BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2015 | WERBUNG INTERNET S.L.WERBUNG INTERNET S.L. was fined by the AEPD €1,000 for sending unsolicited commercial emails without prior consent. The conduct breached Article 21.1 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 17 Nov 2020 | PEDROSO Y GÓMEZ ASESORÍA DE EMPRESAS, S.L.The company was fined by the AEPD in the amount of 6,000 EUR for sending emails without the recipients' consent. The authority also noted the absence of contact information for exercising data protection rights. | ES | AEPD | GDPR | €6,000 | ↗ |
| 22 Jun 2020 | PARTIT DELS SOCIALISTES DE CATALUNYA (PSC-PSOE)PSC-PSOE was fined by the AEPD 5,000 EUR for using personal data obtained in a doctor-patient relationship to send requests for political support. The authority found this breached purpose limitation rules for data processing. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2015 | ZOWROOM, S.L.ZOWROOM, S.L. was fined by the AEPD EUR 500 for sending unsolicited commercial emails. The authority also found that unsubscribe requests were not honored, which constitutes a breach of the LSSI. | ES | AEPD | ePrivacy | €500 | ↗ |
| 29 Jan 2020 | CASA GRACIO OPERATION, SLUCASA GRACIO OPERATION, SLU was fined by the AEPD 10,000 EUR for installing a video surveillance system that could capture public areas and access points. The authority found that this processing breached data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Jan 2025 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined 100,000 EUR by the AEPD for inaccuracies in data retention relating to SIM card purchasers. The authority found a breach of the GDPR data accuracy obligation. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Jan 2015 | SOTO GLOBAL SERVICE, S.L.SOTO GLOBAL SERVICE, S.L. was fined by the AEPD €3,200 for sending nine unsolicited commercial emails without prior consent. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,200 | ↗ |
| 14 Jun 2021 | B.B.B.The entity was fined by the AEPD EUR 3,000 for publicly disseminating surveillance footage without justification. The conduct breached data protection principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Sept 2022 | EDITORIAL RIBADEO S.L.EDITORIAL RIBADEO S.L. was fined EUR 1,000 by the AEPD for failing to meet the information obligations under Articles 12 and 13 of the GDPR. The authority also noted non-compliance with previous data protection decisions. | ES | AEPD | GDPR | €1,000 | ↗ |
| 04 Mar 2021 | ALAVA NORTE, S.L.ALAVA NORTE, S.L. was fined by the AEPD in the amount of 4,000 EUR for installing surveillance cameras without sufficient justification. The cameras captured both public and private spaces, which breached data protection principles. | ES | AEPD | GDPR | €4,000 | ↗ |
| 01 Jan 2019 | GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the Spanish data protection authority, AEPD, in the amount of €25,000. The authority found a breach for failing to appoint a Data Protection Officer as required by Article 37 of the GDPR. | ES | AEPD | GDPR | €25,000 | ↗ |
| 26 Jan 2024 | Allium UPI OÜEstonia’s Data Protection Inspectorate fined Allium UPI OÜ, operator of the Apotheka loyalty program, 3 million euros. The authority found that the company failed to protect customer data and used inadequate security measures, exposing the data of more than 750,000 people. | EE | Andmekaitse Inspektsioon | GDPR | €3,000,000 | ↗ |
| 27 Nov 2024 | Lyngby-Taarbæk KommuneThe Danish DPA reported Lyngby-Taarbæk Municipality to the police for failing to implement adequate security measures. This led to unauthorized access to personal data of about 30,000 citizens, and a fine of 350,000–400,000 DKK was recommended. | DK | Datatilsynet | GDPR | €53,632 | ↗ |
| 17 Aug 2021 | UdlændingestyrelsenThe Danish DPA, Datatilsynet, recommended a fine of DKK 150,000 against Udlændingestyrelsen. The case concerned inadequate security measures in personal data processing, which could have affected the rights of residents at deportation centers. | DK | Datatilsynet | GDPR | €20,171 | ↗ |
| 08 Sept 2021 | Region MidtjyllandRegion Midtjylland was fined for failing to implement adequate access restrictions to an archive containing sensitive patient records. This allowed unauthorized access by patients and staff at a lifestyle center. | DK | Datatilsynet | GDPR | €40,344 | ↗ |
| 14 Jul 2022 | SIRIUS advokaterSIRIUS advokater was recommended a fine of DKK 500,000 by Datatilsynet for failing to implement basic security measures. The deficiencies led to a data breach in which sensitive personal data was compromised during a hacking incident. | DK | Datatilsynet | GDPR | €67,180 | ↗ |
| 26 Apr 2024 | Nationalt Genom CenterThe Danish DPA fined Nationalt Genom Center 50,000 DKK for processing personal data without consulting the supervisory authority. Its own DPIA identified a high risk, which should have triggered prior consultation before processing began. | DK | Datatilsynet | GDPR | €6,705 | ↗ |
| 07 Jul 2021 | Nordbornholms Byggeforretning ApSNordbornholms Byggeforretning ApS was fined 100,000 DKK by Datatilsynet. The company unlawfully disclosed information about a former employee's criminal activities to customers without a legal basis. | DK | Datatilsynet | GDPR | €13,448 | ↗ |
| 22 Jan 2024 | Hvidovre KommuneHvidovre Kommune was fined by Datatilsynet for failing to maintain an appropriate level of security. The issue allowed unauthorized access to protected addresses of children through the municipal dental service's self-service solution, which incorrectly extended access to both custodial parents. | DK | Datatilsynet | GDPR | €26,816 | ↗ |
| 16 Jul 2021 | Region SyddanmarkRegion Syddanmark was fined 500,000 DKK by Datatilsynet for failing to implement appropriate security measures. The vulnerability allowed unauthorized access to sensitive health data of children and was identified and reported by a citizen. | DK | Datatilsynet | GDPR | €67,220 | ↗ |