BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Jan 2024 | CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD 3,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 GDPR, which requires clear notice to data subjects. | ES | AEPD | GDPR | €3,000 | ↗ |
| 01 Jan 2020 | CENTRO DE DIAGNÓSTICO ***LOCALIDAD.1, S.A.The entity was fined for breaching data confidentiality by improperly sharing medical information between different entities without consent. The case involved sensitive data processing and a lack of a valid legal basis for the disclosure. | ES | AEPD | GDPR | €10,000 | ↗ |
| 02 Nov 2022 | QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the AEPD for processing personal data without a valid legal basis and for failing to comply with data deletion requests. The violations concerned Articles 6 and 17 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 22 Oct 2013 | CIVESA 2005 SERVICIOS S LCIVESA 2005 SERVICIOS S L was fined EUR 600 by the AEPD for sending commercial emails to a user who had previously opted out. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 20 Aug 2025 | MOBILITY EVOLUTION S.A.MOBILITY EVOLUTION S.A. was fined EUR 15,000 by the AEPD for failing to properly process data deletion requests submitted through its application. The authority found that the company’s handling of these requests breached Article 25 GDPR on data protection by design and by default. | ES | AEPD | GDPR | €15,000 | ↗ |
| 28 Feb 2017 | DALMORRIS, S.L.DALMORRIS, S.L. was fined EUR 600 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which restricts this type of communication without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 17 Oct 2024 | OK MOBILITY ESPAÑA, S.L.OK MOBILITY ESPAÑA, S.L. was fined by the AEPD in the amount of 100,000 EUR for failing to respond to a data access request. The authority cited breaches of GDPR Articles 5(1)(e), 13, and 15. | ES | AEPD | GDPR | €100,000 | ↗ |
| 20 May 2022 | SERVICIOS PROFESIONALES LA PARADA S.L.The entity installed a video surveillance system that recorded public areas without informing the affected individuals. This breached data protection rules and led to a fine imposed by the AEPD. | ES | AEPD | GDPR | €800 | ↗ |
| 07 Sept 2021 | ***EMPRESA.1The entity was fined for failing to display visible signage informing individuals about video surveillance. The authority considered this a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 23 Mar 2021 | KUTXABANK, S.A.KUTXABANK, S.A. was fined EUR 100,000 by the AEPD for failing to properly handle a data deletion request. The issue affected the complainant’s ability to open a new account. | ES | AEPD | GDPR | €100,000 | ↗ |
| 29 Jan 2020 | B.B.B.The AEPD fined B.B.B. EUR 2,000 for using a phone number for a purpose other than the one for which it was originally collected. The authority found this to be a breach of the GDPR principle of purpose limitation. | ES | AEPD | GDPR | €2,000 | ↗ |
| 24 Jun 2021 | BAZTANDIS, S.L.BAZTANDIS, S.L. was fined EUR 1,000 by the AEPD for deficiencies in signage related to video surveillance. The authority found a breach of Article 13 GDPR concerning the information duties owed to individuals under surveillance. | ES | AEPD | GDPR | €1,000 | ↗ |
| 24 Mar 2023 | COMUNIDAD DE PROPIETARIOS ***DIRECCIÓN.1The homeowners’ association was fined 500 EUR by the AEPD for installing surveillance cameras aimed at public areas without prior administrative authorization. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €500 | ↗ |
| 06 Sept 2022 | MAE WEST SYSTEMS, S.L.MAE WEST SYSTEMS, S.L. was fined EUR 400 by the AEPD for failing to provide the required information on video surveillance signs. The authority found a breach of Article 13 GDPR because individuals under surveillance were not properly informed. | ES | AEPD | GDPR | €400 | ↗ |
| 01 Jan 2025 | AMADEUSAMADEUS was fined EUR 9,000,000 by the AEPD for breaching GDPR Articles 14 and 6. The authority found that the company failed to inform data subjects about the processing of their personal data. | ES | AEPD | GDPR | €9,000,000 | ↗ |
| 05 Dec 2024 | TMETME was fined EUR 200,000 by the AEPD for changing the ownership of a mobile line without consent and for issuing a duplicate SIM card without a valid legal basis. The authority found that these actions failed to meet the requirements for lawful processing and proper authorization of subscriber account changes. | ES | AEPD | GDPR | €200,000 | ↗ |
| 02 Jun 2022 | B.B.B.The entity was fined by the AEPD for improperly positioning surveillance cameras toward public areas without proper signage. This conduct breached data protection requirements. | ES | AEPD | GDPR | €1,000 | ↗ |
| 02 Jun 2016 | TELEFONICA MOVILES ESPAÑA, S.A.U.Telefónica Móviles España was fined €20,000 by the AEPD for using “supercookies” without properly informing users or obtaining their consent. The authority found this conduct to be in breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 03 Dec 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The AEPD imposed a EUR 200,000 fine on Banco Bilbao Vizcaya Argentaria, S.A. for processing personal data without a legal basis. The conduct included signing documents without consent and marking consent checkboxes for commercial purposes without authorization. | ES | AEPD | GDPR | €200,000 | ↗ |
| 16 Apr 2025 | 20 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined by the AEPD for the unauthorized dissemination of a video containing personal data. The authority found a breach of the data minimization principle under Article 5(1)(c) GDPR. | ES | AEPD | GDPR | €30,000 | ↗ |