BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Oct 2013 | SANITAS S.A.SANITAS S.A. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited commercial emails. The authority found that the required information clause was missing, which constitutes a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 04 Nov 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD after a contract was entered into using another person's identity. The case concerns a breach of data protection rules and insufficient identity verification. | ES | AEPD | GDPR | €60,000 | ↗ |
| 01 Jan 2016 | HAPPY SOCIAL MEDIA, LTDHAPPY SOCIAL MEDIA, LTD was fined by the AEPD EUR 3,400 for sending unsolicited marketing emails. The authority found that the messages did not include a simple opt-out mechanism, which breached the LSSI. | ES | AEPD | ePrivacy | €3,400 | ↗ |
| 15 Jul 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for requesting a disproportionate amount of personal data, including a copy of the DNI, to process a request for information about account movements. The authority found this to be a breach of the data minimization principle. | ES | AEPD | GDPR | €70,000 | ↗ |
| 30 Jul 2021 | Mederos Moviten, S.L.Mederos Moviten, S.L. was fined by the AEPD 15,000 EUR for processing personal data without consent. Several unauthorized contracts were created using the complainant’s personal information, indicating unlawful use of personal data. | ES | AEPD | GDPR | €15,000 | ↗ |
| 09 Jul 2021 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 50,000 EUR by the AEPD for failing to implement adequate security measures. The deficiency led to unauthorized bank transfers from a customer's account after a SIM card incident. | ES | AEPD | GDPR | €50,000 | ↗ |
| 26 Jan 2022 | B.B.B.The entity installed a video surveillance system covering public transit areas without a justified cause. This breached data protection principles. | ES | AEPD | GDPR | €500 | ↗ |
| 10 Feb 2021 | CEYLLE SOLUTIONS & DEVELOPMENT S.L.CEYLLE SOLUTIONS & DEVELOPMENT S.L. was fined by the AEPD in the amount of 2,000 EUR for disclosing personal data in emails sent to commercial partners. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 15 Dec 2022 | BENOTAC, S.L.BENOTAC, S.L. was fined by the AEPD EUR 2,500 for operating a video surveillance system without proper signage and for capturing public areas without authorization. The authority also noted the sharing of recordings without the consent of the data subjects. | ES | AEPD | GDPR | €2,500 | ↗ |
| 04 Feb 2020 | TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined 75,000 EUR by the AEPD for processing personal data without consent. The case concerned unauthorized portability of a phone line. | ES | AEPD | GDPR | €75,000 | ↗ |
| 29 Sept 2020 | GABINETE PARAPSICOLÓGICO MYSTIC S.L.The entity was fined for sending unsolicited advertising SMS messages without the recipient's consent. This conduct breached Article 21 of the LSSI and constituted unlawful marketing communication. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 27 Jul 2011 | ASCENDIA REINGENIERIA&CONSULTING S.L.U.ASCENDIA REINGENIERIA&CONSULTING S.L.U. was fined by the AEPD €600 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €600 | ↗ |
| 21 Oct 2013 | VIAJES INCENTIVE GOLF, S.L.VIAJES INCENTIVE GOLF, S.L. was fined by the AEPD 1,200 EUR for sending unsolicited emails. The authority also found that recipients' email addresses were not hidden, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 04 Jun 2013 | UN LUGAR DIFERENTE. S.L.UN LUGAR DIFERENTE. S.L. was fined by the AEPD for sending unauthorized commercial SMS messages to a customer. The messages were sent despite the customer's prior request to opt out. | ES | AEPD | ePrivacy | €600 | ↗ |
| 19 Nov 2021 | Working Capital Management España, S.L.Working Capital Management España, S.L. was fined by the AEPD 40,000 EUR for unlawfully processing personal data. The company included an individual's data in a credit information system without a valid contract, in connection with an identity theft case. | ES | AEPD | GDPR | €40,000 | ↗ |
| 21 Jul 2022 | WUNSCHURLAUB S.L.WUNSCHURLAUB S.L. was fined by the AEPD 3,000 EUR for storing user passwords in plain text and sending them by email without encryption. The authority found this breached GDPR Article 32 on appropriate security measures. | ES | AEPD | GDPR | €3,000 | ↗ |
| 10 Jan 2026 | NAROBESA INV, S.L.NAROBESA INV, S.L. was fined 1,000 EUR by the AEPD for unlawfully accessing a job applicant's credit information without consent during recruitment. The conduct breached data protection rules and occurred in the hiring process. | ES | AEPD | GDPR | €1,000 | ↗ |
| 07 Jun 2012 | HOTEL REY DON SANCHO S.A.HOTEL REY DON SANCHO S.A. was fined EUR 30,001 by the AEPD for continuing to send unsolicited commercial emails despite a request for data cancellation. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 01 Jan 2013 | LIBERBANK, S.A.LIBERBANK, S.A. was fined 1,200 EUR by the AEPD for sending commercial emails without prior consent from recipients. The authority found this to be a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 14 Jun 2023 | B.B.B.The entity was fined EUR 300 by the AEPD for installing a camera on the exterior facade of a building, aimed at public space, without the required administrative authorization. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €300 | ↗ |