Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2023INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L.INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L. was fined by the AEPD EUR 7,000 for unlawfully disclosing personal data, including health information, in response to a Google review. The authority found a breach of confidentiality and of the security obligations under the GDPR.ESAEPDGDPR€7,000
01 Jan 2012IDEAS CREATIVAS DE OPERACION S.L.IDEAS CREATIVAS DE OPERACION S.L. was fined EUR 33,001 by the AEPD for sending unsolicited commercial emails despite requests for data cancellation. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€33,001
31 Jul 2023DOÑA B.B.B.The sanctioned individual created a WhatsApp group with 255 participants without prior consent. As a result, the names and phone numbers of the participants were disclosed, constituting a breach of personal data protection rules.ESAEPDGDPR€2,000
15 Mar 2023BANKINTER CONSUMER FINANCE E.F.C., S.A.Bankinter Consumer Finance issued a duplicate card without the customer's consent and sent it to an incorrect address. This led to unauthorized transactions and indicated a failure in data protection and payment security controls.ESAEPDGDPR€70,000
25 Jul 2023EDICIONES PERIÓDICAS DEL NOROESTE, S.L.The entity published a private video on Twitter without the data subject’s consent. The authority found a breach of data minimization because excessive data were processed beyond what was necessary for the intended purpose.ESAEPDGDPR€10,000
18 Apr 2024DELPASO CAR HIRE, S.L.U.DELPASO CAR HIRE, S.L.U. was fined by the AEPD EUR 2,000 for failing to provide a customer with access to their personal data. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€2,000
29 May 2025IMMUCURA MED, S.L.IMMUCURA MED, S.L. was fined EUR 20,000 by the AEPD for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR.ESAEPDGDPR€20,000
17 Feb 2022VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined EUR 70,000 by the AEPD for issuing a duplicate SIM card to a third party without the customer's consent. This enabled unauthorized access to the customer's bank account.ESAEPDGDPR€70,000
11 Apr 2023CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 200,000 for failing to remove personal data from a credit information system after the debt was sold. The authority found that the continued processing of the data was not compliant with data protection rules.ESAEPDGDPR€200,000
17 Jan 2022SERVICIOS FINANCIEROS CARREFOUR, EFC., S.A.SERVICIOS FINANCIEROS CARREFOUR, EFC., S.A. was fined 20,000 EUR by the AEPD. The authority found that the company failed to properly handle a data subject’s request for erasure, which led to continued processing of personal data despite the prior deletion request.ESAEPDGDPR€20,000
05 Nov 2020B.B.B.The entity was fined by the AEPD EUR 2,000 for using security cameras that recorded public spaces extensively without justification. The authority found that this breached data protection principles.ESAEPDGDPR€2,000
01 Jan 2013FLAYBOX S.L.FLAYBOX S.L. was fined by the AEPD in the amount of EUR 3,100 for sending unsolicited promotional emails despite the recipient's request to unsubscribe. The authority found a breach of Articles 21.1 and 21.2 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€3,100
14 Mar 2022RAMONA FILMS, S.LRAMONA FILMS, S.L was fined by the AEPD for failing to provide requested information to the Spanish Data Protection Agency. The breach concerned the duty to cooperate under GDPR Article 58(1).ESAEPDGDPR€30,000
29 Aug 2025FIATC MUTUA DE SEGUROS Y REASEGUROSFIATC Mutua de Seguros y Reaseguros was fined €40,000 by the AEPD after unauthorized access to its systems. The incident may have exposed personal data, including DNI/CIF, and the authority found inadequate security measures and a breach of Article 5(1)(f) GDPR.ESAEPDGDPR€40,000
08 Aug 2024ASOCIACIÓN SOCIO CULTURAL Y HUMANITARIA VIRGEN DE COROMOTOThe organization was fined 600 EUR by the AEPD for failing to provide access to personal data and information requested by the data protection authority. The case concerned non-compliance with the authority’s powers under Article 58.1 of the GDPR.ESAEPDGDPR€600
10 Jan 2020AUTOMOCION X.X.X. S.L.The company was fined EUR 1,000 by the AEPD for placing an individual's photo, name, and phone number on an adult contact website without consent. The disclosure led to unwanted calls and constituted a breach of personal data protection rules.ESAEPDGDPR€1,000
18 Jun 2021DESPACHO TEJEDOR INFANTES CONSULTORES ASESORES, S.L.The entity unlawfully disclosed personal data to a third party, breaching the confidentiality principle under GDPR. The AEPD imposed a fine of 2,000 EUR.ESAEPDGDPR€2,000
16 Sept 2022B.B.B.B.B.B. was fined EUR 300 by the AEPD for installing a surveillance camera. The authority found that the device may have recorded images of a neighboring property without consent, potentially breaching data protection rules.ESAEPDGDPR€300
12 Dec 2024BREOGAN AUTOLUX, S.L.BREOGAN AUTOLUX, S.L. was fined EUR 10,000 by the AEPD for sending unsolicited SMS advertisements without prior consent from recipients. The authority also found that the messages did not provide an opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€10,000
05 Jul 2019VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined €120,000 by the AEPD for failing to exercise due diligence in response to a fraudulent situation involving unauthorized service contracts. The authority found a breach of Article 6 GDPR.ESAEPDGDPR€120,000