Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Feb 2013ROTULACION Y DISEÑO ALBACETE S.L.The entity was fined for sending unsolicited commercial emails and for failing to provide the required data protection information on its website. The case concerns breaches of information duties and rules on marketing communications.ESAEPDePrivacy€1,200
03 Nov 2021B.B.B.The entity was fined by the AEPD 10,000 EUR for publishing the complainant's phone number on a website without consent. This led to unwanted calls, and despite requests for removal, the number reappeared, breaching GDPR Article 6.ESAEPDGDPR€10,000
01 Jan 2019Xfera Móviles, S.A.Xfera Móviles, S.A. was fined by the AEPD 70,000 EUR for the unauthorized disclosure of personal data caused by an error. The authority found a breach of the GDPR principle of integrity and confidentiality.ESAEPDGDPR€70,000
01 Jan 2016WIZINK BANK S.A.WIZINK BANK S.A. was fined by the AEPD €4,100 for sending unsolicited commercial communications by electronic means. The authority found that the legal requirements for such communications were not met.ESAEPDePrivacy€4,100
25 Jul 2019VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined by the AEPD 60,000 EUR for failing to ensure adequate security of personal data. The breach resulted in unauthorized or unlawful processing, indicating deficiencies in security controls.ESAEPDGDPR€60,000
23 Jan 2024CAJA RURAL DE NAVARRA, S.C.C.CAJA RURAL DE NAVARRA was fined EUR 20,000 by the AEPD for a personal data breach. The incident compromised the confidentiality and integrity of personal data, breaching Article 5(1)(f) of the GDPR.ESAEPDGDPR€20,000
30 May 2011CABLEUROPA, S.A.U.CABLEUROPA, S.A.U. was fined EUR 600 by the AEPD for continuing to send advertising communications to an individual after repeated requests for data cancellation. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
08 Apr 2022CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined EUR 1,000 by the AEPD for sending a commercial SMS to an individual who had already exercised the right to erasure. The authority found this conduct to be a breach of data protection rules.ESAEPDePrivacy€1,000
01 Jan 2024SUPERVISTA OPTICS SLUSUPERVISTA OPTICS SLU was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a user who had previously opted out. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€20,000
07 Jul 2022B.B.B.The entity installed a surveillance camera without proper signage, covering common areas. This breached the data protection rights of affected individuals and the applicable transparency requirements.ESAEPDGDPR€600
01 Jan 2021RODALI GESTIÓN INMOBILIARIA, S.L.RODALI GESTIÓN INMOBILIARIA, S.L. was fined by the AEPD 5,000 EUR for failing to provide clients with information about the processing of their personal data. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€5,000
04 Oct 2025OVH HISPANO, S.L.U.OVH HISPANO, S.L.U. was fined by the AEPD 120,000 EUR for a data protection breach. Confidential emails and documents of third parties were improperly shared due to inadequate data protection measures.ESAEPDGDPR€120,000
06 Sept 2024GESTIÓN DE VENTAS IBERIA S.L.GESTIÓN DE VENTAS IBERIA S.L. was fined 4,000 EUR by the AEPD for failing to provide access as required under Article 58.1 of the GDPR. The case concerns non-compliance with a supervisory authority request.ESAEPDGDPR€4,000
18 Jun 2021IZA OBRAS Y PROMOCIONES, S.A.IZA OBRAS Y PROMOCIONES, S.A. was fined by the AEPD 50,000 EUR for disclosing an employee’s health data and personal email address without consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€50,000
01 Jan 2018PROSAD CONSULTORES, S.L.PROSAD CONSULTORES, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited promotional emails without prior consent. The conduct breached Article 21.1 of the LSSI on electronic commercial communications.ESAEPDePrivacy€1,000
07 Mar 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card to a third party without proper identity verification. The incident enabled unauthorized access to a bank account and resulted in financial loss.ESAEPDGDPR€70,000
02 Jun 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for improper handling of personal data. A complaint revealed discrepancies in the data linked to a customer's identity, and the penalty was reduced due to early payment.ESAEPDGDPR€50,000
27 Apr 2022B.B.B.The entity was fined by the AEPD in the amount of EUR 300 for improperly positioning a surveillance camera. The authority found that the device could capture a private parking area and personal data without sufficient justification.ESAEPDGDPR€300
08 Jul 2022SISTEMAS TUBULARES DE INGENIERÍA CANARIAS, S.L.SISTEMAS TUBULARES DE INGENIERÍA CANARIAS, S.L. was fined by the AEPD 2,000 EUR for breaching data retention and confidentiality principles. The company improperly used personal data to file a police report and shared it with multiple parties.ESAEPDGDPR€2,000
23 Mar 2023B.B.B.B.B.B. was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial emails after a request for data deletion. The conduct breached Article 21 of the LSSI on marketing communications without consent.ESAEPDePrivacy€2,000