU | CNPD | GDPR | €3,100 | ↗ |
| 22 Aug 2024 | Sancțiuni pentru încălcarea RGPDThe ANSPDCP fined the company EUR 3,000 for violating Article 2 of the GDPR. The case concerned non-compliance with data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 22 Aug 2024 | Kaufland România SCSKaufland România SCS was fined EUR 3,000 by ANSPDCP for a data security breach. The case concerns an incident involving personal data protection that resulted in an administrative sanction. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 28 Apr 2026 | RESIDENCIAL ETXE-LAN, S.L.RESIDENCIAL ETXE-LAN, S.L. was fined by the AEPD for failing to provide the required information to the supervisory authority. The breach concerned Article 58(1) GDPR and hindered the authority’s supervisory powers. | ES | AEPD | GDPR | €3,000 | ↗ |
| 26 Feb 2026 | Groupharma s.r.l.s.Groupharma s.r.l.s. was fined EUR 3,000 by the Italian supervisory authority, Garante. The case concerned the company’s failure to respond to a former employee’s request to access and delete personal data, including photos and contact details, from its website after employment ended. | IT | Garante | GDPR | €3,000 | ↗ |
| 30 Jan 2021 | DEGOM, S.A.DEGOM, S.A. was fined EUR 3,000 by the AEPD for failing to display cookie warnings and data protection acceptance checkboxes on its website. The case concerned deficiencies in online transparency and user consent requirements. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 08 Apr 2022 | B.B.B.The entity was fined for installing security cameras that recorded audio and covered areas such as the restroom without proper notice to employees or customers. The authority found this breached GDPR rules on data processing and transparency of information. | ES | AEPD | GDPR | €3,000 | ↗ |
| 01 Jan 2021 | LA MAISON DU BAMBOULA MAISON DU BAMBOU was fined EUR 3,000 by the AEPD for sending commercial emails without the recipient's consent. The conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jan 2014 | COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD EUR 3,000 for sending unsolicited spam messages without providing an opt-out mechanism. The conduct breached Article 21 of the LSSI and failed to meet basic requirements for marketing communications. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 02 Dec 2019 | GARANTIZA AUTOMOCIÓN, S.L.The company was fined by the AEPD in the amount of EUR 3,000 for failing to provide information or obtain consent for the use of cookies on its website. The breach concerned LSSI requirements on transparency and user consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |