BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2024 | CAIXABANK, S.A.CAIXABANK was fined by the AEPD for sending a privacy policy update to a non-client. The authority found that the stated legitimate-interest basis for processing did not have proper consent support. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | MAKING SOLUTIONS, S.L. (MY PERFECT WEDDING)MAKING SOLUTIONS, S.L. (MY PERFECT WEDDING) was fined 1,000 EUR by the AEPD. The authority found a breach of Article 15 GDPR for failing to provide an individual with access to their personal data. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 Jan 2024 | GESTERNOVA, S.A.GESTERNOVA, S.A. was fined by the AEPD in the amount of 220,000 EUR for processing personal data without a valid legal basis. The authority also found that the company failed to provide the required information to the data subject, in breach of GDPR Articles 6(1), 13, and 14. | ES | AEPD | GDPR | €220,000 | ↗ |
| 01 Jan 2024 | HIGHCLIFFE ESTATES MARBELLA, S.L.HIGHCLIFFE ESTATES MARBELLA, S.L. was fined by the AEPD 8,500 EUR for publishing personal data, including names and images, on its website without the data subjects’ consent. The authority found this to be a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €8,500 | ↗ |
| 01 Jan 2024 | VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España 200,000 EUR for processing personal data without meeting the legal requirements of Article 6(1) GDPR. The case was linked to a fraudulent SIM card swap that resulted in unauthorized bank transfers. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | BONTECU DISTRIBUCIONES, S.L.U.BONTECU DISTRIBUCIONES, S.L.U. was fined by the AEPD for processing personal data without consent and for failing to have proper data processing agreements in place. The case concerned a complainant who received an unsolicited contract from Factor Energía. | ES | AEPD | GDPR | €25,000 | ↗ |
| 01 Jan 2024 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for processing personal data without consent. The case involved duplicating a SIM card without the user's authorization, which led to unauthorized bank transactions. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | ORANGE BANK, S.A. SUCURSAL EN ESPAÑAOrange Bank was fined for a security breach that exposed personal data. The authority found a violation of Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €1,500,000 | ↗ |
| 01 Jan 2024 | COMUNIDAD DE PROPIETARIOS L.L.L.COMUNIDAD DE PROPIETARIOS L.L.L. was fined by the AEPD 2,000 EUR for posting a list of debtor co-owners in a publicly accessible area and for sending erroneous debtor lists by email without justification. The authority found that these actions breached data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2024 | UAB VintedUAB Vinted received a EUR 2.385 million GDPR fine in Lithuania. The authority cited issues in user data processing, handling of data subject rights, and risk management. | LT | Valstybinė duomenų apsaugos inspekcija | GDPR | €2,385,000 | ↗ |
| 01 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 120,000 EUR for a data protection breach involving unauthorized SIM card duplication. The incident enabled fraudulent activity, and the authority found that the company had not implemented sufficient preventive measures. | ES | AEPD | GDPR | €120,000 | ↗ |
| 01 Jan 2024 | WAGESTREAM SPAIN S.L.U.WAGESTREAM SPAIN S.L.U. was fined by the AEPD for processing employees’ personal data without proper consent. The case involved names, personal email addresses, bank account numbers, and salary details, in breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2024 | UNIVERSITAS NEBRISSENSIS, S.A.UNIVERSITAS NEBRISSENSIS, S.A. was fined by the AEPD EUR 50,000 for requesting a full copy of a student's ID. The authority found that this breached GDPR data minimization principles and security requirements. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2024 | ESCOLA LES CAROLINES COOP. V.The school was fined by the AEPD 10,000 EUR for processing a minor’s image without a lawful basis. The child’s photograph was displayed on posters inside the school premises, which was found to breach GDPR Article 6(1). | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | ACTIVOS INTELIGENTES, S.L.ACTIVOS INTELIGENTES, S.L. was fined by the AEPD 5,000 EUR for requiring guests to submit selfies with their ID cards during check-in. The authority found the data collection excessive and not properly justified or explained in terms of processing purposes. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2024 | SUPERVISTA OPTICS SLUSUPERVISTA OPTICS SLU was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a user who had previously opted out. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 01 Jan 2024 | INCIBEINCIBE was fined EUR 2,000 by the AEPD for failing to implement data protection by design and by default, in breach of Article 25 GDPR. The procedure concerning the alleged breach of Article 5(1)(f) was dismissed because no serious threat to rights and freedoms was found. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2024 | GASEXPRESS PATRAIX, S.L.GASEXPRESS PATRAIX, S.L. was fined by the AEPD 25,000 EUR for allowing unauthorized access to previous users' data in its automated gas station system. The exposed information included DNI numbers and partial credit card numbers. | ES | AEPD | GDPR | €25,000 | ↗ |
| 01 Jan 2024 | AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD 2,000 EUR for improperly accessing personal data linked to a phone number without the owner's consent. The authority found a breach of Article 7 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2024 | MAD COOL FESTIVAL, S.L.MAD COOL FESTIVAL, S.L. was fined 3,500 EUR by the AEPD for a data breach on its website. The incident exposed users’ personal data, indicating non-compliance with GDPR Articles 5(1)(f) and 32. | ES | AEPD | GDPR | €3,500 | ↗ |