Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Jun 2024APARTAMENTOS BUENAVISTA HOMEAPARTAMENTOS BUENAVISTA HOME was fined EUR 1,000 by the AEPD for requesting guests to submit electronic images of their ID documents. The authority found that this practice breached the GDPR data minimization principle.ESAEPDGDPR€1,000
01 Jan 2019AVON COSMETICS SAUAVON COSMETICS SAU was fined by the AEPD 60,000 EUR for improper processing of personal data. The company included an individual in a creditworthiness file without first verifying the person’s identity.ESAEPDGDPR€60,000
01 Jan 2024B.B.B.B.B.B. was fined by the AEPD in the amount of 10,000 EUR for publishing a patient's medical photos on social media without consent. The conduct breached GDPR Articles 6(1) and 9, which govern lawful processing and special categories of personal data.ESAEPDGDPR€10,000
07 Sept 2021B.B.B.The entity was fined by the AEPD 5,000 EUR for publicly disseminating surveillance footage without justification. The authority found that this conduct breached data protection principles.ESAEPDGDPR€5,000
01 Jan 2019VIAQUA XESTIÓN INTEGRAL DE AUGAS DE GALICIA, S.A.The company changed contract data without authorization, which constituted a breach of Article 6 of the GDPR. The AEPD imposed a fine of 60,000 EUR.ESAEPDGDPR€60,000
14 Sept 2011BONANZA DIGITAL SERVICES S.L.BONANZA DIGITAL SERVICES S.L. was fined by the AEPD €1,800 for sending unsolicited SMS messages with sexual content. The authority found this breached Article 21 of the LSSI on commercial communications sent without recipient consent.ESAEPDePrivacy€1,800
01 Mar 2017CGPN, SARLCGPN, SARL was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails without prior consent. This conduct breached Spanish data protection rules.ESAEPDePrivacy€2,000
01 Jan 2020Caja Rural San José de Nules S. Cooperativa de Crédito de la Comunidad ValencianaCaja Rural San José de Nules was fined by the AEPD 5,000 EUR for publicly displaying individuals’ personal data on a notice board. The conduct breached data protection principles by exposing their economic status.ESAEPDGDPR€5,000
06 Mar 2023B.B.B.The entity was fined by the AEPD €5,000 for publishing radio amateurs’ personal data on a Telegram channel. The breach involved linking call signs to personal information, which violated data protection rules.ESAEPDGDPR€5,000
11 Mar 2022CINCON S.C.CINCON S.C. was fined EUR 500 by the AEPD for failing to provide adequate information about the retention period of personal data collected through a website form. The authority found a breach of Article 13 GDPR because data subjects were not given the required notice.ESAEPDGDPR€500
01 Jan 2019VODAFONE ESPAÑA, S.A.UVodafone España, S.A.U was fined by the AEPD in the amount of 2,500 EUR for sending unsolicited advertising messages to a business phone number without consent. The case concerned Article 21 of the LSSI, which governs marketing communications without prior recipient consent.ESAEPDePrivacy€2,500
23 Apr 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for changing a customer's mobile line ownership without consent. The company also charged the customer's account amounts related to a third party's phone line.ESAEPDGDPR€50,000
01 Jan 2023Vodafone España, S.A.U.The AEPD fined Vodafone España EUR 70,000 for providing a SIM card duplicate to a third party without the data subject's consent. This enabled unauthorized access to personal and banking information.ESAEPDGDPR€70,000
30 Aug 2023LORO PARQUE, S.A.LORO PARQUE, S.A. was fined by the AEPD 250,000 EUR for processing biometric data without a proper legal basis. The authority classified this as a very serious breach of Article 9 GDPR.ESAEPDGDPR€250,000
23 Aug 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined EUR 15,000 by the AEPD for failing to comply with a resolution concerning the right of access. The authority cited a breach of Article 83(6) GDPR.ESAEPDGDPR€15,000
02 Oct 2020INSTITUTO DEL DAÑO CEREBRAL Y PSÍQUICO, S.L.The entity did not provide timely access to clinical records, which constituted a breach of data protection obligations. Deficiencies were also identified in the website's cookie policy, leading the AEPD to impose a fine.ESAEPDePrivacy€3,000
18 Apr 2023B.B.B.A neighbor installed a surveillance camera aimed at the public street without authorization. The authority found this breached the data minimization principle under GDPR Article 5(1)(c).ESAEPDGDPR€300
07 May 2024PINKGREEN BARCELONA, S.L.PINKGREEN BARCELONA, S.L. was fined by the AEPD 4,000 EUR for disclosing personal data of individuals in responses to negative Google reviews. The authority found that the processing breached Articles 6 and 9 of the GDPR.ESAEPDGDPR€4,000
22 Feb 2023MUNDOVIAJES2010, S.L.MUNDOVIAJES2010, S.L. was fined by the AEPD in the amount of 7,000 EUR for processing personal data without consent. The authority also found a failure to provide the required information about data processing, in breach of GDPR Articles 6(1) and 14.ESAEPDGDPR€7,000
09 Sept 2025EVELB TÉCNICAS Y SISTEMAS, S.LEVELB TÉCNICAS Y SISTEMAS, S.L was fined by the AEPD 5,000 EUR for breaching Article 5(1)(f) GDPR. The case concerned inadequate data security measures that caused a temporary loss of data availability.ESAEPDGDPR€5,000