Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2025STRATESYS TECHNOLOGY SOLUTIONS, S.L.STRATESYS TECHNOLOGY SOLUTIONS, S.L. was fined EUR 100,000 by the AEPD for breaching Article 5(1)(f) of the GDPR. The case concerned a failure to protect the integrity and confidentiality of personal data.ESAEPDGDPR€100,000
20 Dec 2021INSEKT FOOD S.L.INSEKT FOOD S.L. was fined by the AEPD EUR 4,000 for sharing an individual's personal data in WhatsApp group chats without consent. The authority found that the processing lacked a lawful basis under Article 6 of the GDPR.ESAEPDGDPR€4,000
10 Oct 2016ROCK INTERNET S.L.ROCK INTERNET S.L. was fined 3,800 EUR by the AEPD. The case concerned sending unsolicited commercial emails without recipient consent, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€3,800
01 Jan 2015JAZZ TELECOM SAUJAZZ TELECOM SAU was fined by the AEPD 2,900 EUR for sending unsolicited SMS advertisements to a complainant. The conduct breached Article 21 of the LSSI on commercial communications without prior consent.ESAEPDePrivacy€2,900
26 Feb 2021PINTODIS, S.L.PINTODIS, S.L. was fined by the AEPD for installing surveillance cameras that recorded employees in private areas without sufficient justification. The authority found this to be a breach of data protection principles.ESAEPDGDPR€10,000
07 Aug 2023FORMACIÓN Y EMPLEO DE EXTREMADURA, S.L.The company sent emails to multiple recipients without using BCC, allowing each recipient to see the other recipients’ email addresses. AEPD treated this as a breach of data protection rules and imposed an 8,000 EUR fine.ESAEPDGDPR€8,000
11 Aug 2020DERDIX 5000 SLThe entity published photos of minors in a magazine without obtaining consent, which constitutes a breach of data protection rules. The case concerns the unauthorized disclosure of children’s images and was sanctioned by the AEPD.ESAEPDGDPR€2,000
29 Apr 2022C.P. ***COMUNIDAD.1The entity installed surveillance cameras without informing the property owners. It also failed to provide the required information on the surveillance signs.ESAEPDGDPR€800
26 Jun 2020ESLORA PROYECTOS, S.L.ESLORA PROYECTOS, S.L. was fined by the AEPD 10,000 EUR for failing to provide cookie information and for not obtaining user consent before using cookies. The authority cited a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€10,000
01 Jan 2019B.B.B.B.B.B. was fined 2,000 EUR by the AEPD for reusing paper containing personal data. This made the data accessible to third parties without consent, constituting a breach of data protection rules.ESAEPDGDPR€2,000
01 Jan 2025A.A.A.A.A.A. failed to properly handle a data access request, which constitutes a breach of Article 15 GDPR. The AEPD imposed a fine of EUR 200, reduced to EUR 160 for early payment.ESAEPDGDPR€200
01 Jan 2016EDUCACION COMPETENCIAL S.L.EDUCACION COMPETENCIAL S.L. was fined by the AEPD €6,000 for sending unsolicited advertising emails. The emails exposed recipients’ addresses, breaching data protection and electronic communications rules.ESAEPDePrivacy€6,000
26 May 2022PREICO JURIDICOS S.L.PREICO JURIDICOS S.L. was fined EUR 6,000 by the AEPD for failing to provide required information. The case concerned a breach of Article 58(1) GDPR.ESAEPDGDPR€6,000
05 Feb 2025RESIDENTIAL QUALITY ENJOY, S.L.The company was fined EUR 2,000 by the AEPD for requesting and processing personal data, including minors' IDs, without proper consent or information. The authority found this to be a breach of data protection principles and transparency obligations.ESAEPDGDPR€2,000
01 Jan 2022ANIVERSALIA NETWORKS, S.L.ANIVERSALIA NETWORKS, S.L. was fined €2,000 by the AEPD. The authority found that the website did not provide adequate contact information for individuals to exercise their data protection rights.ESAEPDGDPR€2,000
01 Oct 2024IBERCAJA BANCO, S.A.Ibercaja Banco, S.A. accessed personal data in the BADEXCUG EXPERIAN file 47 times without consent after the contractual relationship ended. The AEPD found this to be a breach of data protection rules and imposed a 300,000 EUR fine.ESAEPDGDPR€300,000
21 Sept 2022GUUDJOB WORLDWIDE S.L.GUUDJOB WORLDWIDE S.L. failed to delete personal data after a data subject request, breaching GDPR Articles 12 and 17. The AEPD imposed a fine of EUR 1,000, reduced to EUR 800 for early payment.ESAEPDGDPR€1,000
01 Jan 2023OPEN BANK, S.A.Openbank was fined by the AEPD for opening a bank account without the individual's authorization. The account was later used for fraudulent activities, indicating failures in verification and data protection controls.ESAEPDGDPR€70,000
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 120,000 EUR for a data protection breach involving unauthorized SIM card duplication. The incident enabled fraudulent activity, and the authority found that the company had not implemented sufficient preventive measures.ESAEPDGDPR€120,000
29 Jun 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 60,000 for unauthorized processing of personal data. The case involved a fraudulent contract and the porting of a customer's phone line without a valid legal basis.ESAEPDGDPR€60,000