BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Feb 2022 | JIMBO NETWORKS, S.L.JIMBO NETWORKS, S.L. was fined by the AEPD for unlawful processing of personal data obtained from emails and for cookie policy violations on its website. The authority found that users were not properly informed and that valid consent was not obtained where required. | ES | AEPD | GDPR | €15,000 | ↗ |
| 17 Mar 2023 | TELEFÓNICA MÓVILES ESPAÑA, S.A.The AEPD fined TELEFÓNICA MÓVILES ESPAÑA, S.A. 70,000 EUR for changing a customer's mobile tariff without consent. The authority found that the action breached Article 6(1) GDPR because there was no valid legal basis for the change. | ES | AEPD | GDPR | €70,000 | ↗ |
| 06 Oct 2014 | MANGO-ON LINE, S.A.MANGO-ON LINE, S.A. was fined by the AEPD €5,000 for continuing to send newsletters to a complainant despite multiple unsubscribe requests. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jan 2014 | DREAM RING, S.L.DREAM RING, S.L. was fined by the AEPD EUR 6,000 for sending unsolicited commercial SMS messages. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior recipient consent. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 17 Mar 2021 | BODY TONIC SHOP, S.L.BODY TONIC SHOP, S.L. was fined by the AEPD EUR 2,000 for processing personal data without proper consent. The authority found a breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Mar 2017 | PACSOLUTOR S.L.U.PACSOLUTOR S.L.U. was fined by the AEPD in the amount of 3,000 EUR for failing to provide adequate information about cookies on its website. The breach concerned Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 07 Oct 2020 | UST GLOBAL ESPAÑA, S.A.UST Global España, S.A. was fined by the AEPD EUR 5,000 for improperly sharing employees’ personal data in a group email. The disclosed data included names, email addresses, and DNI numbers, which breached data protection principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2012 | IDEAS CREATIVAS DE OPERACIONES, S.L.IDEAS CREATIVAS DE OPERACIONES, S.L. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The authority also found that the company failed to provide a functional opt-out mechanism, in breach of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 01 Jan 2012 | MICROLOANS, S.L.MICROLOANS, S.L. was fined EUR 600 by the AEPD. The authority found that the company sent unsolicited commercial emails without prior consent from recipients, in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 19 Sept 2017 | CEPSA COMERCIAL PETRÓLEO, S.A.U.CEPSA was fined by the AEPD 3,300 EUR for sending two unsolicited commercial emails without prior consent from the recipients. The authority found this breached Article 21 of the LSSI on commercial communications. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 22 Dec 2023 | HISPAPOST, S.A.HISPAPOST, S.A. was fined EUR 60,000 by the AEPD for failing to properly safeguard and handle personal data. The incident resulted in the abandonment of 1,404 letters containing personal information, indicating inadequate data protection procedures. | ES | AEPD | GDPR | €60,000 | ↗ |
| 03 Feb 2011 | HUNTER & GATTI, S.L.HUNTER & GATTI, S.L. was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails. The authority also found that the company failed to provide a proper opt-out mechanism, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 01 Jan 2015 | INSTITUTO SUPERIOR DE ESTUDIOS EMPRESARIALES CAMBRIDGE S.A.The entity was fined by the AEPD 1,500 EUR for sending commercial messages without providing recipients a way to oppose further communications. The authority treated this as a breach of the right to data cancellation and control over continued contact. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 05 May 2022 | SOCIEDAD ESPAÑOLA DE RADIODIFUSIÓN, S.L.The Spanish Data Protection Agency (AEPD) fined SOCIEDAD ESPAÑOLA DE RADIODIFUSIÓN, S.L. EUR 50,000 for publishing audio of a victim’s court testimony without adequate data protection safeguards. The authority found a breach of GDPR Article 5(1)(c) on data minimization. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2022 | HOSPITAL POVISA, S.A.HOSPITAL POVISA, S.A. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned the improper inclusion of private health test results in a public health system, which violated the complainant’s privacy. | ES | AEPD | GDPR | €30,000 | ↗ |
| 03 Mar 2021 | COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD EUR 2,000 for installing a surveillance camera system without the required authorization. The cameras recorded private areas, which breached privacy rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 20 Jan 2021 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 40,000 by the AEPD for failing to respond to a data access request. The case concerns non-compliance with GDPR obligations relating to data subject rights. | ES | AEPD | GDPR | €40,000 | ↗ |
| 15 Jul 2022 | URBANO DIVERTIA, S.L.URBANO DIVERTIA, S.L. was fined by the AEPD 2,000 EUR for sending clients documents that contained personal data of third parties. The company also failed to include a reference to its privacy policy in corporate emails, which breached data protection requirements. | ES | AEPD | GDPR | €2,000 | ↗ |
| 18 Nov 2010 | G.L. GISOFT ANÁLISIS Y DISEÑO S.L.G.L. GISOFT ANÁLISIS Y DISEÑO S.L. was fined by the AEPD in the amount of €600 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits such marketing communications without recipient consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 01 Jan 2022 | FEDERACIÓN DE SERVICIOS A LA CIUDADANÍA DE CCOOThe entity was fined by the AEPD €3,000 for breaching data protection principles. The case involved the improper disclosure of personal data related to a COVID-19 case among employees. | ES | AEPD | GDPR | €3,000 | ↗ |