Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Mar 2023ALTERNATIVA CORELLANA INDEPENDIENTE (ACI)The organization published a court ruling on its blog without anonymizing the personal data of the individuals involved. The AEPD found a breach of the data minimization principle and imposed a 500 EUR fine.ESAEPDGDPR€500
01 Jan 2024BONTECU DISTRIBUCIONES, S.L.U.BONTECU DISTRIBUCIONES, S.L.U. was fined by the AEPD for processing personal data without consent and for failing to have proper data processing agreements in place. The case concerned a complainant who received an unsolicited contract from Factor Energía.ESAEPDGDPR€25,000
03 Dec 2021MEDIOS DE PREVENCIÓN EXTERNOS, S.L.The entity was fined for sending unsolicited advertising emails despite requests to cancel the subscription. This conduct breached rules on electronic commercial communications.ESAEPDePrivacy€2,000
21 Feb 2014INSTITUCIÓN EUROAMERICANA DE FORMACIÓN E.I.R.L.The entity was fined by the AEPD in the amount of 39,000 EUR for sending unsolicited commercial emails without prior recipient consent. This constituted a breach of Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€39,000
01 Jan 2024VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for processing personal data without consent. The case involved duplicating a SIM card without the user's authorization, which led to unauthorized bank transactions.ESAEPDGDPR€200,000
01 Jan 2023B.B.B.The entity installed a video surveillance system in a garage without the required authorization and without informing the affected individuals. This constituted a breach of data protection rules and resulted in a EUR 600 fine imposed by the AEPD.ESAEPDGDPR€600
15 Apr 2021HAZTEOIR.ORGThe association HazteOir.Org was fined EUR 5,000 by the AEPD for including images and names of individuals in a pamphlet without their consent. The authority found this to be a breach of data protection rules.ESAEPDGDPR€5,000
01 Jan 2023CIUDAD RESIDENCIAL H.H.H.CIUDAD RESIDENCIAL H.H.H. was fined by the AEPD EUR 2,000 for breaching the data minimization principle. The case concerned capturing and storing photographs of residents collecting packages without informing them about this processing.ESAEPDGDPR€2,000
01 Jan 2021ASOCIACIÓN JEREZ CAPITALThe entity was fined by the AEPD for failing to comply with data protection rules in relation to its website cookie policy. Non-essential cookies were placed on the site without prior user consent.ESAEPDGDPR€1,000
01 May 2022VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for unauthorized access to a former customer's account. The access enabled a third party to make purchases and subscriptions, indicating improper processing of personal data without consent.ESAEPDGDPR€70,000
27 Jul 2023B.B.B.A neighbor installed a surveillance camera that captured images of the complainant’s property without authorization. The AEPD found this to be a breach of Article 5(1)(c) GDPR and imposed a fine of EUR 300.ESAEPDGDPR€300
01 Jan 2021DAVISER SERVICIOS, S.L.DAVISER SERVICIOS, S.L. was fined by the AEPD 20,000 EUR for using biometric data from fingerprint readers and surveillance cameras without properly informing employees. The authority found this to be a breach of data protection principles.ESAEPDGDPR€20,000
22 Nov 2021B.B.B.The entity installed a surveillance camera in a shared stairway without the consent of the affected persons. The camera captured an excessive area, including private spaces, which breached data protection principles.ESAEPDGDPR€2,000
19 Dec 2024CLUB RÁPIDO DE BOUZASThe club was fined by the AEPD for leaving documents containing players’ personal data, including minors’ data, in a public trash container. The authority found this breached data protection principles, especially confidentiality and security.ESAEPDGDPR€1,000
24 Feb 2025SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L. was fined by the AEPD 15,000 EUR for recording gym sessions without informing participants or obtaining their consent. The authority found this to be a breach of GDPR rules on consent and personal data processing.ESAEPDGDPR€15,000
05 Nov 2020DR MARÍN CIRUGIA PLÁSTICA, S.L.P.DR MARÍN CIRUGIA PLÁSTICA, S.L.P. was fined EUR 4,000 by the AEPD. The authority found that the company failed to provide a privacy policy on its website and used personal data for marketing purposes without consent.ESAEPDePrivacy€4,000
24 Jul 2018TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined by the AEPD 8,100 EUR for sending unsolicited advertising emails without prior recipient consent. The case concerned a breach of Article 21 of the LSSI and reflects unlawful direct marketing practices.ESAEPDePrivacy€8,100
01 Jan 2024ORANGE BANK, S.A. SUCURSAL EN ESPAÑAOrange Bank was fined for a security breach that exposed personal data. The authority found a violation of Article 5(1)(f) of the GDPR.ESAEPDGDPR€1,500,000
17 Dec 2019B.B.B.A private individual was fined by the AEPD for installing a camera aimed at a public space and a building entrance without justification. The authority found a breach of data protection principles.ESAEPDGDPR€2,000
07 Oct 2014BANCO SANTANDER, S.A.Banco Santander was fined by the AEPD EUR 2,000 for sending commercial emails despite the recipient's objection. The authority found this breached Article 21 of the LSSI on unsolicited electronic communications.ESAEPDePrivacy€2,000