Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Jan 2021STOCKHUNTERS, S.L.STOCKHUNTERS, S.L. was fined EUR 4,000 by the AEPD for failing to comply with GDPR Article 13. The authority found that the website privacy policy did not meet the required information standards.ESAEPDGDPR€4,000
17 Mar 2021VASCO ANDALUZA DE INVERSIONES, S.L.VASCO ANDALUZA DE INVERSIONES, S.L. was fined by the AEPD 2,000 EUR for unlawfully sharing personal data with third parties without informing the data subject. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
14 Sept 2018IAHORRO BUSINESS SOLUTIONS SLIAHORRO BUSINESS SOLUTIONS SL was fined by the AEPD €1,000 for sending unsolicited commercial electronic communications. The company also failed to provide a procedure for exercising rights of access, rectification, cancellation, or objection.ESAEPDePrivacy€1,000
21 May 2024BANCO CETELEM, S.A.Banco Cetelem, S.A. was fined by the AEPD 250,000 EUR for unauthorized processing of personal data. The case included charging the complainant’s bank account for a loan taken out by an unknown third party without consent.ESAEPDGDPR€250,000
23 Mar 2021ABANCA CORPORACIÓN BANCARIA, S.A.ABANCA CORPORACIÓN BANCARIA, S.A. was fined EUR 5,000 by the AEPD for using cookies on its website without providing the required information to users or obtaining their consent. The case concerns failures to meet legal notice and consent requirements.ESAEPDePrivacy€5,000
26 Sept 2022ECOMM MOVADGENCY S.L.ECOMM MOVADGENCY S.L. was fined by the AEPD for sending commercial communications without the recipient’s consent. The company continued sending emails despite the recipient’s objection, which breached Article 21 GDPR.ESAEPDGDPR€1,000
01 Jan 2022GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the AEPD for processing a broad range of delivery riders’ personal data without adequate data protection measures. The authority found breaches of GDPR Articles 25 and 32, relating to privacy by design and processing security.ESAEPDGDPR€550,000
01 Jan 2022BANQUETES SANTA ANA, S.L.BANQUETES SANTA ANA, S.L. was fined EUR 5,000 by the AEPD for collecting personal data, including DNI numbers, from wedding guests without providing information about data processing. The authority found a breach of data minimization and transparency obligations.ESAEPDGDPR€5,000
29 Apr 2021CRIQUET PUBLICIDAD, S.L.CRIQUET PUBLICIDAD, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails. The recipient’s address was registered on the Robinson List, which constitutes a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
16 Jan 2020VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined 120,000 EUR by the AEPD for unlawful processing of personal data. The case involved threatening to include a minor's data in a credit file over an alleged unpaid debt.ESAEPDGDPR€120,000
23 Jan 2023FRESHLY COSMETICS, S.L.FRESHLY COSMETICS, S.L. was fined EUR 5,000 by the AEPD for failing to provide a cookie notice on its website. The authority also found that non-essential cookies were used without prior user consent, in breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
23 Feb 2024ENERGY WINNER, S.L.ENERGY WINNER, S.L. was fined EUR 600 by the AEPD. The case concerned the failure to provide access to personal data and information requested by the data protection authority, which constitutes a breach of Article 58.1 GDPR.ESAEPDGDPR€600
23 May 2022EL DIARIO DE PRENSA DIGITAL, S.L.EL DIARIO DE PRENSA DIGITAL, S.L. was fined by the AEPD 50,000 EUR for publishing audio of a victim's testimony in a high-profile court case. The authority found a breach of the GDPR data minimization principle.ESAEPDGDPR€50,000
11 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD EUR 150,000 for processing personal data without proper authorization. The case involved a fraudulent contract created using the complainant’s identity, and the authority found that the company did not adequately verify the identity of the person entering into the contract.ESAEPDGDPR€150,000
01 Jan 2019QUESERIA ARTESANAL AMECO S.L.QUESERIA ARTESANAL AMECO S.L. was fined by the AEPD 5,000 EUR for processing personal data without consent. Customers were unaware of how their data had been obtained, indicating a breach of transparency and lawful processing requirements.ESAEPDGDPR€5,000
01 Jan 2021ORANGE ESPAÑA VIRTUAL, S.L.SIMYO was fined for failing to adequately protect personal data, which enabled unauthorized SIM card duplication. The incident led to fraudulent bank transactions and indicates significant security shortcomings.ESAEPDGDPR€70,000
07 Feb 2025ESTUDIO ALCAZAR DEL GENIL 2022, S.L.ESTUDIO ALCAZAR DEL GENIL 2022, S.L. was fined EUR 10,000 by the AEPD for collecting and storing personal data taken from mailboxes without consent or notice to the data subjects. The authority found breaches of the lawful basis and transparency requirements under GDPR Articles 6(1) and 14.ESAEPDGDPR€10,000
15 Jun 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD for continuing to pursue a debt that had already been settled. The authority treated this as a breach of data protection rules.ESAEPDGDPR€50,000
02 Oct 2023COMUNIDAD DE PROPIETARIOS A.A.A.The president of a homeowners' association shared a bank receipt containing personal data in a WhatsApp group. AEPD found a breach of confidentiality principles under GDPR and imposed a EUR 2,000 fine.ESAEPDGDPR€2,000
01 Jan 2014BONANZA DIGITAL SERVICES S.L.BONANZA DIGITAL SERVICES S.L. was fined by the AEPD 8,000 EUR for sending unsolicited SMS messages promoting “Tarot del Alba”. The company did not provide an opt-out mechanism, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€8,000