BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2022 | GESTERPOOL, S.L.U.The AEPD imposed a 15,000 EUR fine on GESTERPOOL, S.L.U. for unauthorized use of personal data in a commercial call and for contract processing without consent. The case concerns breaches of GDPR rules, including Articles 28 and 58(1). | ES | AEPD | GDPR | €15,000 | ↗ |
| 06 Dec 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide requested information. The case concerns a breach of obligations under data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 19 Jan 2023 | ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal and banking data without consent. The conduct occurred in connection with a contract renewal offer presented as if it came from the complainant's electricity supplier. | ES | AEPD | GDPR | €10,000 | ↗ |
| 24 Mar 2023 | B.B.B.The entity installed surveillance cameras without the required informational signage. AEPD treated this as a breach of data protection rules. | ES | AEPD | GDPR | €300 | ↗ |
| 29 Oct 2024 | TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD for allowing a SIM card to be duplicated without the customer's consent. The incident led to fraudulent activity on the customer's bank account, indicating serious weaknesses in identity verification and security controls. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2023 | TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD 70,000 EUR for changing the ownership of a mobile line without proper verification. The failure enabled unauthorized access to the complainant’s bank data and fraudulent transactions. | ES | AEPD | GDPR | €70,000 | ↗ |
| 23 Apr 2023 | COYARE SLUCOYARE SLU was fined by the AEPD EUR 2,000 for a data protection breach linked to mass email sending. Using CC instead of BCC exposed recipients’ email addresses and could have compromised their identities. | ES | AEPD | GDPR | €2,000 | ↗ |
| 10 Jul 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 100,000 for repeatedly sending a former customer electronic notices about invoice availability. The authority found that the processing lacked a valid legal basis under GDPR Article 6.1. | ES | AEPD | GDPR | €100,000 | ↗ |
| 28 Jun 2023 | FESTINA LOTUS S.A.FESTINA LOTUS S.A. did not respond to requests to delete a user's account and personal data. The authority found a breach of Article 17 GDPR and imposed a fine of EUR 1,000. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 Jan 2022 | JEG'S LIFE STYLE, S.L.JEG'S LIFE STYLE, S.L. was fined by the AEPD 20,000 EUR for breaching data protection rules. The company disclosed private information about a former employee to third parties by email without consent. | ES | AEPD | GDPR | €20,000 | ↗ |
| 03 May 2022 | B.B.B.Y OTRO MAS C.B.The entity installed a video surveillance system without providing the required information to data subjects. The conduct breached Article 13 of the GDPR and resulted in a EUR 300 fine imposed by the AEPD. | ES | AEPD | GDPR | €300 | ↗ |
| 07 Jun 2023 | ELECTRAWORKS - CEUTA, S.A.ELECTRAWORKS - CEUTA, S.A. did not comply with a data deletion request and retained personal data for 10 years without proper justification. The AEPD found this to be a breach of Article 13 GDPR and imposed a 10,000 EUR fine. | ES | AEPD | GDPR | €10,000 | ↗ |
| 15 Oct 2012 | MYID ESPAÑA S.L.MYID ESPAÑA S.L. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited commercial emails despite requests to unsubscribe. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 22 Jun 2022 | B.B.B.An individual's personal data was used without consent to publish an online advertisement for sexual services, resulting in harassment. The responsible entity was fined for violating Article 6(1) of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 11 Jan 2017 | WIZINK BANK, S.A.WIZINK BANK, S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial emails despite a request to unsubscribe. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 17 Jun 2020 | LA CASA COMPROMETIDA, S.Coop.The entity was fined by the AEPD in the amount of 3,000 EUR for failing to comply with data protection rules regarding its website cookie policy. The case concerned deficiencies in the required information or consent related to cookies. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 11 Dec 2025 | UPGYMS IBERIA, S.L.UPGYMS IBERIA, S.L. was fined by the AEPD EUR 5,000 for sending unsolicited commercial SMS messages without obtaining recipient consent. The conduct breached the LSSI rules on marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 06 Sept 2022 | B.B.B.The entity failed to provide the information required under Article 13 GDPR when processing personal data. AEPD imposed a fine of EUR 2,000 for this breach. | ES | AEPD | GDPR | €2,000 | ↗ |
| 23 May 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD for assigning a customer's DNI to a third party. This enabled unauthorized access to personal data and invoices, constituting a data protection breach. | ES | AEPD | GDPR | €60,000 | ↗ |
| 24 Feb 2010 | INBORNTECH S.L.INBORNTECH S.L. was fined by the AEPD 1,200 EUR for sending an unsolicited commercial email. The authority found that the requirements of Article 21 of the LSSI were not met. | ES | AEPD | ePrivacy | €1,200 | ↗ |