Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2018SHANA RETAIL S.L.SHANA RETAIL S.L. was fined by the AEPD for improperly disposing of documents containing personal data. The breach concerned data protection rules and the need to prevent unauthorized disclosure of information.ESAEPDGDPR€15,000
23 Apr 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for changing a customer's tariff without consent. The case involved identity impersonation and improper processing of personal data under the GDPR.ESAEPDGDPR€50,000
07 Oct 2014CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial communications by email. The conduct breached Article 21 of the LSSI, which restricts unwanted marketing messages.ESAEPDePrivacy€5,000
27 Feb 2023VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for breaching Article 6(1) GDPR after a SIM card was duplicated without consent. The incident enabled unauthorized access to a customer's bank accounts, indicating serious failures in verification and data protection controls.ESAEPDGDPR€200,000
01 Jan 2023UNIQUE HOTEL APARTMENT. S.LThe hotel improperly managed guest registration records, breaching data protection principles. It failed to maintain numerical order and did not communicate the records to the competent security forces.ESAEPDGDPR€2,000
17 Oct 2023MOBILITY AUTOCENTRO, S.L.MOBILITY AUTOCENTRO, S.L. was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial SMS messages. The authority found that recipients were not given an opt-out option, which breached the Spanish LSSI.ESAEPDePrivacy€2,000
24 Oct 2013SANITAS S.A.SANITAS S.A. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited commercial emails. The authority found that the required information clause was missing, which constitutes a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200
04 Nov 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD after a contract was entered into using another person's identity. The case concerns a breach of data protection rules and insufficient identity verification.ESAEPDGDPR€60,000
01 Jan 2016HAPPY SOCIAL MEDIA, LTDHAPPY SOCIAL MEDIA, LTD was fined by the AEPD EUR 3,400 for sending unsolicited marketing emails. The authority found that the messages did not include a simple opt-out mechanism, which breached the LSSI.ESAEPDePrivacy€3,400
15 Jul 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for requesting a disproportionate amount of personal data, including a copy of the DNI, to process a request for information about account movements. The authority found this to be a breach of the data minimization principle.ESAEPDGDPR€70,000
30 Jul 2021Mederos Moviten, S.L.Mederos Moviten, S.L. was fined by the AEPD 15,000 EUR for processing personal data without consent. Several unauthorized contracts were created using the complainant’s personal information, indicating unlawful use of personal data.ESAEPDGDPR€15,000
09 Jul 2021ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 50,000 EUR by the AEPD for failing to implement adequate security measures. The deficiency led to unauthorized bank transfers from a customer's account after a SIM card incident.ESAEPDGDPR€50,000
26 Jan 2022B.B.B.The entity installed a video surveillance system covering public transit areas without a justified cause. This breached data protection principles.ESAEPDGDPR€500
10 Feb 2021CEYLLE SOLUTIONS & DEVELOPMENT S.L.CEYLLE SOLUTIONS & DEVELOPMENT S.L. was fined by the AEPD in the amount of 2,000 EUR for disclosing personal data in emails sent to commercial partners. The authority found a breach of data protection rules.ESAEPDGDPR€2,000
15 Dec 2022BENOTAC, S.L.BENOTAC, S.L. was fined by the AEPD EUR 2,500 for operating a video surveillance system without proper signage and for capturing public areas without authorization. The authority also noted the sharing of recordings without the consent of the data subjects.ESAEPDGDPR€2,500
04 Feb 2020TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined 75,000 EUR by the AEPD for processing personal data without consent. The case concerned unauthorized portability of a phone line.ESAEPDGDPR€75,000
29 Sept 2020GABINETE PARAPSICOLÓGICO MYSTIC S.L.The entity was fined for sending unsolicited advertising SMS messages without the recipient's consent. This conduct breached Article 21 of the LSSI and constituted unlawful marketing communication.ESAEPDePrivacy€2,500
27 Jul 2011ASCENDIA REINGENIERIA&CONSULTING S.L.U.ASCENDIA REINGENIERIA&CONSULTING S.L.U. was fined by the AEPD €600 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€600
21 Oct 2013VIAJES INCENTIVE GOLF, S.L.VIAJES INCENTIVE GOLF, S.L. was fined by the AEPD 1,200 EUR for sending unsolicited emails. The authority also found that recipients' email addresses were not hidden, in breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200
04 Jun 2013UN LUGAR DIFERENTE. S.L.UN LUGAR DIFERENTE. S.L. was fined by the AEPD for sending unauthorized commercial SMS messages to a customer. The messages were sent despite the customer's prior request to opt out.ESAEPDePrivacy€600