Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Oct 2013HERBORISTERÍA TRÉBOL-HIDROLINFA C.B.HERBORISTERÍA TRÉBOL-HIDROLINFA C.B. was fined EUR 600 by the AEPD for sending a commercial email without providing a valid electronic address for recipients to object to the processing of their data for advertising purposes. The authority found a breach of Article 21.2 of the LSSI.ESAEPDePrivacy€600
01 Jan 2020VOLTIMUM, S.A.VOLTIMUM, S.A. was fined EUR 2,000 by the AEPD for sending commercial emails after the recipient had opted out. The authority found this to be a breach of Article 21 of the LSSI on marketing communications.ESAEPDePrivacy€2,000
01 Jul 2022RCI BANQUE, S.A. SUCURSAL EN ESPAÑARCI Banque, S.A. Sucursal en España was fined by the AEPD for failing to properly handle a request for erasure under Article 17 GDPR. As a result, the data subject received unwanted communications about a debt they did not owe.ESAEPDGDPR€20,000
27 Sept 2021B.B.B.The entity was fined by the AEPD for operating a video surveillance system without proper informational signage. The system also captured footage beyond the intended purpose, including public transit areas.ESAEPDGDPR€1,500
01 Jan 2018ADGOALS MEDIA S.L.ADGOALS MEDIA S.L. was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited SMS advertisements without prior recipient consent. The authority also found that no opt-out mechanism was provided, which constitutes a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,500
25 Feb 2021Mistore Canarias, S.L.U.Mistore Canarias, S.L.U. was fined by the AEPD 5,000 EUR for processing personal data without consent. The conduct resulted in unauthorized charges to a customer's bank account.ESAEPDGDPR€5,000
04 Feb 2020VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 60,000 EUR for a data protection violation. The case involved unauthorized data processing and signature forgery by an employee, which led to a fraudulent service transfer.ESAEPDGDPR€60,000
03 Dec 2019MYMOVILES EUROPA 2000, S.L.MYMOVILES EUROPA 2000, S.L. was fined by the AEPD €1,500 for failing to provide the required privacy information on its website. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€1,500
31 Mar 2017B.B.B.B.B.B. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The emails continued despite repeated requests from the recipient to stop, which breached the LSSI.ESAEPDePrivacy€30,001
01 Jan 2024EXCEL HOTELS & RESORTS, S.A.EXCEL HOTELS & RESORTS, S.A. was fined by the AEPD 40,000 EUR for leaving property owners’ personal data unattended, including ID and passport numbers. The authority found that this created unauthorized access to sensitive personal information and breached data protection principles.ESAEPDGDPR€40,000
04 Feb 2025LÍNEAS FINANCIERAS INTERNACIONALES, S.L.The entity was fined EUR 500 by the AEPD for sending unsolicited commercial communications by email without prior consent. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€500
05 Nov 2019CERRAJERO ONLINE S.L.CERRAJERO ONLINE S.L. was fined EUR 1,500 by the AEPD for collecting personal data without providing the required information to data subjects. The authority treated this as a breach of data protection rules.ESAEPDGDPR€1,500
07 Sept 2023IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORAIberia was fined by the AEPD EUR 50,000 for a breach related to personal data handling during a flight from Quito to Dublin. Passengers were asked to provide identity documents and marriage certificates to justify travel during COVID-19 restrictions.ESAEPDGDPR€50,000
24 Jan 2024CAJA RURAL DE ASTURIAS, S.C.C.CAJA RURAL DE ASTURIAS was fined by the AEPD EUR 250,000 for breaching the confidentiality and integrity principles of personal data. The incident allowed unauthorized access to personal data, indicating a failure to protect data appropriately.ESAEPDGDPR€250,000
27 Nov 2020CERTIME, S.A.CERTIME, S.A. was fined by the AEPD in the amount of 5,000 EUR for processing personal data for a purpose different from the one originally specified. The authority found this to be a breach of Article 5(1)(b) GDPR.ESAEPDGDPR€5,000
22 Feb 2022VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 70,000 EUR for issuing a duplicate SIM card to a third party without proper authorization. This enabled unauthorized access to the complainant’s bank data and resulted in fraudulent transactions.ESAEPDGDPR€70,000
04 Oct 2021SAKBO SPAIN, S.L.SAKBO SPAIN, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€5,000
10 Mar 2023DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the customer's consent. The action enabled unauthorized bank transactions, indicating a serious breach of data protection and authentication security.ESAEPDGDPR€200,000
11 May 20103Emultimedia comunicación en Internet S.L.3Emultimedia comunicación en Internet S.L. was fined €600 by the AEPD for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€600
29 Jun 2023FUNDACIÓN VEDRUNA EDUCACIÓN COLEGIOA teacher publicly disclosed the content of an email concerning a student's issues, breaching the duty of confidentiality. The AEPD found a violation of data protection rules and imposed a 15,000 EUR fine.ESAEPDGDPR€15,000