BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Feb 2024 | SOCIEDAD CONJUNTA PARA LA EMISIÓN Y GESTIÓN DE MEDIOS DE PAGO EFC SAIberia Cards was fined by the AEPD for failing to properly delete customer data after confirming cancellation. This caused issues when a former customer reapplied for a card. | ES | AEPD | GDPR | €20,000 | ↗ |
| 21 Feb 2024 | DIBEA ESTETIC, S.L.DIBEA ESTETIC, S.L. was fined EUR 7,000 by the AEPD for transferring personal data without the data subject’s consent. The authority found this conduct to be contrary to Article 6(1) of the GDPR. | ES | AEPD | GDPR | €7,000 | ↗ |
| 20 Feb 2024 | SPORT & SPA GEST, S.L.SPORT & SPA GEST, S.L. was fined by the AEPD 20,000 EUR for breaches of GDPR Articles 6(1), 13, 9, and 35. The case concerned improper data processing and insufficient information provided to users. | ES | AEPD | GDPR | €20,000 | ↗ |
| 19 Feb 2024 | DHL PARCEL IBERIA, S.L.U.DHL Parcel Iberia, S.L.U. was fined by the AEPD 5,000 EUR for failing to implement appropriate technical and organizational measures to ensure security appropriate to the risk, as required by Article 32 GDPR. As a result, personal data, including phone numbers, were exposed on shipping labels. | ES | AEPD | GDPR | €5,000 | ↗ |
| 19 Feb 2024 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 200,000 by the AEPD for processing personal data without a legal basis. The case concerned a phone number portability carried out without the user's consent, which breached the requirement for lawful processing. | ES | AEPD | GDPR | €200,000 | ↗ |
| 16 Feb 2024 | Anonymised (HDPA 6/2024)The company was fined 2,000 EUR by the HDPA for unlawful processing of personal data. It used vehicle tracking data outside working hours to locate an employee. | GR | HDPA | GDPR | €2,000 | ↗ |
| 15 Feb 2024 | Fiziska personaA monetary fine of 100 EUR was imposed by DVI on a natural person. The decision is final and has entered into force. | LV | DVI | GDPR | €100 | ↗ |
| 15 Feb 2024 | Dr TelemarketingBetween 11 February 2021 and 24 January 2022, 80,240 connected unsolicited marketing calls were made to subscribers registered with the TPS who had not consented to receive them. Two complaints were received, and the calls related to the Irish Lottery. The company stopped engaging with the Commissioner during the investigation and did not provide a satisfactory explanation for the Lotto Express calls. | GB | ICO | GDPR | €116,000 | ↗ |
| 14 Feb 2024 | ALL IN DIGITAL MARKETING SLALL IN DIGITAL MARKETING SL was fined by the AEPD €5,000 for continuing to send commercial emails despite repeated requests to unsubscribe. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 14 Feb 2024 | PRENSA IBÉRICA MEDIA S.L.PRENSA IBÉRICA MEDIA S.L. was fined by the AEPD in the amount of 5,000 EUR for failing to obtain proper user consent for cookies on its website. The authority found that this practice breached the LSSI requirements on cookies. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 13 Feb 2024 | DIGIMAN ALICANTE, S.L.DIGIMAN ALICANTE, S.L. was fined by the AEPD 1,000 EUR for operating a video surveillance system without the required signage. The authority found that the lack of notice breached the information obligations under GDPR Article 13. | ES | AEPD | GDPR | €1,000 | ↗ |
| 13 Feb 2024 | FACTOR ENERGÍA, S.A.FACTOR ENERGÍA, S.A. was fined by the AEPD 6,000 EUR for processing personal data without a legal basis, in breach of Article 6(1) GDPR. The company failed to communicate the termination of a gas contract and improperly shared personal data with other companies. | ES | AEPD | GDPR | €6,000 | ↗ |
| 13 Feb 2024 | LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD €10,000 for installing non-essential cookies on its website without obtaining valid user consent. The authority found this to be a breach of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 12 Feb 2024 | MEYDIS, S.L.MEYDIS, S.L. was fined EUR 80,000 by the AEPD for failing to provide required information during an investigation. The authority found a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €80,000 | ↗ |
| 08 Feb 2024 | AREIA CONSULTING, LTDAREIA CONSULTING, LTD was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial emails without prior recipient consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 08 Feb 2024 | Agenzia territoriale della Regione Puglia per il servizio di gestione dei rifiuti (AGER)The Garante fined Agenzia territoriale della Regione Puglia per il servizio di gestione dei rifiuti (AGER) EUR 6,000. The authority found that the organization failed to appoint a Data Protection Officer in a timely manner, despite the GDPR requirement being in force for about three years. | IT | Garante | GDPR | €6,000 | ↗ |
| 08 Feb 2024 | ADADE BURGOS, S.L.ADADE BURGOS, S.L. was fined by the AEPD 5,000 EUR for improper use of personal data. The company informed clients about an employee’s disciplinary dismissal in a manner that breached data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 08 Feb 2024 | Medtronic Italia S.p.a.Medtronic Italia S.p.a. was fined by the Garante in the amount of €300,000 for a data protection breach. The authority found inadequate technical and organizational measures that led to unauthorized disclosure of data. | IT | Garante | GDPR | €300,000 | ↗ |
| 07 Feb 2024 | Account Exchange SRLAccount Exchange SRL was fined EUR 2,000 by ANSPDCP for violating GDPR provisions related to data processing. The case concerned non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 07 Feb 2024 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe entity was fined by the AEPD 4,000 EUR for failing to provide access to personal data and the information requested by the data protection authority. The case concerns non-compliance with Article 58.1 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |