Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2022GESTERPOOL, S.L.U.The AEPD imposed a 15,000 EUR fine on GESTERPOOL, S.L.U. for unauthorized use of personal data in a commercial call and for contract processing without consent. The case concerns breaches of GDPR rules, including Articles 28 and 58(1).ESAEPDGDPR€15,000
06 Dec 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide requested information. The case concerns a breach of obligations under data protection rules.ESAEPDGDPR€5,000
19 Jan 2023ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal and banking data without consent. The conduct occurred in connection with a contract renewal offer presented as if it came from the complainant's electricity supplier.ESAEPDGDPR€10,000
24 Mar 2023B.B.B.The entity installed surveillance cameras without the required informational signage. AEPD treated this as a breach of data protection rules.ESAEPDGDPR€300
29 Oct 2024TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD for allowing a SIM card to be duplicated without the customer's consent. The incident led to fraudulent activity on the customer's bank account, indicating serious weaknesses in identity verification and security controls.ESAEPDGDPR€200,000
01 Jan 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD 70,000 EUR for changing the ownership of a mobile line without proper verification. The failure enabled unauthorized access to the complainant’s bank data and fraudulent transactions.ESAEPDGDPR€70,000
23 Apr 2023COYARE SLUCOYARE SLU was fined by the AEPD EUR 2,000 for a data protection breach linked to mass email sending. Using CC instead of BCC exposed recipients’ email addresses and could have compromised their identities.ESAEPDGDPR€2,000
10 Jul 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 100,000 for repeatedly sending a former customer electronic notices about invoice availability. The authority found that the processing lacked a valid legal basis under GDPR Article 6.1.ESAEPDGDPR€100,000
28 Jun 2023FESTINA LOTUS S.A.FESTINA LOTUS S.A. did not respond to requests to delete a user's account and personal data. The authority found a breach of Article 17 GDPR and imposed a fine of EUR 1,000.ESAEPDGDPR€1,000
01 Jan 2022JEG'S LIFE STYLE, S.L.JEG'S LIFE STYLE, S.L. was fined by the AEPD 20,000 EUR for breaching data protection rules. The company disclosed private information about a former employee to third parties by email without consent.ESAEPDGDPR€20,000
03 May 2022B.B.B.Y OTRO MAS C.B.The entity installed a video surveillance system without providing the required information to data subjects. The conduct breached Article 13 of the GDPR and resulted in a EUR 300 fine imposed by the AEPD.ESAEPDGDPR€300
07 Jun 2023ELECTRAWORKS - CEUTA, S.A.ELECTRAWORKS - CEUTA, S.A. did not comply with a data deletion request and retained personal data for 10 years without proper justification. The AEPD found this to be a breach of Article 13 GDPR and imposed a 10,000 EUR fine.ESAEPDGDPR€10,000
15 Oct 2012MYID ESPAÑA S.L.MYID ESPAÑA S.L. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited commercial emails despite requests to unsubscribe. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,200
22 Jun 2022B.B.B.An individual's personal data was used without consent to publish an online advertisement for sexual services, resulting in harassment. The responsible entity was fined for violating Article 6(1) of the GDPR.ESAEPDGDPR€10,000
11 Jan 2017WIZINK BANK, S.A.WIZINK BANK, S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial emails despite a request to unsubscribe. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€5,000
17 Jun 2020LA CASA COMPROMETIDA, S.Coop.The entity was fined by the AEPD in the amount of 3,000 EUR for failing to comply with data protection rules regarding its website cookie policy. The case concerned deficiencies in the required information or consent related to cookies.ESAEPDePrivacy€3,000
11 Dec 2025UPGYMS IBERIA, S.L.UPGYMS IBERIA, S.L. was fined by the AEPD EUR 5,000 for sending unsolicited commercial SMS messages without obtaining recipient consent. The conduct breached the LSSI rules on marketing communications.ESAEPDePrivacy€5,000
06 Sept 2022B.B.B.The entity failed to provide the information required under Article 13 GDPR when processing personal data. AEPD imposed a fine of EUR 2,000 for this breach.ESAEPDGDPR€2,000
23 May 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD for assigning a customer's DNI to a third party. This enabled unauthorized access to personal data and invoices, constituting a data protection breach.ESAEPDGDPR€60,000
24 Feb 2010INBORNTECH S.L.INBORNTECH S.L. was fined by the AEPD 1,200 EUR for sending an unsolicited commercial email. The authority found that the requirements of Article 21 of the LSSI were not met.ESAEPDePrivacy€1,200