BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Dec 2021 | MEDIOS DE PREVENCIÓN EXTERNOS, S.L.The entity was fined for sending unsolicited advertising emails despite requests to cancel the subscription. This conduct breached rules on electronic commercial communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 21 Feb 2014 | INSTITUCIÓN EUROAMERICANA DE FORMACIÓN E.I.R.L.The entity was fined by the AEPD in the amount of 39,000 EUR for sending unsolicited commercial emails without prior recipient consent. This constituted a breach of Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €39,000 | ↗ |
| 01 Jan 2024 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for processing personal data without consent. The case involved duplicating a SIM card without the user's authorization, which led to unauthorized bank transactions. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2023 | B.B.B.The entity installed a video surveillance system in a garage without the required authorization and without informing the affected individuals. This constituted a breach of data protection rules and resulted in a EUR 600 fine imposed by the AEPD. | ES | AEPD | GDPR | €600 | ↗ |
| 15 Apr 2021 | HAZTEOIR.ORGThe association HazteOir.Org was fined EUR 5,000 by the AEPD for including images and names of individuals in a pamphlet without their consent. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2023 | CIUDAD RESIDENCIAL H.H.H.CIUDAD RESIDENCIAL H.H.H. was fined by the AEPD EUR 2,000 for breaching the data minimization principle. The case concerned capturing and storing photographs of residents collecting packages without informing them about this processing. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2021 | ASOCIACIÓN JEREZ CAPITALThe entity was fined by the AEPD for failing to comply with data protection rules in relation to its website cookie policy. Non-essential cookies were placed on the site without prior user consent. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 May 2022 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for unauthorized access to a former customer's account. The access enabled a third party to make purchases and subscriptions, indicating improper processing of personal data without consent. | ES | AEPD | GDPR | €70,000 | ↗ |
| 27 Jul 2023 | B.B.B.A neighbor installed a surveillance camera that captured images of the complainant’s property without authorization. The AEPD found this to be a breach of Article 5(1)(c) GDPR and imposed a fine of EUR 300. | ES | AEPD | GDPR | €300 | ↗ |
| 01 Jan 2021 | DAVISER SERVICIOS, S.L.DAVISER SERVICIOS, S.L. was fined by the AEPD 20,000 EUR for using biometric data from fingerprint readers and surveillance cameras without properly informing employees. The authority found this to be a breach of data protection principles. | ES | AEPD | GDPR | €20,000 | ↗ |
| 22 Nov 2021 | B.B.B.The entity installed a surveillance camera in a shared stairway without the consent of the affected persons. The camera captured an excessive area, including private spaces, which breached data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 19 Dec 2024 | CLUB RÁPIDO DE BOUZASThe club was fined by the AEPD for leaving documents containing players’ personal data, including minors’ data, in a public trash container. The authority found this breached data protection principles, especially confidentiality and security. | ES | AEPD | GDPR | €1,000 | ↗ |
| 24 Feb 2025 | SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L. was fined by the AEPD 15,000 EUR for recording gym sessions without informing participants or obtaining their consent. The authority found this to be a breach of GDPR rules on consent and personal data processing. | ES | AEPD | GDPR | €15,000 | ↗ |
| 05 Nov 2020 | DR MARÍN CIRUGIA PLÁSTICA, S.L.P.DR MARÍN CIRUGIA PLÁSTICA, S.L.P. was fined EUR 4,000 by the AEPD. The authority found that the company failed to provide a privacy policy on its website and used personal data for marketing purposes without consent. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 24 Jul 2018 | TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined by the AEPD 8,100 EUR for sending unsolicited advertising emails without prior recipient consent. The case concerned a breach of Article 21 of the LSSI and reflects unlawful direct marketing practices. | ES | AEPD | ePrivacy | €8,100 | ↗ |
| 01 Jan 2024 | ORANGE BANK, S.A. SUCURSAL EN ESPAÑAOrange Bank was fined for a security breach that exposed personal data. The authority found a violation of Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €1,500,000 | ↗ |
| 17 Dec 2019 | B.B.B.A private individual was fined by the AEPD for installing a camera aimed at a public space and a building entrance without justification. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 07 Oct 2014 | BANCO SANTANDER, S.A.Banco Santander was fined by the AEPD EUR 2,000 for sending commercial emails despite the recipient's objection. The authority found this breached Article 21 of the LSSI on unsolicited electronic communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 07 Jun 2021 | EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L.EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L. was fined EUR 1,000 by the AEPD for improperly sharing an employee’s personal data with the company committee. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 09 Jan 2024 | 20 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined 45,000 EUR by the AEPD for publicly exposing the image of a victim of an alleged crime. The authority found that this constituted a breach of data protection rules. | ES | AEPD | GDPR | €45,000 | ↗ |