BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2022 | ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP.The company was fined by the AEPD EUR 10,000 for processing personal data without consent. The authority also found that its website privacy information was insufficient, including missing contact details and information on data subject rights. | ES | AEPD | GDPR | €10,000 | ↗ |
| 21 Sept 2018 | XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD in the amount of 4,000 EUR for sending unsolicited commercial SMS messages without the recipient’s consent. The conduct breached Article 21.1 of the LSSI, which requires prior consent for marketing communications. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 20 Nov 2017 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 66,000 by the AEPD for sending unsolicited promotional SMS messages. The authority also noted that recipients were not given a means to object to the processing of their data for marketing purposes. | ES | AEPD | ePrivacy | €66,000 | ↗ |
| 26 May 2021 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 50,000 EUR for sending SMS messages about an alleged debt for services not contracted by the complainant. The case involved incorrect processing of personal data and the use of inaccurate contact details. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2015 | SURGE CENTRO DE ESTUDIOS S.L.SURGE CENTRO DE ESTUDIOS S.L. was fined by the AEPD EUR 1,400 for sending unsolicited commercial emails to the complainant. This conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,400 | ↗ |
| 15 Feb 2021 | ANYTIME FITNESS IBERIA, S.L.ANYTIME FITNESS IBERIA, S.L. was fined by the AEPD 15,000 EUR for failing to delete personal data after a request and for sending promotional SMS messages without consent. The case concerns non-compliance with data subject rights and rules on direct marketing. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 20 Feb 2021 | FLEXOGRÁFICA DEL MEDITERRÁNEO, S.L.The company was fined by the AEPD for failing to provide a privacy policy and cookie management on its websites. The authority also found that user consent was collected in a generic manner, which did not meet data protection requirements. | ES | AEPD | GDPR | €3,000 | ↗ |
| 04 Jun 2021 | INTERSUMI S.C.INTERSUMI S.C. was fined EUR 2,000 by the AEPD for not having an adequate privacy policy on its website. The authority found this to be a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 14 Apr 2021 | MASTER DISTANCIA S.A.MASTER DISTANCIA S.A. was fined EUR 25,000 by the AEPD for unlawfully processing personal data by including it in credit information systems without a valid legal basis. The authority found a breach of GDPR Article 6. | ES | AEPD | GDPR | €25,000 | ↗ |
| 11 Apr 2023 | SOCIEDAD VASCONGADA DE PUBLICACIONES, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. AEPD found that this breached the data minimization principle. | ES | AEPD | GDPR | €150,000 | ↗ |
| 01 Jan 2013 | GALIBROKER GESTION TURISTICA, S.L.GALIBROKER GESTION TURISTICA, S.L. was fined by the AEPD 6,000 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 24 Sept 2015 | KREDITECH SPAIN S.L.KREDITECH SPAIN S.L. was fined by the AEPD in the amount of 2,600 EUR for sending unsolicited commercial emails to a complainant. The authority found this conduct to be in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,600 | ↗ |
| 03 Nov 2021 | B.B.B.The entity processed personal data without consent by using the complainant's data to make a purchase on Amazon. The authority found a breach of GDPR Article 6. | ES | AEPD | GDPR | €2,000 | ↗ |
| 18 Dec 2023 | MOTORSPORT NETWORK ESPAÑA, S.L.MOTORSPORT NETWORK ESPAÑA, S.L. was fined by the AEPD 5,000 EUR for using an illegal cookie consent mechanism on its website. Users were required to accept cookies to access free content or subscribe in order to avoid them. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 28 Oct 2015 | MUTUA MADRILEÑA AUTOMOVILISTA SOCIEDAD DE SEGUROS A PRIMA FIJAMutua Madrileña was fined 40,001 EUR by the AEPD for sending unsolicited commercial emails despite the recipient’s objection. The case concerns a breach of data protection and direct marketing rules. | ES | AEPD | ePrivacy | €40,001 | ↗ |
| 13 Dec 2022 | CONSULTORÍA PERITACIONES ALMERIENSES, S.L.The company did not respond to a data access request and failed to publish information on data processing or the data controller on its website. AEPD treated this as a breach of the information obligations under Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2016 | AUTO OJA S.A.AUTO OJA S.A. was fined by the AEPD 10,000 EUR for sending unsolicited promotional emails to a customer. The company continued contacting the recipient despite requests to be removed from the mailing list, which breached the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 19 May 2025 | GATIGOS, S.L.GATIGOS, S.L. was fined EUR 6,000 by the AEPD for failing to provide access to personal data and the information requested by the data protection authority. The authority found a breach of Article 58(1) GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 14 Aug 2024 | GRUPO INMOBILIARIO GONTEGA, S.L.GRUPO INMOBILIARIO GONTEGA, S.L. was fined by the AEPD EUR 450 for failing to properly handle a data access request. The authority found a breach of Article 15 GDPR and non-compliance with its resolution. | ES | AEPD | GDPR | €450 | ↗ |
| 20 Aug 2021 | A.A.A. (FRUTERIA)The entity was fined for operating a video surveillance system without the required signage informing individuals of its presence. The authority treated this as a breach of Article 13 GDPR on transparency and information duties. | ES | AEPD | GDPR | €1,000 | ↗ |