BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 May 2022 | UNIDAD EDITORIAL INFORMACIÓN GENERAL, S.L.U.The entity published an audio recording of a victim's court testimony without consent. AEPD found this to be a breach of data protection law and imposed a 50,000 EUR fine. | ES | AEPD | GDPR | €50,000 | ↗ |
| 18 Mar 2025 | AUTOESCUELA A.A.A.The AEPD imposed a EUR 500 fine on AUTOESCUELA A.A.A. for failing to respond to a data subject's request for access to and deletion of personal data. The authority also found that the company did not provide the required signage for its video surveillance system, breaching GDPR information duties. | ES | AEPD | GDPR | €500 | ↗ |
| 07 Feb 2011 | EL CORTE INGLES, S.A.EL CORTE INGLES, S.A. was fined 35,000 EUR by the AEPD for sending nine commercial emails without the recipient’s consent. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €35,000 | ↗ |
| 08 Jul 2024 | COMERCIAL GIRONA DE LLIBRES, S.L.COMERCIAL GIRONA DE LLIBRES, S.L. was fined by the AEPD 20,000 EUR for inadequate security measures. The authority cited, among other issues, the sending of credentials by email, which breached Article 32 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 10 Nov 2023 | VERNE INFORMATION TECHNOLOGY, S.L.VERNE INFORMATION TECHNOLOGY, S.L. was fined 2,000 EUR by the AEPD. The case concerned sending unsolicited commercial electronic communications without prior consent or an existing contractual relationship. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 03 Oct 2023 | ASOCIACIÓN DE PROFESIONALES DE LA SEGURIDAD PRIVADA DE ESPAÑAThe association was fined for sending emails from personal email addresses instead of corporate ones. The authority found that this practice breached GDPR confidentiality and security requirements. | ES | AEPD | GDPR | €1,500 | ↗ |
| 26 Oct 2022 | FUNDACIÓN CITIZENGOFUNDACIÓN CITIZENGO was fined by the AEPD EUR 5,000 for sending unsolicited emails without recipients’ consent. The authority found a breach of Article 7 GDPR on valid consent. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2024 | SANTANDER CONSUMER FINANCE, S.A.Santander Consumer Finance, S.A. was fined by the AEPD 500,000 EUR for a data protection breach. The incident affected personal identification and contact data of 28,120 individuals. | ES | AEPD | GDPR | €500,000 | ↗ |
| 30 Oct 2023 | CLÍNICA PARÍS, S.L.CLÍNICA PARÍS, S.L. was fined 1,000 EUR by the AEPD for failing to properly handle a data subject access request. The authority found a breach of GDPR obligations. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 Jan 2021 | ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINEThe entity was fined by the AEPD 5,000 EUR for failing to comply with a data deletion request and for sending unsolicited marketing emails without consent. The case indicates non-compliance with data subject rights and rules on direct marketing communications. | ES | AEPD | GDPR | €5,000 | ↗ |
| 30 May 2016 | UNION DISTRIBUIDORA DE EDICIONES DE ARAGON S.L.UNION DISTRIBUIDORA DE EDICIONES DE ARAGON S.L. was fined EUR 800 by the AEPD for sending unsolicited commercial emails. The authority found that the messages continued despite the recipient’s attempts to unsubscribe. | ES | AEPD | ePrivacy | €800 | ↗ |
| 14 Mar 2011 | IVY SOLUTIONS S.L.IVY SOLUTIONS S.L. was fined EUR 600 by the AEPD for sending unsolicited commercial emails without the recipient's consent. The conduct breached Article 21 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €600 | ↗ |
| 01 Jan 2019 | IKEA IBERICA, S.A.U.The AEPD fined IKEA IBERICA, S.A.U. 10,000 EUR for installing cookies on users’ devices without obtaining prior informed consent. The authority found this breached Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 25 Mar 2017 | IMPACTING EMAIL MARKETING SOLUTIONS S.L.IMPACTING EMAIL MARKETING SOLUTIONS S.L. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent. The authority found this conduct to be in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 25 Feb 2022 | B.B.B.B.B.B. was fined by the AEPD in the amount of EUR 300 for installing a surveillance camera that captured a public transit area. The footage was then disseminated without consent, which constituted a breach of data protection rules. | ES | AEPD | GDPR | €300 | ↗ |
| 21 Mar 2012 | GROUPON SPAIN SLGROUPON SPAIN SL was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails. The messages were sent despite the recipient's requests to unsubscribe, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 11 Apr 2023 | CORPORACION DE MEDIOS DE EXTREMADURA, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. The authority found a breach of the data minimization principle and imposed a 150,000 EUR fine. | ES | AEPD | GDPR | €150,000 | ↗ |
| 04 Nov 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 70,000 EUR for processing a fraudulent phone number portability request without the data subject's consent. The authority found a breach of GDPR Article 6(1). | ES | AEPD | GDPR | €70,000 | ↗ |
| 11 Feb 2020 | AMALFI SERVICIOS DE RESTAURACIÓN S.L.AMALFI SERVICIOS DE RESTAURACIÓN S.L. was fined by the AEPD 6,000 EUR for installing surveillance cameras without proper consent. The authority also found that the cameras captured images of public spaces without sufficient justification, breaching data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 28 May 2024 | B.B.B.B.B.B., a councilor, unlawfully published the personal data of a complainant and their spouse in a municipal meeting note. The information was shared with a group of about 400 people, causing reputational harm. | ES | AEPD | GDPR | €1,000 | ↗ |