BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Sept 2021 | B.B.B.The entity was fined for operating a video surveillance system aimed at public and private spaces without sufficient justification. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €2,500 | ↗ |
| 24 Feb 2011 | B.B.B.B.B.B. was fined EUR 600 by the AEPD for sending an unsolicited commercial email to the complainant without meeting the required legal conditions. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications. | ES | AEPD | ePrivacy | €600 | ↗ |
| 12 Jan 2023 | ORANGEORANGE was fined EUR 1,000,000 by the AEPD for breaching data protection principles. The authority found failures to implement privacy by design and privacy by default in connection with SIM swapping incidents. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 08 Apr 2022 | B.B.B.The entity was fined for installing security cameras that recorded audio and covered areas such as the restroom without proper notice to employees or customers. The authority found this breached GDPR rules on data processing and transparency of information. | ES | AEPD | GDPR | €3,000 | ↗ |
| 01 Jan 2018 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 20,000 EUR by the AEPD for sending unsolicited marketing emails. The authority found that recipients were not given an effective unsubscribe option, despite a request to be removed from the mailing list. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 01 Jan 2020 | BANCO DE SABADELL, S.A.Banco de Sabadell was fined for sending a commercial email to a customer who had previously opted out of such communications. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Mar 2017 | CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD €10,000 for sending commercial emails without a valid unsubscribe link. The case concerned non-compliance with electronic communications rules and recipients’ right to opt out easily. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 01 Jan 2021 | LA MAISON DU BAMBOULA MAISON DU BAMBOU was fined EUR 3,000 by the AEPD for sending commercial emails without the recipient's consent. The conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 20 Dec 2019 | GESTHOTEL ACTIVOS BALAGARES S.L.GESTHOTEL ACTIVOS BALAGARES S.L. was fined by the AEPD 15,000 EUR for disclosing special categories of personal data, including medical information. The authority found a breach of the integrity and confidentiality principle under GDPR Article 5(1)(f). | ES | AEPD | GDPR | €15,000 | ↗ |
| 24 Jan 2024 | CAIXA RURAL LA VALL SAN ISIDRO, S.C.C.CAIXA RURAL LA VALL SAN ISIDRO was fined by the AEPD 15,000 EUR for a personal data breach. The incident allowed unauthorized third-party access and affected the confidentiality and integrity of the data. | ES | AEPD | GDPR | €15,000 | ↗ |
| 01 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the original user's consent. The incident led to unauthorized access to personal and banking data. | ES | AEPD | GDPR | €200,000 | ↗ |
| 23 Jul 2022 | GESTIONES AUTO LOW COST S. LThe entity was fined for not having a privacy policy on its website. The breach concerned Article 13 of the GDPR, which requires specific information to be provided to data subjects. | ES | AEPD | GDPR | €1,000 | ↗ |
| 26 Sept 2018 | VILAN DATAMINING SLVILAN DATAMINING SL was fined by the AEPD €800 for sending unsolicited commercial emails. The messages did not provide a way to exercise the rights of access, rectification, cancellation, or objection. | ES | AEPD | ePrivacy | €800 | ↗ |
| 28 Jul 2016 | IMPACTING EMAIL MARKETING SOLUTIONS, S.L.IMPACTING EMAIL MARKETING SOLUTIONS, S.L. was fined by the AEPD 10,000 EUR for sending unsolicited commercial communications by SMS without recipient consent. The case concerns a breach of data protection and direct marketing rules. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 13 Jan 2015 | LEROY MERLIN ESPAÑA S.L.U.LEROY MERLIN ESPAÑA S.L.U. was fined by the AEPD EUR 3,900 for sending unsolicited commercial SMS messages without recipient consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,900 | ↗ |
| 26 Apr 2011 | VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined 600 EUR by the AEPD for sending unsolicited advertising SMS messages. The authority found that the messages were sent despite the recipient’s opt-out request, which breached Article 21.2 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 16 Mar 2023 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for failing to implement adequate security measures. A SIM card duplication enabled unauthorized access to a customer’s personal data and financial accounts. | ES | AEPD | GDPR | €200,000 | ↗ |
| 24 Jun 2021 | NEXTGEN FINANCIAL SERVICES S.L.NEXTGEN FINANCIAL SERVICES S.L. failed to update the address in a loan contract and did not correct inaccurate data in a credit file. The AEPD found this to be a breach of the right to data rectification and imposed a fine of 50,000 EUR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 27 Sept 2011 | EDICIONES FINDER, S.L.EDICIONES FINDER, S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails without recipient consent. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 27 Oct 2022 | COPY COFFEE, S.L.COPY COFFEE, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails despite the recipient's prior objection. The authority found a breach of Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |