Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Oct 2014MANGO-ON LINE, S.A.MANGO-ON LINE, S.A. was fined by the AEPD €5,000 for continuing to send newsletters to a complainant despite multiple unsubscribe requests. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€5,000
01 Jan 2014DREAM RING, S.L.DREAM RING, S.L. was fined by the AEPD EUR 6,000 for sending unsolicited commercial SMS messages. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior recipient consent.ESAEPDePrivacy€6,000
17 Mar 2021BODY TONIC SHOP, S.L.BODY TONIC SHOP, S.L. was fined by the AEPD EUR 2,000 for processing personal data without proper consent. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
01 Mar 2017PACSOLUTOR S.L.U.PACSOLUTOR S.L.U. was fined by the AEPD in the amount of 3,000 EUR for failing to provide adequate information about cookies on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€3,000
07 Oct 2020UST GLOBAL ESPAÑA, S.A.UST Global España, S.A. was fined by the AEPD EUR 5,000 for improperly sharing employees’ personal data in a group email. The disclosed data included names, email addresses, and DNI numbers, which breached data protection principles.ESAEPDGDPR€5,000
01 Jan 2012IDEAS CREATIVAS DE OPERACIONES, S.L.IDEAS CREATIVAS DE OPERACIONES, S.L. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The authority also found that the company failed to provide a functional opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€30,001
01 Jan 2012MICROLOANS, S.L.MICROLOANS, S.L. was fined EUR 600 by the AEPD. The authority found that the company sent unsolicited commercial emails without prior consent from recipients, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
19 Sept 2017CEPSA COMERCIAL PETRÓLEO, S.A.U.CEPSA was fined by the AEPD 3,300 EUR for sending two unsolicited commercial emails without prior consent from the recipients. The authority found this breached Article 21 of the LSSI on commercial communications.ESAEPDePrivacy€3,300
22 Dec 2023HISPAPOST, S.A.HISPAPOST, S.A. was fined EUR 60,000 by the AEPD for failing to properly safeguard and handle personal data. The incident resulted in the abandonment of 1,404 letters containing personal information, indicating inadequate data protection procedures.ESAEPDGDPR€60,000
03 Feb 2011HUNTER & GATTI, S.L.HUNTER & GATTI, S.L. was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails. The authority also found that the company failed to provide a proper opt-out mechanism, in breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
01 Jan 2015INSTITUTO SUPERIOR DE ESTUDIOS EMPRESARIALES CAMBRIDGE S.A.The entity was fined by the AEPD 1,500 EUR for sending commercial messages without providing recipients a way to oppose further communications. The authority treated this as a breach of the right to data cancellation and control over continued contact.ESAEPDePrivacy€1,500
05 May 2022SOCIEDAD ESPAÑOLA DE RADIODIFUSIÓN, S.L.The Spanish Data Protection Agency (AEPD) fined SOCIEDAD ESPAÑOLA DE RADIODIFUSIÓN, S.L. EUR 50,000 for publishing audio of a victim’s court testimony without adequate data protection safeguards. The authority found a breach of GDPR Article 5(1)(c) on data minimization.ESAEPDGDPR€50,000
01 Jan 2022HOSPITAL POVISA, S.A.HOSPITAL POVISA, S.A. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned the improper inclusion of private health test results in a public health system, which violated the complainant’s privacy.ESAEPDGDPR€30,000
03 Mar 2021COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD EUR 2,000 for installing a surveillance camera system without the required authorization. The cameras recorded private areas, which breached privacy rules.ESAEPDGDPR€2,000
20 Jan 2021XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 40,000 by the AEPD for failing to respond to a data access request. The case concerns non-compliance with GDPR obligations relating to data subject rights.ESAEPDGDPR€40,000
15 Jul 2022URBANO DIVERTIA, S.L.URBANO DIVERTIA, S.L. was fined by the AEPD 2,000 EUR for sending clients documents that contained personal data of third parties. The company also failed to include a reference to its privacy policy in corporate emails, which breached data protection requirements.ESAEPDGDPR€2,000
18 Nov 2010G.L. GISOFT ANÁLISIS Y DISEÑO S.L.G.L. GISOFT ANÁLISIS Y DISEÑO S.L. was fined by the AEPD in the amount of €600 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits such marketing communications without recipient consent.ESAEPDePrivacy€600
01 Jan 2022FEDERACIÓN DE SERVICIOS A LA CIUDADANÍA DE CCOOThe entity was fined by the AEPD €3,000 for breaching data protection principles. The case involved the improper disclosure of personal data related to a COVID-19 case among employees.ESAEPDGDPR€3,000
26 Sept 2012DIGITARAN, S.L.U.DIGITARAN, S.L.U. was fined by the AEPD 3,000 EUR for sending unsolicited advertising SMS messages to a user registered on the Robinson List. The conduct breached Article 21 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€3,000
19 May 2016GRUPO YAMM COMIDA A DOMICILIO, S.L.GRUPO YAMM COMIDA A DOMICILIO, S.L. was fined by the AEPD €1,400 for sending unsolicited commercial emails to a complainant despite requests to stop. The case concerns a breach of the LSSI rules on marketing communications.ESAEPDePrivacy€1,400