Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Nov 2019HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined by the AEPD 60,000 EUR for sending a patient's medical report to an insurance company without proper consent. The case concerns a breach of data protection rules and the special protection applicable to health data.ESAEPDGDPR€60,000
20 Jun 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD €65,000 for improper handling of personal data. The company failed to notify the rectification or deletion of personal data, which led to unwarranted debt collection calls.ESAEPDGDPR€65,000
23 Jan 2024CAJA RURAL DE ZAMORA COOPERATIVA DE CRÉDITOCAJA RURAL DE ZAMORA was fined by the AEPD EUR 15,000 for a personal data breach. The incident affected the confidentiality and integrity of personal data, breaching GDPR Article 5(1)(f).ESAEPDGDPR€15,000
29 Jul 2013ENDESA, S.A.ENDESA, S.A. was fined EUR 600 by the AEPD for sending commercial emails to a former customer despite requests to delete personal data. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
22 Apr 2022DISPLAY CONNECTORS, S.LDISPLAY CONNECTORS, S.L was fined EUR 300,000 by the AEPD for automatically publishing videos containing personal data without first ensuring the processing was lawful. The authority found this conduct breached data protection rules.ESAEPDGDPR€300,000
27 Sept 2022ALBERO FORTE COMPOSITE, S.L.The company used employees’ facial images for clocking in and out without proper notice about biometric data processing. AEPD found this to be a breach of data protection rules and imposed a 20,000 EUR fine.ESAEPDGDPR€20,000
01 Mar 2023ILUROBOX, S.L.ILUROBOX, S.L. was fined by the AEPD EUR 3,000 for including individuals in a WhatsApp group without their consent. The authority found that this breached Article 6(1) GDPR because there was no lawful basis for the processing.ESAEPDGDPR€3,000
16 Nov 2010INGORA SERAI S.L.INGORA SERAI S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits unsolicited marketing communications.ESAEPDePrivacy€600
01 Jan 2013GOOGLE INCGoogle Inc. was fined by the AEPD EUR 130,000 for failing to provide adequate information on privacy and cookie policies on a website. The authority found a breach of the LSSI information requirements toward users.ESAEPDePrivacy€130,000
28 Jun 2022ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. failed to provide the required information to the Spanish Data Protection Agency, which constitutes a breach of Article 58.1 of the GDPR. The AEPD imposed a fine of 3,000 EUR.ESAEPDGDPR€3,000
15 Apr 2025COLPER BUSINESS 2020 S.L.COLPER BUSINESS 2020 S.L. was fined by the AEPD EUR 20,000 for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR.ESAEPDGDPR€20,000
11 Jan 2023AXEL SPRINGER ESPAÑA S.AAXEL SPRINGER ESPAÑA S.A was fined 5,000 EUR by the AEPD for non-compliance with data protection rules in its cookie policy. The website required users to disable providers individually and did not offer an option to disable all cookies at once.ESAEPDePrivacy€5,000
20 Jan 2015SYNERTEC GROUP S.L.SYNERTEC GROUP S.L. was fined by the AEPD in the amount of €52,000 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€52,000
12 May 2021E4LEGAL ANALYTICS, S.L. (EMÉRITA LEGAL)E4LEGAL ANALYTICS, S.L. was fined by the AEPD EUR 3,100,000 for processing personal data from judicial sentences without proper authorization. The case concerned the reuse of data in a way that may have breached data protection rules and restrictions on further use.ESAEPDGDPR€3,100,000
17 May 2021VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 80,000 EUR for processing personal data without proper consent. The case involved linking phone lines to incorrect data and enrolling a customer in services without authorization.ESAEPDGDPR€80,000
01 Jan 2013OPEN COMUNICACION, S.L.OPEN COMUNICACION, S.L. was fined by the AEPD in the amount of 30,001 EUR for sending numerous unsolicited advertising emails without prior express consent from recipients. The authority also found that the company failed to provide an effective system for recipients to object to such messages, in breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
25 Feb 2022DIGITAL CONTENT DISTRIBUTION LTD.DIGITAL CONTENT DISTRIBUTION LTD. was fined by the AEPD EUR 100 for sending marketing emails without the recipient's consent. The conduct breached Article 21 of the LSSI on electronic commercial communications.ESAEPDePrivacy€100
01 Jan 2019XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 60,000 by the AEPD for processing personal data without a legal basis. The authority found a breach of Article 6 GDPR, meaning the processing lacked a lawful basis.ESAEPDGDPR€60,000
20 Dec 2025KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD 5,000 EUR for processing personal data without a legal basis. The case concerned debt collection related to a loan that the complainant had neither consented to nor requested.ESAEPDGDPR€5,000
16 Jun 2023BORSA MEDIC, S.L.BORSA MEDIC, S.L. was fined 10,000 EUR by the AEPD for failing to comply with a data deletion request and for sending unsolicited advertising emails after the recipient objected. The case concerns breaches of data protection and electronic commerce rules.ESAEPDePrivacy€10,000