Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2018ZARA LIBRO S.L. (DIFUSIÓN DEL LIBRO)ZARA LIBRO S.L. was fined by the AEPD in the amount of 1,000 EUR for sending a commercial email without a prior commercial relationship. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
05 Feb 2021NEXTSTEPAGENCY, S.L.NEXTSTEPAGENCY, S.L. was fined by the AEPD in the amount of 1,000 EUR for failing to provide reliable ownership information and details about data transfers to China on its website. The authority found a breach of the information obligations under Article 13 GDPR.ESAEPDGDPR€1,000
01 Jan 2019TODO POR EL 431, S.L.TODO POR EL 431, S.L. was fined by the AEPD €4,000 for using surveillance cameras oriented toward public spaces without justified cause. The authority found this to be a breach of data protection rules.ESAEPDGDPR€4,000
06 Jun 2022URQUÍA & BAS, CORREDURÍA DE SEGUROS S.L.URQUÍA & BAS, CORREDURÍA DE SEGUROS S.L. was fined by the AEPD 2,000 EUR for failing to notify a personal data breach in time. The case concerns the Article 33 GDPR obligation to report breaches to the supervisory authority.ESAEPDGDPR€2,000
24 Mar 2020VOX ESPAÑAVOX ESPAÑA was fined by the AEPD 1,500 EUR for retaining personal data after a deletion request. The case also involved sending an email to a former member despite consent being withdrawn, which breached GDPR requirements.ESAEPDGDPR€1,500
18 Feb 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 70,000 EUR by the AEPD for incorrectly linking a customer's phone lines to another person's details. The case concerned a breach of data protection rules and indicated deficiencies in personal data processing.ESAEPDGDPR€70,000
01 Jan 2024UNIVERSITAS NEBRISSENSIS, S.A.UNIVERSITAS NEBRISSENSIS, S.A. was fined by the AEPD EUR 50,000 for requesting a full copy of a student's ID. The authority found that this breached GDPR data minimization principles and security requirements.ESAEPDGDPR€50,000
21 Feb 2022RECICLAJES ECOLÓGICOS MELJACAN, S.L.The company was fined by the AEPD for breaching data protection rules. The authority found that the website did not meet the required information and consent standards for data processing and cookie policies.ESAEPDePrivacy€7,000
26 Oct 2021AMAZON ROAD TRANSPORT SPAIN, S.LAmazon Road Transport Spain, S.L was fined 3,300,000 EUR by the AEPD for requiring job candidates to provide a criminal record certificate and consent for data transfers outside the EEA. The authority found that these practices breached GDPR and LOPDGDD rules on lawful processing and data transfer safeguards.ESAEPDGDPR€3,300,000
01 Jan 2022UNIQUEDESIGN & DECOR, S.L.UNIQUEDESIGN & DECOR, S.L. was fined by the AEPD 5,000 EUR for not having an accessible privacy policy on its website. The authority found a breach of Article 13 GDPR because users were not properly provided with the required information.ESAEPDGDPR€5,000
01 Jan 2013IBÉRICA SECTORIAL DE ANÁLISIS, S.L.U.IBÉRICA SECTORIAL DE ANÁLISIS, S.L.U. was fined by the AEPD 1,400 EUR for sending unsolicited commercial emails. The authority found that the messages lacked a valid opt-out address, in breach of Article 21 of the LSSI.ESAEPDePrivacy€1,400
31 May 2017LEAD CONVERSIÓN, S.L.LEAD CONVERSIÓN, S.L. was fined by the AEPD €2,000 for sending unsolicited commercial emails. The conduct breached rules on electronic communications and recipient consent.ESAEPDePrivacy€2,000
14 Feb 2024ALL IN DIGITAL MARKETING SLALL IN DIGITAL MARKETING SL was fined by the AEPD €5,000 for continuing to send commercial emails despite repeated requests to unsubscribe. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
22 Jun 2020ARANOW PACKAGING MACHINERY, S.L.ARANOW PACKAGING MACHINERY, S.L. was fined by the AEPD for non-compliance of its website with data protection rules. The breach concerned the absence of compliant Privacy and Cookie Policies.ESAEPDePrivacy€3,000
01 Jan 2013GLOBAL BUSINESS DEVELOPMENT CONSULTING, S.L.GLOBAL BUSINESS DEVELOPMENT CONSULTING, S.L. was fined by the AEPD EUR 1,300 for continuing to send commercial communications after unsubscribe requests. The conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,300
02 Oct 2020GRUPO OCIO DESARROLLO Y SERVICIOS, S.L.The entity was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited commercial communications via WhatsApp. The authority found a breach of the complainant's rights to data protection and to object to data processing.ESAEPDePrivacy€1,500
26 Mar 2021CAIXABANK S.A.CAIXABANK S.A. was fined EUR 60,000 by the AEPD for processing personal data without consent. The case concerned a current account contract signed on behalf of the complainant without proper authorization.ESAEPDGDPR€60,000
07 Jun 2024Club Balonmano GijónClub Balonmano Gijón was fined EUR 1,000 by the AEPD for unlawfully processing personal data by publishing images of minors on its website without a legal basis. The case indicates a breach of the lawfulness principle and the protection of children's image rights.ESAEPDGDPR€1,000
02 Feb 2022TARIFER SERVICIOS, S.L.TARIFER SERVICIOS, S.L. was fined by the AEPD 2,000 EUR for using non-essential cookies without user consent. The authority also found that the website did not provide the required cookie information.ESAEPDePrivacy€2,000
01 Nov 2015OLYMPIA METROPOLITANA S.A.OLYMPIA METROPOLITANA S.A. was fined 1,100 EUR by the AEPD for sending commercial emails to a recipient who had already requested to unsubscribe. The authority found this conduct breached the LSSI rules on marketing communications.ESAEPDePrivacy€1,100