Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Feb 2021FLEXOGRÁFICA DEL MEDITERRÁNEO, S.L.The company was fined by the AEPD for failing to provide a privacy policy and cookie management on its websites. The authority also found that user consent was collected in a generic manner, which did not meet data protection requirements.ESAEPDGDPR€3,000
04 Jun 2021INTERSUMI S.C.INTERSUMI S.C. was fined EUR 2,000 by the AEPD for not having an adequate privacy policy on its website. The authority found this to be a breach of Article 13 of the GDPR.ESAEPDGDPR€2,000
14 Apr 2021MASTER DISTANCIA S.A.MASTER DISTANCIA S.A. was fined EUR 25,000 by the AEPD for unlawfully processing personal data by including it in credit information systems without a valid legal basis. The authority found a breach of GDPR Article 6.ESAEPDGDPR€25,000
11 Apr 2023SOCIEDAD VASCONGADA DE PUBLICACIONES, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. AEPD found that this breached the data minimization principle.ESAEPDGDPR€150,000
01 Jan 2013GALIBROKER GESTION TURISTICA, S.L.GALIBROKER GESTION TURISTICA, S.L. was fined by the AEPD 6,000 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€6,000
24 Sept 2015KREDITECH SPAIN S.L.KREDITECH SPAIN S.L. was fined by the AEPD in the amount of 2,600 EUR for sending unsolicited commercial emails to a complainant. The authority found this conduct to be in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€2,600
03 Nov 2021B.B.B.The entity processed personal data without consent by using the complainant's data to make a purchase on Amazon. The authority found a breach of GDPR Article 6.ESAEPDGDPR€2,000
18 Dec 2023MOTORSPORT NETWORK ESPAÑA, S.L.MOTORSPORT NETWORK ESPAÑA, S.L. was fined by the AEPD 5,000 EUR for using an illegal cookie consent mechanism on its website. Users were required to accept cookies to access free content or subscribe in order to avoid them.ESAEPDePrivacy€5,000
28 Oct 2015MUTUA MADRILEÑA AUTOMOVILISTA SOCIEDAD DE SEGUROS A PRIMA FIJAMutua Madrileña was fined 40,001 EUR by the AEPD for sending unsolicited commercial emails despite the recipient’s objection. The case concerns a breach of data protection and direct marketing rules.ESAEPDePrivacy€40,001
13 Dec 2022CONSULTORÍA PERITACIONES ALMERIENSES, S.L.The company did not respond to a data access request and failed to publish information on data processing or the data controller on its website. AEPD treated this as a breach of the information obligations under Article 13 GDPR.ESAEPDGDPR€2,000
01 Jan 2016AUTO OJA S.A.AUTO OJA S.A. was fined by the AEPD 10,000 EUR for sending unsolicited promotional emails to a customer. The company continued contacting the recipient despite requests to be removed from the mailing list, which breached the LSSI.ESAEPDePrivacy€10,000
19 May 2025GATIGOS, S.L.GATIGOS, S.L. was fined EUR 6,000 by the AEPD for failing to provide access to personal data and the information requested by the data protection authority. The authority found a breach of Article 58(1) GDPR.ESAEPDGDPR€6,000
14 Aug 2024GRUPO INMOBILIARIO GONTEGA, S.L.GRUPO INMOBILIARIO GONTEGA, S.L. was fined by the AEPD EUR 450 for failing to properly handle a data access request. The authority found a breach of Article 15 GDPR and non-compliance with its resolution.ESAEPDGDPR€450
20 Aug 2021A.A.A. (FRUTERIA)The entity was fined for operating a video surveillance system without the required signage informing individuals of its presence. The authority treated this as a breach of Article 13 GDPR on transparency and information duties.ESAEPDGDPR€1,000
25 Jul 2019CONTAPUBLI RIOJA, S.L. (GESTIRIOJA)CONTAPUBLI RIOJA, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails. The conduct continued despite the recipient's objection and request for data deletion.ESAEPDePrivacy€2,500
01 Jan 2025TELEROSA SPAIN, S.L.TELEROSA SPAIN, S.L. was fined 450 EUR by the AEPD for sending unsolicited commercial SMS messages without prior express consent. The authority also noted that there was no pre-existing contractual relationship with the recipients.ESAEPDePrivacy€450
02 Dec 2011PROMOMOVIL TELECOMUNICACIONES S.L.PROMOMOVIL TELECOMUNICACIONES S.L. was fined by the AEPD 1,200 EUR for sending unsolicited promotional SMS messages without recipient consent. The conduct breached Article 21 of the LSSI on commercial communications without prior consent.ESAEPDePrivacy€1,200
01 Jan 2024WAGESTREAM SPAIN S.L.U.WAGESTREAM SPAIN S.L.U. was fined by the AEPD for processing employees’ personal data without proper consent. The case involved names, personal email addresses, bank account numbers, and salary details, in breach of Article 6(1) GDPR.ESAEPDGDPR€2,000
01 Jan 2019CENTRO DE ESTUDIOS DIRIGIDOS DELTA, S.L.The entity sent a document via WhatsApp containing personal data of three individuals without their consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€5,000
12 Jul 2024CLIDEA DESARROLLO, S.A.CLIDEA DESARROLLO, S.A. was fined by the AEPD 3,000 EUR for sending an email to 349 recipients without using the BCC field. This exposed the personal email addresses of all recipients.ESAEPDGDPR€3,000