Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Feb 2020VODAFONE ESPAÑA, S.A.U.The AEPD imposed a 50,000 EUR fine on VODAFONE ESPAÑA, S.A.U. for sending an SMS indicating a contract using incorrect personal data. The authority found a breach of Article 6 GDPR concerning the lawful basis for processing.ESAEPDGDPR€50,000
17 Oct 2019VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España, S.A.U. EUR 75,000 for incorrectly charging a customer's account and retaining inaccurate personal data. The case concerns breaches of data protection principles, including data accuracy and proper processing.ESAEPDGDPR€75,000
07 Aug 2024EXPANSION CONSULTING 2020, S.L.EXPANSION CONSULTING 2020, S.L. was fined by the AEPD in the amount of €4,000 for failing to provide access to personal data and the information requested by the data protection authority. The case concerned non-compliance with Article 58(1) GDPR.ESAEPDGDPR€4,000
29 Jan 2020COLEGIO ARENALES CARABANCHELThe school was fined by the AEPD 5,000 EUR for unlawfully sharing and publishing images of children without consent. The case involved a breach of data protection rules and the need for valid consent to process minors’ images.ESAEPDGDPR€5,000
01 Jan 2021Dña. B.B.B.The entity was fined for publishing personal images and contact numbers on a dating website without proper consent. The authority found a breach of Article 6(1) of the GDPR.ESAEPDGDPR€2,000
30 May 2012ESCUELA HIPICA OLIMPIA, S.L.ESCUELA HIPICA OLIMPIA, S.L. was fined by the AEPD EUR 1,200 for sending commercial emails after the individual requested deletion of personal data and cessation of advertising communications. The case concerns failure to respect the recipient’s opt-out and data erasure request.ESAEPDePrivacy€1,200
26 Jan 2021VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD 100,000 EUR for unlawfully registering a prepaid phone line under the complainant’s ID and accessing credit information without a legitimate interest. The company also failed to properly comply with requests for access to and deletion of personal data.ESAEPDGDPR€100,000
27 Apr 2023B.B.B.The entity installed a surveillance camera without informing tenants or obtaining their consent. The camera captured shared areas, which constituted a breach of data protection rules.ESAEPDGDPR€5,000
01 Jan 2016PROSAD CONSULTORES S.L.PROSAD CONSULTORES S.L. was fined by the AEPD EUR 800 for sending unsolicited commercial emails. The recipient had not given prior consent and was listed on the Robinson List, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€800
22 Feb 2023CONGREGACIÓN DEL SANTÍSIMO REDENTOR CURIA PROVINCIALThe entity was fined 500 EUR by the AEPD for installing a video surveillance system that could capture public areas without prior administrative authorization. The authority found this to be a breach of Article 5(1)(c) GDPR.ESAEPDGDPR€500
14 Sept 2011Asociación de Comerciantes, Empresarios y Profesionales ACTIVAThe entity was fined by the AEPD for sending unsolicited commercial emails without prior consent from recipients. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€1,200
02 Oct 2025EMAGISTER SERVICIOS DE FORMACIÓN, S.L.EMAGISTER SERVICIOS DE FORMACIÓN, S.L. was fined EUR 80,000 by the AEPD for a data security incident involving unauthorized processes on its web servers. The authority found a breach of data protection principles.ESAEPDGDPR€80,000
02 Apr 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 52,000 by the AEPD for sending SMS messages to a complainant about another customer's unpaid bills. The authority found that this disclosure breached data protection rules.ESAEPDGDPR€52,000
23 Dec 2024HYUNDAI MOTOR ESPAÑA S.L.U.HYUNDAI MOTOR ESPAÑA S.L.U. was fined EUR 2,000,000 by the AEPD for a data security incident. Unauthorized access to customer data occurred, breaching data protection principles.ESAEPDGDPR€2,000,000
22 Nov 2019CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union CSI-CSIF was fined EUR 3,000 by the AEPD for publishing an electoral census list containing personal data, including DNI numbers, in a public WhatsApp group. The authority found this breached data protection principles.ESAEPDGDPR€3,000
25 Jan 2023FUNDACIÓN GOODJOBFUNDACIÓN GOODJOB was fined EUR 2,000 by the AEPD. The authority found that the organization collected unnecessary health data related to disability without a proper legal basis, breaching data minimization principles.ESAEPDGDPR€2,000
20 Jul 2011VENTURA 24 S.L.VENTURA 24 S.L. was fined by the AEPD EUR 30,001 for continuing to send emails to a user after they requested cancellation of their data. The authority found this to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
31 Mar 2022FUNDACIÓ ESCOLA PRIVADA DE GESTIÓThe entity was fined by the AEPD 5,000 EUR for failing to implement adequate security measures under Article 32 of the GDPR. This deficiency led to a personal data breach.ESAEPDGDPR€5,000
10 Oct 2024FEDERAL NAJANAJANA, S.L.FEDERAL NAJANAJANA, S.L. was fined by the AEPD €2,000 for sending unsolicited commercial messages via WhatsApp without the recipient’s explicit consent. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€2,000
03 Dec 2020Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined by the AEPD 75,000 EUR for failing to properly verify the identity of individuals requesting changes in line ownership. This failure resulted in unauthorized access and processing of personal data.ESAEPDGDPR€75,000