Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Aug 2024PUERTO FOGONES SLPUERTO FOGONES SL was fined EUR 2,000 by the AEPD. The authority found a breach for failing to provide access to information as required under Article 58.1 of the GDPR.ESAEPDGDPR€2,000
08 Apr 2022AVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCAAVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCA was fined by the AEPD for failing to implement robust access controls. The weakness enabled attackers to encrypt files and demand a ransom, indicating significant gaps in technical and organizational safeguards.ESAEPDGDPR€40,000
03 Apr 2023CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including an individual's data in a creditworthiness file without a lawful basis. The authority found this conduct violated Article 6 of the GDPR.ESAEPDGDPR€200,000
07 Nov 2020B.B.B.B.B.B. was fined by the AEPD EUR 2,000 for operating a video surveillance system directed toward public space. The measure affected the rights of third parties without justified cause and raised data protection compliance concerns.ESAEPDGDPR€2,000
10 May 2022B.B.B.The entity was fined by the AEPD EUR 300 for installing surveillance cameras that recorded a neighbor’s property and a public street. The authority found this to be a breach of data protection rules.ESAEPDGDPR€300
01 Jan 2014COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD €3,000 for sending unsolicited commercial messages by electronic means. The conduct breached Article 21 of the LSSI, which prohibits such communications without prior consent.ESAEPDePrivacy€3,000
03 Mar 2022B.B.B.The entity was fined EUR 300 by the AEPD for implementing a video surveillance system that did not comply with data protection rules. The authority found a breach of the data minimization principle and a failure to provide adequate information to data subjects.ESAEPDGDPR€300
25 Feb 2025SERVICIOS ESPECIALES, S.A.SERVICIOS ESPECIALES, S.A. was fined by the AEPD 200,000 EUR for disclosing the identity of a complainant in a workplace harassment case. The authority found a breach of personal data confidentiality principles.ESAEPDGDPR€200,000
18 Jul 2025LUXURY ANGELS, S.L.LUXURY ANGELS, S.L. was fined EUR 500 by the AEPD for sending a client a form that contained a third party’s personal data. The authority treated this as a breach of data protection principles.ESAEPDGDPR€500
02 Jun 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for continuing to send investment reports by postal mail despite the complainant’s request to receive them by email. The authority found a breach of the right to object and to stop data processing.ESAEPDGDPR€70,000
01 Jan 2013SEARCHTASK S.L.U.SEARCHTASK S.L.U. was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior consent.ESAEPDePrivacy€30,001
01 Jan 2014COMERCIAL POLINDUS 21, SLUCOMERCIAL POLINDUS 21, SLU was fined by the AEPD EUR 1,200 for sending an SMS to a number listed on the Robinson List. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€1,200
01 Oct 2013CIRCULO GACELA S.L.U.CIRCULO GACELA S.L.U. was fined by the AEPD EUR 1,800 for sending unsolicited commercial emails without prior consent. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,800
01 Jan 2012REED EXHIBITIONS IBERIA, S.A.REED EXHIBITIONS IBERIA, S.A. was fined by the AEPD 1,200 EUR for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI despite the recipient’s requests to unsubscribe.ESAEPDePrivacy€1,200
06 Aug 2025SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.ASERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A suffered a data breach involving unauthorized access to and exfiltration of customer personal data, including payment information. The incident was linked to phishing and account compromise, resulting in the loss of sensitive data.ESAEPDGDPR€2,500,000
01 Jan 2015DIVINITEL, S.L.DIVINITEL, S.L. was fined by the AEPD EUR 2,000 for sending unsolicited commercial messages without recipient consent. This constituted a breach of Article 21.2 of the LSSI.ESAEPDePrivacy€2,000
24 Apr 2023B.B.B.B.B.B. published the complainant’s image and name on its website without consent. AEPD found this to be a breach of data protection rules and imposed a EUR 1,000 fine.ESAEPDGDPR€1,000
24 May 2013RIZOS S.L.RIZOS S.L. was fined by the AEPD EUR 1,800 for sending commercial messages without providing information on how to opt out. This breached Article 21.2 of the LSSI, which requires a clear unsubscribe option for recipients.ESAEPDePrivacy€1,800
23 Jan 2024CAJA RURAL DE EXTREMADURA S.C.C.CAJA RURAL DE EXTREMADURA S.C.C. was fined by the AEPD 250,000 EUR for a breach that compromised the confidentiality and integrity of personal data. The authority found a violation of Article 5(1)(f) of the GDPR.ESAEPDGDPR€250,000
24 Mar 2021ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A. was fined EUR 30,000 by the AEPD. The authority found that after a policy was canceled, the company continued processing personal data without a lawful basis, in breach of Article 6 GDPR.ESAEPDGDPR€30,000