Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Oct 2013SANITAS S.A.SANITAS S.A. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited commercial emails. The authority found that the required information clause was missing, which constitutes a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200
04 Nov 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD after a contract was entered into using another person's identity. The case concerns a breach of data protection rules and insufficient identity verification.ESAEPDGDPR€60,000
01 Jan 2016HAPPY SOCIAL MEDIA, LTDHAPPY SOCIAL MEDIA, LTD was fined by the AEPD EUR 3,400 for sending unsolicited marketing emails. The authority found that the messages did not include a simple opt-out mechanism, which breached the LSSI.ESAEPDePrivacy€3,400
15 Jul 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for requesting a disproportionate amount of personal data, including a copy of the DNI, to process a request for information about account movements. The authority found this to be a breach of the data minimization principle.ESAEPDGDPR€70,000
30 Jul 2021Mederos Moviten, S.L.Mederos Moviten, S.L. was fined by the AEPD 15,000 EUR for processing personal data without consent. Several unauthorized contracts were created using the complainant’s personal information, indicating unlawful use of personal data.ESAEPDGDPR€15,000
09 Jul 2021ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 50,000 EUR by the AEPD for failing to implement adequate security measures. The deficiency led to unauthorized bank transfers from a customer's account after a SIM card incident.ESAEPDGDPR€50,000
26 Jan 2022B.B.B.The entity installed a video surveillance system covering public transit areas without a justified cause. This breached data protection principles.ESAEPDGDPR€500
10 Feb 2021CEYLLE SOLUTIONS & DEVELOPMENT S.L.CEYLLE SOLUTIONS & DEVELOPMENT S.L. was fined by the AEPD in the amount of 2,000 EUR for disclosing personal data in emails sent to commercial partners. The authority found a breach of data protection rules.ESAEPDGDPR€2,000
15 Dec 2022BENOTAC, S.L.BENOTAC, S.L. was fined by the AEPD EUR 2,500 for operating a video surveillance system without proper signage and for capturing public areas without authorization. The authority also noted the sharing of recordings without the consent of the data subjects.ESAEPDGDPR€2,500
04 Feb 2020TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined 75,000 EUR by the AEPD for processing personal data without consent. The case concerned unauthorized portability of a phone line.ESAEPDGDPR€75,000
29 Sept 2020GABINETE PARAPSICOLÓGICO MYSTIC S.L.The entity was fined for sending unsolicited advertising SMS messages without the recipient's consent. This conduct breached Article 21 of the LSSI and constituted unlawful marketing communication.ESAEPDePrivacy€2,500
27 Jul 2011ASCENDIA REINGENIERIA&CONSULTING S.L.U.ASCENDIA REINGENIERIA&CONSULTING S.L.U. was fined by the AEPD €600 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€600
21 Oct 2013VIAJES INCENTIVE GOLF, S.L.VIAJES INCENTIVE GOLF, S.L. was fined by the AEPD 1,200 EUR for sending unsolicited emails. The authority also found that recipients' email addresses were not hidden, in breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200
04 Jun 2013UN LUGAR DIFERENTE. S.L.UN LUGAR DIFERENTE. S.L. was fined by the AEPD for sending unauthorized commercial SMS messages to a customer. The messages were sent despite the customer's prior request to opt out.ESAEPDePrivacy€600
19 Nov 2021Working Capital Management España, S.L.Working Capital Management España, S.L. was fined by the AEPD 40,000 EUR for unlawfully processing personal data. The company included an individual's data in a credit information system without a valid contract, in connection with an identity theft case.ESAEPDGDPR€40,000
21 Jul 2022WUNSCHURLAUB S.L.WUNSCHURLAUB S.L. was fined by the AEPD 3,000 EUR for storing user passwords in plain text and sending them by email without encryption. The authority found this breached GDPR Article 32 on appropriate security measures.ESAEPDGDPR€3,000
10 Jan 2026NAROBESA INV, S.L.NAROBESA INV, S.L. was fined 1,000 EUR by the AEPD for unlawfully accessing a job applicant's credit information without consent during recruitment. The conduct breached data protection rules and occurred in the hiring process.ESAEPDGDPR€1,000
07 Jun 2012HOTEL REY DON SANCHO S.A.HOTEL REY DON SANCHO S.A. was fined EUR 30,001 by the AEPD for continuing to send unsolicited commercial emails despite a request for data cancellation. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€30,001
01 Jan 2013LIBERBANK, S.A.LIBERBANK, S.A. was fined 1,200 EUR by the AEPD for sending commercial emails without prior consent from recipients. The authority found this to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200
14 Jun 2023B.B.B.The entity was fined EUR 300 by the AEPD for installing a camera on the exterior facade of a building, aimed at public space, without the required administrative authorization. The authority treated this as a breach of data protection rules.ESAEPDGDPR€300