BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Aug 2024 | PUERTO FOGONES SLPUERTO FOGONES SL was fined EUR 2,000 by the AEPD. The authority found a breach for failing to provide access to information as required under Article 58.1 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 08 Apr 2022 | AVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCAAVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCA was fined by the AEPD for failing to implement robust access controls. The weakness enabled attackers to encrypt files and demand a ransom, indicating significant gaps in technical and organizational safeguards. | ES | AEPD | GDPR | €40,000 | ↗ |
| 03 Apr 2023 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including an individual's data in a creditworthiness file without a lawful basis. The authority found this conduct violated Article 6 of the GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 07 Nov 2020 | B.B.B.B.B.B. was fined by the AEPD EUR 2,000 for operating a video surveillance system directed toward public space. The measure affected the rights of third parties without justified cause and raised data protection compliance concerns. | ES | AEPD | GDPR | €2,000 | ↗ |
| 10 May 2022 | B.B.B.The entity was fined by the AEPD EUR 300 for installing surveillance cameras that recorded a neighbor’s property and a public street. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €300 | ↗ |
| 01 Jan 2014 | COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD €3,000 for sending unsolicited commercial messages by electronic means. The conduct breached Article 21 of the LSSI, which prohibits such communications without prior consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 03 Mar 2022 | B.B.B.The entity was fined EUR 300 by the AEPD for implementing a video surveillance system that did not comply with data protection rules. The authority found a breach of the data minimization principle and a failure to provide adequate information to data subjects. | ES | AEPD | GDPR | €300 | ↗ |
| 25 Feb 2025 | SERVICIOS ESPECIALES, S.A.SERVICIOS ESPECIALES, S.A. was fined by the AEPD 200,000 EUR for disclosing the identity of a complainant in a workplace harassment case. The authority found a breach of personal data confidentiality principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 18 Jul 2025 | LUXURY ANGELS, S.L.LUXURY ANGELS, S.L. was fined EUR 500 by the AEPD for sending a client a form that contained a third party’s personal data. The authority treated this as a breach of data protection principles. | ES | AEPD | GDPR | €500 | ↗ |
| 02 Jun 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for continuing to send investment reports by postal mail despite the complainant’s request to receive them by email. The authority found a breach of the right to object and to stop data processing. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2013 | SEARCHTASK S.L.U.SEARCHTASK S.L.U. was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior consent. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 01 Jan 2014 | COMERCIAL POLINDUS 21, SLUCOMERCIAL POLINDUS 21, SLU was fined by the AEPD EUR 1,200 for sending an SMS to a number listed on the Robinson List. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 01 Oct 2013 | CIRCULO GACELA S.L.U.CIRCULO GACELA S.L.U. was fined by the AEPD EUR 1,800 for sending unsolicited commercial emails without prior consent. This conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,800 | ↗ |
| 01 Jan 2012 | REED EXHIBITIONS IBERIA, S.A.REED EXHIBITIONS IBERIA, S.A. was fined by the AEPD 1,200 EUR for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI despite the recipient’s requests to unsubscribe. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 06 Aug 2025 | SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.ASERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A suffered a data breach involving unauthorized access to and exfiltration of customer personal data, including payment information. The incident was linked to phishing and account compromise, resulting in the loss of sensitive data. | ES | AEPD | GDPR | €2,500,000 | ↗ |
| 01 Jan 2015 | DIVINITEL, S.L.DIVINITEL, S.L. was fined by the AEPD EUR 2,000 for sending unsolicited commercial messages without recipient consent. This constituted a breach of Article 21.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 24 Apr 2023 | B.B.B.B.B.B. published the complainant’s image and name on its website without consent. AEPD found this to be a breach of data protection rules and imposed a EUR 1,000 fine. | ES | AEPD | GDPR | €1,000 | ↗ |
| 24 May 2013 | RIZOS S.L.RIZOS S.L. was fined by the AEPD EUR 1,800 for sending commercial messages without providing information on how to opt out. This breached Article 21.2 of the LSSI, which requires a clear unsubscribe option for recipients. | ES | AEPD | ePrivacy | €1,800 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE EXTREMADURA S.C.C.CAJA RURAL DE EXTREMADURA S.C.C. was fined by the AEPD 250,000 EUR for a breach that compromised the confidentiality and integrity of personal data. The authority found a violation of Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €250,000 | ↗ |
| 24 Mar 2021 | ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A. was fined EUR 30,000 by the AEPD. The authority found that after a policy was canceled, the company continued processing personal data without a lawful basis, in breach of Article 6 GDPR. | ES | AEPD | GDPR | €30,000 | ↗ |