BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Nov 2022 | B.B.B.The entity was fined by the AEPD EUR 300 for installing surveillance cameras that recorded images and sound in public and communal areas without the required authorization. This constituted a breach of data protection rules. | ES | AEPD | GDPR | €300 | ↗ |
| 01 Jan 2023 | QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined 20,000 EUR by the AEPD for unlawfully obtaining personal data from a website. The data was then used for promotional purposes without the consent of the data subjects. | ES | AEPD | GDPR | €20,000 | ↗ |
| 01 Jan 2014 | DIVER KARTING, S.L.DIVER KARTING, S.L. was fined by the AEPD in the amount of EUR 2,300 for continuing to send commercial communications after the individual exercised the right to object and requested to unsubscribe. The case concerns failure to respect a valid opt-out from direct marketing. | ES | AEPD | ePrivacy | €2,300 | ↗ |
| 04 Jul 2023 | BALLESPE, S.LBALLESPE, S.L was fined by the AEPD in the amount of 500 EUR for installing surveillance cameras that captured public areas without proper signage. The case concerns a breach of data protection rules and the duty to inform individuals being recorded. | ES | AEPD | GDPR | €500 | ↗ |
| 18 Jan 2022 | MAJESTIC SOLUTIONS S.L.MAJESTIC SOLUTIONS S.L. was fined by the AEPD 10,000 EUR for failing to provide all required information to affected individuals after a personal data security breach. The authority found a breach of Article 34(2) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 26 Oct 2020 | ESTILO 1221, S.C.ESTILO 1221, S.C. was fined by the AEPD EUR 1,500 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21.1 of the LSSI, which prohibits this type of marketing communication without prior consent. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 24 May 2023 | PARTIDO LOCAL DE VILLANUEVA DEL PARDILLOPartido Local de Villanueva del Pardillo was fined EUR 500 by the AEPD for publishing an image on Facebook without the data subject's consent. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 10 Jan 2026 | MULTISPORTS GALICIA, S.L.MULTISPORTS GALICIA, S.L. was fined by the AEPD EUR 6,000 for failing to implement appropriate technical and organizational measures proportionate to the risk. The weakness allowed easy access to personal data of race participants through its website. | ES | AEPD | GDPR | €6,000 | ↗ |
| 21 May 2021 | COOPERA RC SERVICES, S.L.COOPERA RC SERVICES, S.L. was fined by the AEPD 2,000 EUR for failing to provide the contact details needed to exercise data protection rights. The authority found a breach of the information obligations under Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 29 May 2023 | VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España 70,000 EUR for processing call and SMS diversion without the customer's consent. The conduct was linked to a bank fraud incident, indicating a serious failure in data protection and service authorization controls. | ES | AEPD | GDPR | €70,000 | ↗ |
| 23 May 2024 | 20 AÑOS DE MÚSICA A.I.E.The entity was fined for collecting copies of identity documents and personal data without proper data protection information. The authority found breaches of the data minimization and transparency principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Sept 2022 | B.B.B.The entity was fined for installing surveillance cameras that captured public areas without prior administrative authorization. This constituted a breach of data protection regulations. | ES | AEPD | GDPR | €300 | ↗ |
| 15 Nov 2024 | AXARQUIA VELEZ DENTAL, S.L.AXARQUIA VELEZ DENTAL, S.L. was fined by the AEPD 5,000 EUR for failing to properly signpost the video surveillance system inside its premises. The authority found a breach of GDPR transparency requirements. | ES | AEPD | GDPR | €5,000 | ↗ |
| 20 Apr 2021 | EB CREATIVE LABEB CREATIVE LAB was fined by the AEPD EUR 5,000 for failing to provide information or obtain consent for cookies on its website. The breach concerned Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 19 Jun 2019 | VF JEANSWEAR ESPAÑA S.L.VF Jeanswear España S.L. was fined by the AEPD 5,000 EUR for using cookies on its website without obtaining user consent. The case concerns a breach of data protection rules and consent requirements for cookies. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 25 Apr 2016 | PARABEBES SERVICIOS INFANTILES Y PREMAMÁ, S.L.The entity was fined by the AEPD for sending unsolicited commercial emails to a complainant. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,900 | ↗ |
| 05 Jan 2022 | CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined by the AEPD in the amount of EUR 5,000 for sending commercial SMS messages without the recipient’s consent. The conduct breached Article 21 of the LSSI, which governs unsolicited electronic marketing. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 23 Jun 2020 | COMUNIDAD DE PROPIETAROS R.R.R.The entity was fined for installing video surveillance cameras without the required informational signage. The case concerned a breach of data protection rules and the obligation to properly inform individuals subject to monitoring. | ES | AEPD | GDPR | €2,000 | ↗ |
| 18 Jun 2020 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD in the amount of EUR 30,000 for consulting personal data in credit files without an existing contractual relationship. The authority found that this conduct breached data processing principles. | ES | AEPD | GDPR | €30,000 | ↗ |
| 10 May 2024 | EUSKALTEL, S.A.EUSKALTEL, S.A. was fined 400,000 EUR by the AEPD for failing to comply with a resolution requiring access to geolocation data. The authority found a breach of Article 58.2 of the GDPR. | ES | AEPD | GDPR | €400,000 | ↗ |