BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Dec 2023 | SOCIETE DE SUPPORT LOGISTIQUECNIL imposed a fine of EUR 32 million on SOCIETE DE SUPPORT LOGISTIQUE. The case concerned identified regulatory violations, with no further details provided in the source data. | FR | CNIL | GDPR | €32,000,000 | ↗ |
| 27 Dec 2023 | COMITE SOCIAL ECONOMIQUE D'ENTREPRISES (procédure simplifiée)The CNIL imposed an administrative fine of 10,000 EUR on COMITE SOCIAL ECONOMIQUE D'ENTREPRISES under a simplified procedure. The case concerns a confirmed regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €10,000 | ↗ |
| 27 Dec 2023 | ASSOCIATION PROMOUVANT DES ACTIONS AU SEIN D'UNE COMMUNE (procédure simplifiée)CNIL imposed a 5,000 EUR fine on ASSOCIATION PROMOUVANT DES ACTIONS AU SEIN D'UNE COMMUNE and issued an injunction. The case concerned a confirmed data protection breach handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 29 Dec 2023 | SOCIETE PERMETTANT D'EFFECTUER DES PAIEMENTS EN LIGNEA fine of EUR 105,000 was imposed by the CNIL. The case concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €105,000 | ↗ |
| 29 Dec 2023 | CORPORACIÓN DUAL GRUPO LC, S.L.CORPORACIÓN DUAL GRUPO LC, S.L. was fined €500 by the AEPD for failing to provide access to personal data and information requested by the data protection authority. The case concerns non-compliance with GDPR obligations, including Article 58(1). | ES | AEPD | GDPR | €500 | ↗ |
| 29 Dec 2023 | SOCIETE PROPOSANT DES SERVICES DE TELECOMUNICATIONCNIL imposed a fine of EUR 10,000,000 on SOCIETE PROPOSANT DES SERVICES DE TELECOMUNICATION. The case concerns breaches of personal data protection rules. | FR | CNIL | GDPR | €10,000,000 | ↗ |
| 29 Dec 2023 | SOCIETE DE SITES EN LIGNE DE JEUX-CONCOURS ET TESTS PRODUITSCNIL imposed a fine of 75,000 EUR on SOCIETE DE SITES EN LIGNE DE JEUX-CONCOURS ET TESTS PRODUITS and issued an injunction. The case concerns identified breaches of rules supervised by CNIL. | FR | CNIL | GDPR | €75,000 | ↗ |
| 29 Dec 2023 | SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUESThe CNIL imposed a fine of EUR 100,000 on SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES. The case concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €100,000 | ↗ |
| 01 Jan 2024 | SANTANDER CONSUMER FINANCE, S.A.Santander Consumer Finance, S.A. was fined by the AEPD 500,000 EUR for a data protection breach. The incident affected personal identification and contact data of 28,120 individuals. | ES | AEPD | GDPR | €500,000 | ↗ |
| 01 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the original user's consent. The incident led to unauthorized access to personal and banking data. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | CIBERSEO JAÉN, S.L.CIBERSEO JAÉN, S.L. was fined EUR 1,500 by the AEPD for publishing a photograph of an individual without consent on a job search website. The case concerned processing personal data without a lawful basis, contrary to Article 6 of the GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 01 Jan 2024 | B.B.B.B.B.B. was fined by the AEPD in the amount of 10,000 EUR for publishing a patient's medical photos on social media without consent. The conduct breached GDPR Articles 6(1) and 9, which govern lawful processing and special categories of personal data. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD for issuing a duplicate SIM card without proper consent or identity verification. The failure enabled identity theft and fraudulent transactions. | ES | AEPD | GDPR | €300,000 | ↗ |
| 01 Jan 2024 | ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. was fined by the AEPD EUR 140,000 for unauthorized access to personal data. The authority found a breach of GDPR confidentiality and security principles. | ES | AEPD | GDPR | €140,000 | ↗ |
| 01 Jan 2024 | FRESHLY COSMETICS, S.L.FRESHLY COSMETICS, S.L. was fined by the AEPD EUR 10,000 for using advertising cookies on its website without user consent. The authority found this breached Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 01 Jan 2024 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 200,000 EUR by the AEPD for issuing a duplicate SIM card without the customer’s consent. The incident led to unauthorized financial transactions, indicating significant failures in authorization and security controls. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined by the AEPD for failing to ensure the integrity and confidentiality of personal data and for conducting an inadequate risk analysis and impact assessment. The deficiencies led to data breaches involving third-party systems, indicating weaknesses in operational and oversight controls. | ES | AEPD | GDPR | €1,040,000 | ↗ |
| 01 Jan 2024 | ENDESA ENERGIA, S.A.U.ENDESA ENERGIA, S.A.U. was fined €200,000 by the AEPD for changing the contract holder and bank account without consent. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | EMPRENDEDORES ONLINE, LLCEMPRENDEDORES ONLINE, LLC was fined by the AEPD 10,000 EUR for recording and sharing course participants’ personal data without consent. The authority found a breach of GDPR Articles 5(1)(f) and 6(1), indicating unlawful processing and insufficient legal basis. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | B.B.B.The entity “Amor Ideal”, a personal relationship agency, was fined EUR 600 by the AEPD. The authority found that it failed to provide the required information about personal data processing, which constitutes a breach of Article 13 GDPR. | ES | AEPD | GDPR | €600 | ↗ |