Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2024CAIXABANK, S.A.CAIXABANK was fined by the AEPD for sending a privacy policy update to a non-client. The authority found that the stated legitimate-interest basis for processing did not have proper consent support.ESAEPDGDPR€200,000
01 Jan 2024MAKING SOLUTIONS, S.L. (MY PERFECT WEDDING)MAKING SOLUTIONS, S.L. (MY PERFECT WEDDING) was fined 1,000 EUR by the AEPD. The authority found a breach of Article 15 GDPR for failing to provide an individual with access to their personal data.ESAEPDGDPR€1,000
01 Jan 2024GESTERNOVA, S.A.GESTERNOVA, S.A. was fined by the AEPD in the amount of 220,000 EUR for processing personal data without a valid legal basis. The authority also found that the company failed to provide the required information to the data subject, in breach of GDPR Articles 6(1), 13, and 14.ESAEPDGDPR€220,000
01 Jan 2024HIGHCLIFFE ESTATES MARBELLA, S.L.HIGHCLIFFE ESTATES MARBELLA, S.L. was fined by the AEPD 8,500 EUR for publishing personal data, including names and images, on its website without the data subjects’ consent. The authority found this to be a breach of Article 6(1) GDPR.ESAEPDGDPR€8,500
01 Jan 2024VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España 200,000 EUR for processing personal data without meeting the legal requirements of Article 6(1) GDPR. The case was linked to a fraudulent SIM card swap that resulted in unauthorized bank transfers.ESAEPDGDPR€200,000
01 Jan 2024BONTECU DISTRIBUCIONES, S.L.U.BONTECU DISTRIBUCIONES, S.L.U. was fined by the AEPD for processing personal data without consent and for failing to have proper data processing agreements in place. The case concerned a complainant who received an unsolicited contract from Factor Energía.ESAEPDGDPR€25,000
01 Jan 2024VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for processing personal data without consent. The case involved duplicating a SIM card without the user's authorization, which led to unauthorized bank transactions.ESAEPDGDPR€200,000
01 Jan 2024ORANGE BANK, S.A. SUCURSAL EN ESPAÑAOrange Bank was fined for a security breach that exposed personal data. The authority found a violation of Article 5(1)(f) of the GDPR.ESAEPDGDPR€1,500,000
01 Jan 2024COMUNIDAD DE PROPIETARIOS L.L.L.COMUNIDAD DE PROPIETARIOS L.L.L. was fined by the AEPD 2,000 EUR for posting a list of debtor co-owners in a publicly accessible area and for sending erroneous debtor lists by email without justification. The authority found that these actions breached data protection principles.ESAEPDGDPR€2,000
01 Jan 2024UAB VintedUAB Vinted received a EUR 2.385 million GDPR fine in Lithuania. The authority cited issues in user data processing, handling of data subject rights, and risk management.LTValstybinė duomenų apsaugos inspekcijaGDPR€2,385,000
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 120,000 EUR for a data protection breach involving unauthorized SIM card duplication. The incident enabled fraudulent activity, and the authority found that the company had not implemented sufficient preventive measures.ESAEPDGDPR€120,000
01 Jan 2024WAGESTREAM SPAIN S.L.U.WAGESTREAM SPAIN S.L.U. was fined by the AEPD for processing employees’ personal data without proper consent. The case involved names, personal email addresses, bank account numbers, and salary details, in breach of Article 6(1) GDPR.ESAEPDGDPR€2,000
01 Jan 2024UNIVERSITAS NEBRISSENSIS, S.A.UNIVERSITAS NEBRISSENSIS, S.A. was fined by the AEPD EUR 50,000 for requesting a full copy of a student's ID. The authority found that this breached GDPR data minimization principles and security requirements.ESAEPDGDPR€50,000
01 Jan 2024ESCOLA LES CAROLINES COOP. V.The school was fined by the AEPD 10,000 EUR for processing a minor’s image without a lawful basis. The child’s photograph was displayed on posters inside the school premises, which was found to breach GDPR Article 6(1).ESAEPDGDPR€10,000
01 Jan 2024ACTIVOS INTELIGENTES, S.L.ACTIVOS INTELIGENTES, S.L. was fined by the AEPD 5,000 EUR for requiring guests to submit selfies with their ID cards during check-in. The authority found the data collection excessive and not properly justified or explained in terms of processing purposes.ESAEPDGDPR€5,000
01 Jan 2024SUPERVISTA OPTICS SLUSUPERVISTA OPTICS SLU was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a user who had previously opted out. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€20,000
01 Jan 2024INCIBEINCIBE was fined EUR 2,000 by the AEPD for failing to implement data protection by design and by default, in breach of Article 25 GDPR. The procedure concerning the alleged breach of Article 5(1)(f) was dismissed because no serious threat to rights and freedoms was found.ESAEPDGDPR€2,000
01 Jan 2024GASEXPRESS PATRAIX, S.L.GASEXPRESS PATRAIX, S.L. was fined by the AEPD 25,000 EUR for allowing unauthorized access to previous users' data in its automated gas station system. The exposed information included DNI numbers and partial credit card numbers.ESAEPDGDPR€25,000
01 Jan 2024AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD 2,000 EUR for improperly accessing personal data linked to a phone number without the owner's consent. The authority found a breach of Article 7 of the GDPR.ESAEPDGDPR€2,000
01 Jan 2024MAD COOL FESTIVAL, S.L.MAD COOL FESTIVAL, S.L. was fined 3,500 EUR by the AEPD for a data breach on its website. The incident exposed users’ personal data, indicating non-compliance with GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€3,500