Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2019QUESERIA ARTESANAL AMECO S.L.QUESERIA ARTESANAL AMECO S.L. was fined by the AEPD 5,000 EUR for processing personal data without consent. Customers were unaware of how their data had been obtained, indicating a breach of transparency and lawful processing requirements.ESAEPDGDPR€5,000
01 Jan 2021ORANGE ESPAÑA VIRTUAL, S.L.SIMYO was fined for failing to adequately protect personal data, which enabled unauthorized SIM card duplication. The incident led to fraudulent bank transactions and indicates significant security shortcomings.ESAEPDGDPR€70,000
07 Feb 2025ESTUDIO ALCAZAR DEL GENIL 2022, S.L.ESTUDIO ALCAZAR DEL GENIL 2022, S.L. was fined EUR 10,000 by the AEPD for collecting and storing personal data taken from mailboxes without consent or notice to the data subjects. The authority found breaches of the lawful basis and transparency requirements under GDPR Articles 6(1) and 14.ESAEPDGDPR€10,000
15 Jun 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD for continuing to pursue a debt that had already been settled. The authority treated this as a breach of data protection rules.ESAEPDGDPR€50,000
02 Oct 2023COMUNIDAD DE PROPIETARIOS A.A.A.The president of a homeowners' association shared a bank receipt containing personal data in a WhatsApp group. AEPD found a breach of confidentiality principles under GDPR and imposed a EUR 2,000 fine.ESAEPDGDPR€2,000
01 Jan 2014BONANZA DIGITAL SERVICES S.L.BONANZA DIGITAL SERVICES S.L. was fined by the AEPD 8,000 EUR for sending unsolicited SMS messages promoting “Tarot del Alba”. The company did not provide an opt-out mechanism, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€8,000
01 Jan 2024GASEXPRESS PATRAIX, S.L.GASEXPRESS PATRAIX, S.L. was fined by the AEPD 25,000 EUR for allowing unauthorized access to previous users' data in its automated gas station system. The exposed information included DNI numbers and partial credit card numbers.ESAEPDGDPR€25,000
01 Jan 2019AMADOR RECREATIVOS, S.L.AMADOR RECREATIVOS, S.L. was fined by the AEPD 6,000 EUR for installing a video surveillance system aimed at public space without justified cause. The case concerned an unjustified scope of monitoring and a breach of data protection rules.ESAEPDGDPR€6,000
02 Feb 2023DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card without the complainant's consent. The incident led to attempts to gain unauthorized access to the complainant's bank accounts.ESAEPDGDPR€70,000
01 Jan 2015ALDA GLOBAL SERVICES, S.L.ALDA GLOBAL SERVICES, S.L. was fined EUR 600 by the AEPD. The case concerned sending unsolicited commercial communications by SMS without consent, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
15 Oct 2024TERRA, BRASA Y MAR, S.L.TERRA, BRASA Y MAR, S.L. was fined 500 EUR by the AEPD for adding the complainant's phone number to a WhatsApp group without consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€500
12 May 2023CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union sent an email containing personal data of election officials and representatives without their consent. AEPD found this to be a breach of data protection rules and imposed a 4,000 EUR fine.ESAEPDGDPR€4,000
01 Jan 2024AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD 2,000 EUR for improperly accessing personal data linked to a phone number without the owner's consent. The authority found a breach of Article 7 of the GDPR.ESAEPDGDPR€2,000
11 Sept 2025THE OBJECTIVE MEDIA, S.L.THE OBJECTIVE MEDIA, S.L. published an individual's personal data on its website without consent. The AEPD found this to be a breach of data protection principles and imposed a 20,000 EUR fine.ESAEPDGDPR€20,000
01 Jan 2015BANCO SANTANDER, S.A.Banco Santander was fined EUR 1,500 by the AEPD for sending unsolicited commercial emails to a recipient who had previously opted out. The authority found this to be a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,500
01 Jan 2024MAD COOL FESTIVAL, S.L.MAD COOL FESTIVAL, S.L. was fined 3,500 EUR by the AEPD for a data breach on its website. The incident exposed users’ personal data, indicating non-compliance with GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€3,500
04 Feb 2022CORON ISLAND SLUCORON ISLAND SLU was fined by the AEPD 2,000 EUR for requiring a customer’s phone number when issuing an invoice. The authority found that the data was not necessary for invoicing, which breached the data minimization principle.ESAEPDGDPR€2,000
03 Jul 2025BANCO INVERSIS, S.A.Banco Inversis, S.A. was fined by the AEPD in the amount of 10,000 EUR for a personal data breach. The case involved unauthorized access to personal data, which breached Article 5(1)(f) of the GDPR.ESAEPDGDPR€10,000
22 Mar 2018ARGOINFOR S.L.ARGOINFOR S.L. was fined by the AEPD in the amount of 1,000 EUR. The case concerned the sending of unsolicited commercial emails, which breaches Article 21 of the LSSI.ESAEPDePrivacy€1,000
08 Aug 2024OAC LOGÍSTICA, S.L.OAC LOGÍSTICA, S.L. was fined by the AEPD in the amount of EUR 600 for failing to provide access. The breach concerned Article 58(1) of the GDPR.ESAEPDGDPR€600