BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2023 | B.B.B.The entity used a video from a training session containing the complainant’s personal statements without consent. The material was used for marketing purposes to attract new clients, which constituted a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 19 May 2025 | REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESAREAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA was fined by the AEPD 2,000 EUR for publishing personal data of individuals involved in an electoral process on its website. This conduct breached data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 14 Feb 2022 | COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company sent a customer's electricity supply contract containing personal data to an incorrect address. This breached data protection principles and led to a fine by the AEPD. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Jan 2023 | VACACIONES EDREAMS, S.L.VACACIONES EDREAMS, S.L. was fined by the AEPD in the amount of 10,000 EUR for failing to provide access to personal data upon a customer request. The authority found a breach of Article 15 of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 29 Jul 2022 | LA CASA DEL BAMBÚLA CASA DEL BAMBÚ was fined €200 by the AEPD for continuing to send marketing emails to a customer after an unsubscribe request. The authority found this to be a breach of Article 21 of the LSSI on unsolicited commercial communications. | ES | AEPD | ePrivacy | €200 | ↗ |
| 09 Apr 2024 | ADNAYA GREEN SOLUTIONS, S.L.ADNAYA GREEN SOLUTIONS, S.L. was fined by the AEPD EUR 10,000 for unlawfully sharing personal data with a third party without consent. The authority found this conduct breached Article 6(1) of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 15 Nov 2019 | HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined by the AEPD 60,000 EUR for sending a patient's medical report to an insurance company without proper consent. The case concerns a breach of data protection rules and the special protection applicable to health data. | ES | AEPD | GDPR | €60,000 | ↗ |
| 20 Jun 2019 | XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD €65,000 for improper handling of personal data. The company failed to notify the rectification or deletion of personal data, which led to unwarranted debt collection calls. | ES | AEPD | GDPR | €65,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE ZAMORA COOPERATIVA DE CRÉDITOCAJA RURAL DE ZAMORA was fined by the AEPD EUR 15,000 for a personal data breach. The incident affected the confidentiality and integrity of personal data, breaching GDPR Article 5(1)(f). | ES | AEPD | GDPR | €15,000 | ↗ |
| 29 Jul 2013 | ENDESA, S.A.ENDESA, S.A. was fined EUR 600 by the AEPD for sending commercial emails to a former customer despite requests to delete personal data. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 22 Apr 2022 | DISPLAY CONNECTORS, S.LDISPLAY CONNECTORS, S.L was fined EUR 300,000 by the AEPD for automatically publishing videos containing personal data without first ensuring the processing was lawful. The authority found this conduct breached data protection rules. | ES | AEPD | GDPR | €300,000 | ↗ |
| 27 Sept 2022 | ALBERO FORTE COMPOSITE, S.L.The company used employees’ facial images for clocking in and out without proper notice about biometric data processing. AEPD found this to be a breach of data protection rules and imposed a 20,000 EUR fine. | ES | AEPD | GDPR | €20,000 | ↗ |
| 01 Mar 2023 | ILUROBOX, S.L.ILUROBOX, S.L. was fined by the AEPD EUR 3,000 for including individuals in a WhatsApp group without their consent. The authority found that this breached Article 6(1) GDPR because there was no lawful basis for the processing. | ES | AEPD | GDPR | €3,000 | ↗ |
| 16 Nov 2010 | INGORA SERAI S.L.INGORA SERAI S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits unsolicited marketing communications. | ES | AEPD | ePrivacy | €600 | ↗ |
| 01 Jan 2013 | GOOGLE INCGoogle Inc. was fined by the AEPD EUR 130,000 for failing to provide adequate information on privacy and cookie policies on a website. The authority found a breach of the LSSI information requirements toward users. | ES | AEPD | ePrivacy | €130,000 | ↗ |
| 28 Jun 2022 | ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. failed to provide the required information to the Spanish Data Protection Agency, which constitutes a breach of Article 58.1 of the GDPR. The AEPD imposed a fine of 3,000 EUR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Apr 2025 | COLPER BUSINESS 2020 S.L.COLPER BUSINESS 2020 S.L. was fined by the AEPD EUR 20,000 for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 11 Jan 2023 | AXEL SPRINGER ESPAÑA S.AAXEL SPRINGER ESPAÑA S.A was fined 5,000 EUR by the AEPD for non-compliance with data protection rules in its cookie policy. The website required users to disable providers individually and did not offer an option to disable all cookies at once. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 20 Jan 2015 | SYNERTEC GROUP S.L.SYNERTEC GROUP S.L. was fined by the AEPD in the amount of €52,000 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent. | ES | AEPD | ePrivacy | €52,000 | ↗ |
| 12 May 2021 | E4LEGAL ANALYTICS, S.L. (EMÉRITA LEGAL)E4LEGAL ANALYTICS, S.L. was fined by the AEPD EUR 3,100,000 for processing personal data from judicial sentences without proper authorization. The case concerned the reuse of data in a way that may have breached data protection rules and restrictions on further use. | ES | AEPD | GDPR | €3,100,000 | ↗ |