Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
25 May 2018Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the AEPD for sending unsolicited commercial SMS messages to a non-customer without consent. The case concerns a breach of direct marketing rules and the requirement to obtain prior consent.ESAEPDePrivacy€3,300
12 Jun 2017VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 3,300 EUR for sending commercial communications to a former customer after a request for data cancellation. The authority also noted an allegation of sharing personal data with third parties without consent.ESAEPDePrivacy€3,300
19 Sept 2017CEPSA COMERCIAL PETRÓLEO, S.A.U.CEPSA was fined by the AEPD 3,300 EUR for sending two unsolicited commercial emails without prior consent from the recipients. The authority found this breached Article 21 of the LSSI on commercial communications.ESAEPDePrivacy€3,300
01 Jan 2019VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España, S.A.U. 3,300 EUR for sending unsolicited commercial SMS messages despite the recipient's objection. This conduct breached Article 21 of the LSSI on commercial communications.ESAEPDePrivacy€3,300
23 Jan 2017BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€3,300
21 Nov 2017IBERIA LINEAS AEREAS DE ESPAÑA, S.A. OPERADORA, SOCIEDAD UNIPERSONALIberia was fined by the AEPD in the amount of 3,300 EUR for sending commercial emails without the recipient's consent. The authority found a breach of Article 21.1 of the LSSI on unsolicited electronic communications.ESAEPDePrivacy€3,300
01 Jan 2015CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD in the amount of EUR 3,300. The authority found that the company sent unsolicited advertising emails and failed to properly handle unsubscribe requests, in breach of Article 21 of the LSSI.ESAEPDePrivacy€3,300
03 Feb 2023Epic LtdEpic Ltd was fined by the CyDPC in the amount of 3,250 EUR for making unsolicited calls to former customers without a legal basis. The authority also found insufficient technical and organizational measures to ensure compliant data processing and inadequate data security controls.CYCyDPCGDPR€3,250
01 Jan 2015SOTO GLOBAL SERVICE, S.L.SOTO GLOBAL SERVICE, S.L. was fined by the AEPD €3,200 for sending nine unsolicited commercial emails without prior consent. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€3,200
01 Jan 2013FLAYBOX S.L.FLAYBOX S.L. was fined by the AEPD in the amount of EUR 3,100 for sending unsolicited promotional emails despite the recipient's request to unsubscribe. The authority found a breach of Articles 21.1 and 21.2 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€3,100
16 Feb 2022Anonymisé (CNPD decision-04-fr-2022)The CNPD found that the companies failed to meet the Article 13 GDPR information obligation toward data subjects, including employees and third parties. The breach concerned the lack of proper notice about data processing activities.LUCNPDGDPR€3,100
22 Aug 2024Sancțiuni pentru încălcarea RGPDThe ANSPDCP fined the company EUR 3,000 for violating Article 2 of the GDPR. The case concerned non-compliance with data protection requirements.ROANSPDCPGDPR€3,000
22 Aug 2024Kaufland România SCSKaufland România SCS was fined EUR 3,000 by ANSPDCP for a data security breach. The case concerns an incident involving personal data protection that resulted in an administrative sanction.ROANSPDCPGDPR€3,000
28 Apr 2026RESIDENCIAL ETXE-LAN, S.L.RESIDENCIAL ETXE-LAN, S.L. was fined by the AEPD for failing to provide the required information to the supervisory authority. The breach concerned Article 58(1) GDPR and hindered the authority’s supervisory powers.ESAEPDGDPR€3,000
26 Feb 2026Groupharma s.r.l.s.Groupharma s.r.l.s. was fined EUR 3,000 by the Italian supervisory authority, Garante. The case concerned the company’s failure to respond to a former employee’s request to access and delete personal data, including photos and contact details, from its website after employment ended.ITGaranteGDPR€3,000
30 Jan 2021DEGOM, S.A.DEGOM, S.A. was fined EUR 3,000 by the AEPD for failing to display cookie warnings and data protection acceptance checkboxes on its website. The case concerned deficiencies in online transparency and user consent requirements.ESAEPDePrivacy€3,000
08 Apr 2022B.B.B.The entity was fined for installing security cameras that recorded audio and covered areas such as the restroom without proper notice to employees or customers. The authority found this breached GDPR rules on data processing and transparency of information.ESAEPDGDPR€3,000
01 Jan 2021LA MAISON DU BAMBOULA MAISON DU BAMBOU was fined EUR 3,000 by the AEPD for sending commercial emails without the recipient's consent. The conduct breached Article 21 of the LSSI.ESAEPDePrivacy€3,000
01 Jan 2014COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD EUR 3,000 for sending unsolicited spam messages without providing an opt-out mechanism. The conduct breached Article 21 of the LSSI and failed to meet basic requirements for marketing communications.ESAEPDePrivacy€3,000
02 Dec 2019GARANTIZA AUTOMOCIÓN, S.L.The company was fined by the AEPD in the amount of EUR 3,000 for failing to provide information or obtain consent for the use of cookies on its website. The breach concerned LSSI requirements on transparency and user consent.ESAEPDePrivacy€3,000