BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2024 | COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company was fined EUR 80,000 by the AEPD for processing a gas contract without the complainant's consent. It used personal data without authorization, which constitutes a breach of data protection law. | ES | AEPD | GDPR | €80,000 | ↗ |
| 01 Jan 2024 | XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD for failing to ensure the security and confidentiality of personal data. The incident resulted in a data breach and created a risk of identity theft. | ES | AEPD | GDPR | €4,000,000 | ↗ |
| 01 Jan 2024 | FLEXICAR IBÉRICA, S.L.FLEXICAR IBÉRICA, S.L. was fined €50,000 by the AEPD for a personal data breach. The incident occurred when information belonging to other clients was mistakenly shared via WhatsApp. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2024 | a small recruitment bureauA small recruitment bureau in the Netherlands was fined EUR 6,000 by the Autoriteit Persoonsgegevens for failing to respond on time to an ex-candidate’s request to delete personal data. The Raad van State upheld the fine in case ECLI:NL:RVS:2024:2221. | NL | Autoriteit Persoonsgegevens | GDPR | €6,000 | ↗ |
| 01 Jan 2024 | FRUTAS CALISA, S.L.FRUTAS CALISA, S.L. was fined 300 EUR by the AEPD for contacting an individual via WhatsApp without prior consent. The authority found this conduct to be a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 01 Jan 2024 | EXCEL HOTELS & RESORTS, S.A.EXCEL HOTELS & RESORTS, S.A. was fined by the AEPD 40,000 EUR for leaving property owners’ personal data unattended, including ID and passport numbers. The authority found that this created unauthorized access to sensitive personal information and breached data protection principles. | ES | AEPD | GDPR | €40,000 | ↗ |
| 01 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 130,000 EUR for unauthorized SIM card duplication. The incident led to identity theft and fraudulent charges, and the authority found the data protection measures insufficient. | ES | AEPD | GDPR | €130,000 | ↗ |
| 01 Jan 2024 | EDP SOLAR ESPAÑA, S.A.EDP SOLAR ESPAÑA, S.A. was fined by the AEPD for failing to meet data protection obligations. The breach concerned Article 5(1)(c) of the GDPR, which requires data minimization. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2024 | EDA TV CONSULTING S.L.EDA TV CONSULTING S.L. was fined 5,000 EUR by the AEPD for publishing a minor’s image without consent. The case concerns a breach of data protection rules and the child’s privacy rights. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2024 | ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓNThe entity was fined €4,000 by the AEPD for processing personal data without a lawful basis and for failing to inform the data subject. The authority found breaches of Articles 6 and 14 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 01 Jan 2024 | Santander BankIn 2024, Santander Bank was fined 1,440,000 PLN by UODO. The sanction concerned the failure to report a personal data breach, which is a significant breach of GDPR obligations. | PL | Urząd Ochrony Danych Osobowych | GDPR | €331,000 | ↗ |
| 01 Jan 2024 | REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS S.L.U.REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS S.L.U. was fined by the AEPD for processing personal data without consent, which led to unauthorized access to a customer's data. The authority also found inadequate security measures. | ES | AEPD | GDPR | €1,380,000 | ↗ |
| 01 Jan 2024 | Unnamed data controllerNAIH imposed a HUF 50 million fine on an unnamed public body for failing to provide data to the Central Public Information Register. The case concerned non-publication of financial data required by law. | HU | Nemzeti Adatvédelmi és Információszabadság Hatóság | GDPR | €130,000 | ↗ |
| 02 Jan 2024 | FEDERACIÓN DE SERVICIOS PÚBLICOS DE LA UGT (FSP-UGT)The entity sent emails that disclosed personal data of multiple recipients. The AEPD found a breach of the confidentiality principle under Article 5(1)(f) GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 04 Jan 2024 | N*** -FußballvereinigungThe football association failed to implement appropriate technical and organizational measures for handling data deletion requests. The authority found breaches of Articles 25 and 17 GDPR and imposed a fine of EUR 11,000. | AT | DSB | GDPR | €11,000 | ↗ |
| 05 Jan 2024 | B.B.B.The entity was fined for publishing personal images and phone numbers on Telegram channels without the data subjects’ consent. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 08 Jan 2024 | VUKMAL TRADE, S.L.VUKMAL TRADE, S.L. was fined by the AEPD €2,000 for requiring an employee to use a personal mobile phone for work purposes without consent. The company also shared the employee’s personal number with other staff, breaching data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 08 Jan 2024 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SL.The entity sent unsolicited commercial emails to an individual registered on the Robinson List. This breached Article 21 of the LSSI and led to a fine imposed by the AEPD. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 08 Jan 2024 | INVERTIA TENERIFE 2019, S.L.INVERTIA TENERIFE 2019, S.L. was fined 1,000 EUR by the AEPD for failing to meet its information obligations toward data subjects. The authority found that the required information under Article 13 GDPR was not provided. | ES | AEPD | GDPR | €1,000 | ↗ |
| 09 Jan 2024 | EDITEUR DE SITE WEB - ANNUAIRE INVERSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 1,500 on EDITEUR DE SITE WEB - ANNUAIRE INVERSE under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision. | FR | CNIL | GDPR | €1,500 | ↗ |