BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Dec 2022 | SECURITAS DIREC ESPAÑA, S.A.SECURITAS DIREC ESPAÑA, S.A. was fined by the AEPD 50,000 EUR for failing to provide complete access to personal data logs linked to an alarm system. The case concerned an inadequate response to a data subject access request. | ES | AEPD | GDPR | €50,000 | ↗ |
| 02 Aug 2021 | FUENSANTA S.L.FUENSANTA S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to provide access to information under Article 58.1 of the GDPR. The case concerned non-compliance with information access obligations toward the supervisory authority. | ES | AEPD | GDPR | €3,000 | ↗ |
| 02 Mar 2023 | WILLOUGHBY COLLEGE, S.A.WILLOUGHBY COLLEGE, S.A. failed to provide requested information to the Spanish Data Protection Agency, which constituted a breach of Article 58.1 of the GDPR. A fine was imposed and reduced due to early payment and acknowledgment of responsibility. | ES | AEPD | GDPR | €1,500 | ↗ |
| 01 Jan 2024 | CAIXABANK, S.A.CAIXABANK was fined by the AEPD for sending a privacy policy update to a non-client. The authority found that the stated legitimate-interest basis for processing did not have proper consent support. | ES | AEPD | GDPR | €200,000 | ↗ |
| 23 May 2018 | BELEADER INTERNET MARKETING S.L.BELEADER INTERNET MARKETING S.L. was fined 5,000 EUR by the AEPD. The authority found that the company sent unsolicited emails and did not honor unsubscribe requests. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 16 Feb 2022 | FEDERACION CASTELLANO-LEONESA DE SALVAMENTO Y SOCORRISMOThe organization was fined EUR 2,000 by the AEPD for requiring participants to consent to data processing and image rights transfers without any option to refuse. The authority found this incompatible with Article 6(1) GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 10 Mar 2021 | B.B.B.The entity was fined by the AEPD in the amount of 4,000 EUR for installing a video surveillance system aimed at public areas. The authority also found that images were captured without justified cause and retained longer than permitted by law. | ES | AEPD | GDPR | €4,000 | ↗ |
| 09 Jul 2025 | EDICIONES CATÓLICOS Y VIDA PÚBLICA, S.L.U.The entity was fined for using non-essential cookies without obtaining prior user consent. This conduct breached the LSSI requirements on obtaining consent before activating such tracking tools. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 29 Oct 2019 | JOKER PREMIUM INVEX, S.L.JOKER PREMIUM INVEX, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited commercial communications. The company used personal data taken from public sources without the individuals’ consent. | ES | AEPD | GDPR | €10,000 | ↗ |
| 11 Jan 2024 | DESPACHO TORRENTE, S.L.P.DESPACHO TORRENTE, S.L.P. was fined by the AEPD 10,000 EUR for improperly disclosing personal data, including sensitive information, in a letter concerning damage at public facilities. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 07 Aug 2021 | SPORTIUM APUESTAS DIGITAL S.A.U.SPORTIUM APUESTAS DIGITAL S.A.U. was fined by the AEPD 5,000 EUR for sending marketing emails after a data deletion request and for having non-compliant cookie policies on its website. The case indicates failures in data protection and user consent controls. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 23 Apr 2021 | VODAFONE SERVICIOS, S.L.U.Vodafone Servicios, S.L.U. was fined by the AEPD 50,000 EUR for failing to verify a customer's identity. The lapse enabled identity fraud and the unauthorized creation of an account. | ES | AEPD | GDPR | €50,000 | ↗ |
| 14 Feb 2023 | MENZIES AVIATION SPAIN S.L.MENZIES AVIATION SPAIN S.L. was fined by the AEPD 2,000 EUR for sending emails to multiple recipients without using BCC. This exposed employees’ personal data to other recipients. | ES | AEPD | GDPR | €2,000 | ↗ |
| 31 Mar 2022 | ALQUILER SEGURO, S.A.U.ALQUILER SEGURO, S.A.U. accessed personal data from Asnef for purposes other than those intended. The AEPD found this to be a breach of data protection rules and imposed a 70,000 EUR fine. | ES | AEPD | GDPR | €70,000 | ↗ |
| 27 Apr 2021 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 3,000 for sending commercial emails without the recipient’s consent. The authority found a breach of Article 21 of the LSSI, despite the recipient’s attempts to unsubscribe. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 24 Dec 2022 | EXPLOTACIONES HOSTELERAS Y DE OCIO ALBACETEÑAS, S.L.The entity was fined by the AEPD for breaching data protection rules. Its surveillance cameras were positioned to capture public areas without proper legal authorization. | ES | AEPD | GDPR | €500 | ↗ |
| 30 May 2022 | MARIELI GABRIELA, S.L.MARIELI GABRIELA, S.L. was fined by the AEPD in the amount of 3,000 EUR for charging amounts to the complainant's bank account without consent. The authority found a breach of Article 6(1) GDPR, meaning there was no lawful basis for the processing. | ES | AEPD | GDPR | €3,000 | ↗ |
| 09 May 2024 | HEADBLUE MARKETING, S.L.HEADBLUE MARKETING, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial electronic communications without consent. The authority also found a failure to respond to access requests. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 29 Jul 2011 | INFORMA D&B, SAINFORMA D&B, SA was fined by the AEPD 50,000 EUR for continuing to send commercial emails after the recipient requested unsubscribing and objected to data processing. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €50,000 | ↗ |
| 07 Jul 2022 | B.B.B.A private individual was fined 600 EUR by the AEPD for improperly positioning surveillance cameras. The cameras were directed toward public areas, which breached data protection rules. | ES | AEPD | GDPR | €600 | ↗ |