Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jun 2024KAFFA KOFFEE ORGANISATION, S.L.KAFFA KOFFEE ORGANISATION, S.L. was fined by the AEPD EUR 2,000 for sending an email to more than 400 recipients without using BCC. This exposed other recipients’ email addresses and breached GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€2,000
30 Jul 2025ONEY SERVICIOS FINANCIEROS EFC, S.A.The AEPD fined ONEY Servicios Financieros EFC, S.A. 150,000 EUR for failing to adequately protect personal data. The breach led to a security incident in which a third party accessed a customer's account through a vishing attack.ESAEPDGDPR€150,000
11 Jan 2021RIPOBRUNA 2007, S.L.RIPOBRUNA 2007, S.L. was fined by the AEPD 2,000 EUR for installing surveillance cameras directed toward public spaces without justified cause. The authority found this processing to be contrary to data protection principles.ESAEPDGDPR€2,000
30 Jul 2014ORANGE ESPAGNE S.A.U.ORANGE ESPAGNE S.A.U. was fined by the AEPD EUR 1,500 for sending unsolicited commercial SMS messages. The recipient had previously requested removal from the advertising list, and the conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,500
09 Sept 2021B.B.B.B.B.B. was fined by the AEPD for installing a CCTV system in a café that recorded public areas without proper signage. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,000
15 Jul 2024ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD 200,000 EUR for failing to properly handle a data subject’s request for deletion and for processing personal data without a legal basis. The case concerns breaches of core data protection obligations.ESAEPDGDPR€200,000
12 Mar 2024SARARTE, S.L.SARARTE, S.L. was fined 6,000 EUR by the AEPD for disclosing personal data, including a private mobile number, to 18 people without consent. The case indicates a breach of data protection rules and unauthorized sharing of information.ESAEPDGDPR€6,000
24 Mar 2023A.A.A.A.A.A. was fined EUR 300 by the AEPD for failing to provide adequate information about data processing in a video surveillance system. The authority found a breach of Article 13 GDPR because data subjects did not receive the required information.ESAEPDGDPR€300
19 Feb 2024XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 200,000 by the AEPD for processing personal data without a legal basis. The case concerned a phone number portability carried out without the user's consent, which breached the requirement for lawful processing.ESAEPDGDPR€200,000
30 Jul 2010TELEFONICA MOVILES ESPAÑA S.A.TELEFONICA MOVILES ESPAÑA S.A. was fined by the AEPD EUR 600 for sending unsolicited commercial messages without prior consent. This constituted a breach of Article 21.1 of the Spanish LSSI.ESAEPDePrivacy€600
01 Jan 2013SPACIO TERMAL, S.L.SPACIO TERMAL, S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails without the required consent. The conduct breached Article 21 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€600
22 Jul 2025KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD in the amount of EUR 4,000 for sending unsolicited messages and processing personal data without a legal basis. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€4,000
07 Feb 2022IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined €30,000 by the AEPD for using non-essential cookies on its website without obtaining prior user consent. The case concerns non-compliance with cookie consent rules and related user information requirements.ESAEPDePrivacy€30,000
29 Apr 2021LA ROCA NETWORKS, S.L.LA ROCA NETWORKS, S.L. was fined by the AEPD €1,000 for sending commercial emails to an individual whose email address was included in the Robinson List. The conduct breached Spanish data protection rules governing unsolicited marketing communications.ESAEPDePrivacy€1,000
01 Jan 2022UNION SINDICAL OBRERAThe labor union UNION SINDICAL OBRERA was fined by the AEPD for failing to comply with a prior decision on the complainant’s right to data deletion. Despite being notified of the obligation to stop, it continued sending emails.ESAEPDGDPR€3,000
30 Nov 2022CBHNOS S.L.CBHNOS S.L. was fined 500 EUR by the AEPD for installing a video surveillance system that could capture images of public areas. The authority considered this a breach of data protection rules.ESAEPDGDPR€500
30 Oct 2024COLEGIO NOTARIAL DE ARAGÓNCOLEGIO NOTARIAL DE ARAGÓN was fined by the AEPD for implementing a fingerprint-based time control system without carrying out a data protection impact assessment. The authority found breaches of GDPR Articles 9 and 35.ESAEPDGDPR€10,000
01 Jan 2021ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 800,000 EUR by the AEPD for failing to adequately protect personal data. The breach enabled identity fraud and unauthorized access to banking information through SIM card duplication.ESAEPDGDPR€800,000
02 Feb 2011TELEFONICA MOVILES ESPAÑA S.A.TELEFONICA MOVILES ESPAÑA S.A. was fined EUR 30,001 by the AEPD for sending unsolicited commercial communications via MMS and SMS. The messages were sent after the complainant had revoked consent, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,001
01 Jan 2024ENDESA ENERGIA, S.A.U.ENDESA ENERGIA, S.A.U. was fined €200,000 by the AEPD for changing the contract holder and bank account without consent. The authority found a breach of data protection principles.ESAEPDGDPR€200,000