BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2016 | AUTOCLUB MUTUA MADRILEÑA S.L.AUTOCLUB MUTUA MADRILEÑA S.L. was fined by the AEPD 5,000 EUR for sending an unsolicited commercial SMS without prior consent. The authority also found that no opt-out mechanism was provided, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jan 2016 | PROSAD CONSULTORES S.L.PROSAD CONSULTORES S.L. was fined by the AEPD EUR 800 for sending unsolicited commercial emails. The recipient had not given prior consent and was listed on the Robinson List, which breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €800 | ↗ |
| 01 Jan 2016 | WIZINK BANK S.A.WIZINK BANK S.A. was fined by the AEPD €4,100 for sending unsolicited commercial communications by electronic means. The authority found that the legal requirements for such communications were not met. | ES | AEPD | ePrivacy | €4,100 | ↗ |
| 01 Jan 2016 | HAPPY SOCIAL MEDIA, LTDHAPPY SOCIAL MEDIA, LTD was fined by the AEPD EUR 3,400 for sending unsolicited marketing emails. The authority found that the messages did not include a simple opt-out mechanism, which breached the LSSI. | ES | AEPD | ePrivacy | €3,400 | ↗ |
| 01 Jan 2016 | BANCO SANTANDER, S.A.Banco Santander, S.A. was fined by the AEPD €8,000 for sending unsolicited commercial emails. The authority found that the messages did not provide a valid email address for recipients to opt out, breaching Article 21 of the LSSI. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 01 Jan 2016 | TELE PIZZA S.A.U.TELE PIZZA S.A.U. was fined EUR 2,500 by the AEPD for sending commercial emails without providing a valid electronic address for exercising ARCO rights. This breached Article 21.2 of the LSSI and indicates a failure to meet required recipient information obligations. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 01 Jan 2016 | TOYS CENTRE, S.L.TOYS CENTRE, S.L. continued sending promotional emails to a complainant even after confirming removal from the mailing list. The AEPD fined the company for failing to comply with the requirements for commercial communications. | ES | AEPD | ePrivacy | €6,200 | ↗ |
| 01 Jan 2016 | PROCTER & GAMBLE ESPAÑAProcter & Gamble España was fined 20,000 EUR by the AEPD for continuing to send marketing emails to a complainant after unsubscribe requests. The authority found this conduct breached the LSSI rules on electronic communications. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 01 Jan 2016 | VODAFONE ONO, S.A.U.Vodafone Ono, S.A.U. was fined by the AEPD 6,000 EUR for sending unsolicited advertising SMS messages to a complainant. The complainant's data had previously been canceled, indicating a breach of data handling and marketing communication rules. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 01 Jan 2016 | ORANGE ESPAGNE S.A.U.ORANGE ESPAGNE S.A.U. was fined by the AEPD 2,500 EUR for sending unsolicited commercial communications by electronic means without the recipient's consent. The case indicates a breach of electronic marketing rules and the requirement for prior consent. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 14 Jan 2016 | Comune di Santa FlaviaThe Garante fined Comune di Santa Flavia €10,000 for unlawfully publishing documents on its website that disclosed individuals' health data. The case involved the disclosure of sensitive personal data without a lawful basis. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Jan 2016 | Q.12 s.r.l.Q.12 s.r.l. was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice for its video surveillance system. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 21 Jan 2016 | Federico FabiFederico Fabi was fined by the Garante for failing to provide the required information to data subjects when collecting personal data through forms on the company’s website. The case concerns a breach of transparency and notice obligations under data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 21 Jan 2016 | Alfonso EspositoAlfonso Esposito, a gynecologist, was fined by the Garante for processing clients’ personal data for medical purposes without obtaining their consent. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jan 2016 | Comune di AdriaComune di Adria was fined EUR 4,000 by the Garante for unlawfully disclosing personal data of third parties. The authority sent photographic results to a complainant that contained data relating to other individuals, breaching data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Jan 2016 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 10,500 for sending unsolicited advertising SMS messages without prior recipient consent. The authority also found that no opt-out mechanism was provided, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €10,500 | ↗ |
| 21 Jan 2016 | Malta Games di Belgiorno Chiara & C. s.a.s.Malta Games di Belgiorno Chiara & C. s.a.s. was fined EUR 2,400 by the Garante. The authority found that the company failed to provide the required information to data subjects about personal data processing through a video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 27 Jan 2016 | Planetcall s.r.l.Planetcall s.r.l. was fined €20,000 by the Garante for failing to designate data processors and for using inadequate authentication credentials. The case concerned breaches of the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Jan 2016 | Agenzia di promozione economica della ToscanaAgenzia di promozione economica della Toscana was fined 10,000 EUR by the Garante for publishing lists of disabled candidates admitted to competitive exams on its institutional websites. The authority found that this disclosure breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2016 | Punto Fermo s.r.l.Punto Fermo s.r.l. was fined by the Garante EUR 12,000 for retaining surveillance footage for 25 days. This exceeded the one-week limit set by the general rules on video surveillance. | IT | Garante | GDPR | €12,000 | ↗ |