Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2023B.B.B.The entity used a video from a training session containing the complainant’s personal statements without consent. The material was used for marketing purposes to attract new clients, which constituted a breach of data protection rules.ESAEPDGDPR€10,000
19 May 2025REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESAREAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA was fined by the AEPD 2,000 EUR for publishing personal data of individuals involved in an electoral process on its website. This conduct breached data protection principles.ESAEPDGDPR€2,000
14 Feb 2022COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company sent a customer's electricity supply contract containing personal data to an incorrect address. This breached data protection principles and led to a fine by the AEPD.ESAEPDGDPR€100,000
01 Jan 2023VACACIONES EDREAMS, S.L.VACACIONES EDREAMS, S.L. was fined by the AEPD in the amount of 10,000 EUR for failing to provide access to personal data upon a customer request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€10,000
29 Jul 2022LA CASA DEL BAMBÚLA CASA DEL BAMBÚ was fined €200 by the AEPD for continuing to send marketing emails to a customer after an unsubscribe request. The authority found this to be a breach of Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€200
09 Apr 2024ADNAYA GREEN SOLUTIONS, S.L.ADNAYA GREEN SOLUTIONS, S.L. was fined by the AEPD EUR 10,000 for unlawfully sharing personal data with a third party without consent. The authority found this conduct breached Article 6(1) of the GDPR.ESAEPDGDPR€10,000
15 Nov 2019HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined by the AEPD 60,000 EUR for sending a patient's medical report to an insurance company without proper consent. The case concerns a breach of data protection rules and the special protection applicable to health data.ESAEPDGDPR€60,000
20 Jun 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD €65,000 for improper handling of personal data. The company failed to notify the rectification or deletion of personal data, which led to unwarranted debt collection calls.ESAEPDGDPR€65,000
23 Jan 2024CAJA RURAL DE ZAMORA COOPERATIVA DE CRÉDITOCAJA RURAL DE ZAMORA was fined by the AEPD EUR 15,000 for a personal data breach. The incident affected the confidentiality and integrity of personal data, breaching GDPR Article 5(1)(f).ESAEPDGDPR€15,000
29 Jul 2013ENDESA, S.A.ENDESA, S.A. was fined EUR 600 by the AEPD for sending commercial emails to a former customer despite requests to delete personal data. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
22 Apr 2022DISPLAY CONNECTORS, S.LDISPLAY CONNECTORS, S.L was fined EUR 300,000 by the AEPD for automatically publishing videos containing personal data without first ensuring the processing was lawful. The authority found this conduct breached data protection rules.ESAEPDGDPR€300,000
27 Sept 2022ALBERO FORTE COMPOSITE, S.L.The company used employees’ facial images for clocking in and out without proper notice about biometric data processing. AEPD found this to be a breach of data protection rules and imposed a 20,000 EUR fine.ESAEPDGDPR€20,000
01 Mar 2023ILUROBOX, S.L.ILUROBOX, S.L. was fined by the AEPD EUR 3,000 for including individuals in a WhatsApp group without their consent. The authority found that this breached Article 6(1) GDPR because there was no lawful basis for the processing.ESAEPDGDPR€3,000
16 Nov 2010INGORA SERAI S.L.INGORA SERAI S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits unsolicited marketing communications.ESAEPDePrivacy€600
01 Jan 2013GOOGLE INCGoogle Inc. was fined by the AEPD EUR 130,000 for failing to provide adequate information on privacy and cookie policies on a website. The authority found a breach of the LSSI information requirements toward users.ESAEPDePrivacy€130,000
28 Jun 2022ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. failed to provide the required information to the Spanish Data Protection Agency, which constitutes a breach of Article 58.1 of the GDPR. The AEPD imposed a fine of 3,000 EUR.ESAEPDGDPR€3,000
15 Apr 2025COLPER BUSINESS 2020 S.L.COLPER BUSINESS 2020 S.L. was fined by the AEPD EUR 20,000 for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR.ESAEPDGDPR€20,000
11 Jan 2023AXEL SPRINGER ESPAÑA S.AAXEL SPRINGER ESPAÑA S.A was fined 5,000 EUR by the AEPD for non-compliance with data protection rules in its cookie policy. The website required users to disable providers individually and did not offer an option to disable all cookies at once.ESAEPDePrivacy€5,000
20 Jan 2015SYNERTEC GROUP S.L.SYNERTEC GROUP S.L. was fined by the AEPD in the amount of €52,000 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€52,000
12 May 2021E4LEGAL ANALYTICS, S.L. (EMÉRITA LEGAL)E4LEGAL ANALYTICS, S.L. was fined by the AEPD EUR 3,100,000 for processing personal data from judicial sentences without proper authorization. The case concerned the reuse of data in a way that may have breached data protection rules and restrictions on further use.ESAEPDGDPR€3,100,000