Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2024GASEXPRESS PATRAIX, S.L.GASEXPRESS PATRAIX, S.L. was fined by the AEPD 25,000 EUR for allowing unauthorized access to previous users' data in its automated gas station system. The exposed information included DNI numbers and partial credit card numbers.ESAEPDGDPR€25,000
01 Jan 2019AMADOR RECREATIVOS, S.L.AMADOR RECREATIVOS, S.L. was fined by the AEPD 6,000 EUR for installing a video surveillance system aimed at public space without justified cause. The case concerned an unjustified scope of monitoring and a breach of data protection rules.ESAEPDGDPR€6,000
02 Feb 2023DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card without the complainant's consent. The incident led to attempts to gain unauthorized access to the complainant's bank accounts.ESAEPDGDPR€70,000
01 Jan 2015ALDA GLOBAL SERVICES, S.L.ALDA GLOBAL SERVICES, S.L. was fined EUR 600 by the AEPD. The case concerned sending unsolicited commercial communications by SMS without consent, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
15 Oct 2024TERRA, BRASA Y MAR, S.L.TERRA, BRASA Y MAR, S.L. was fined 500 EUR by the AEPD for adding the complainant's phone number to a WhatsApp group without consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€500
12 May 2023CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union sent an email containing personal data of election officials and representatives without their consent. AEPD found this to be a breach of data protection rules and imposed a 4,000 EUR fine.ESAEPDGDPR€4,000
01 Jan 2024AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD 2,000 EUR for improperly accessing personal data linked to a phone number without the owner's consent. The authority found a breach of Article 7 of the GDPR.ESAEPDGDPR€2,000
11 Sept 2025THE OBJECTIVE MEDIA, S.L.THE OBJECTIVE MEDIA, S.L. published an individual's personal data on its website without consent. The AEPD found this to be a breach of data protection principles and imposed a 20,000 EUR fine.ESAEPDGDPR€20,000
01 Jan 2015BANCO SANTANDER, S.A.Banco Santander was fined EUR 1,500 by the AEPD for sending unsolicited commercial emails to a recipient who had previously opted out. The authority found this to be a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,500
01 Jan 2024MAD COOL FESTIVAL, S.L.MAD COOL FESTIVAL, S.L. was fined 3,500 EUR by the AEPD for a data breach on its website. The incident exposed users’ personal data, indicating non-compliance with GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€3,500
04 Feb 2022CORON ISLAND SLUCORON ISLAND SLU was fined by the AEPD 2,000 EUR for requiring a customer’s phone number when issuing an invoice. The authority found that the data was not necessary for invoicing, which breached the data minimization principle.ESAEPDGDPR€2,000
03 Jul 2025BANCO INVERSIS, S.A.Banco Inversis, S.A. was fined by the AEPD in the amount of 10,000 EUR for a personal data breach. The case involved unauthorized access to personal data, which breached Article 5(1)(f) of the GDPR.ESAEPDGDPR€10,000
22 Mar 2018ARGOINFOR S.L.ARGOINFOR S.L. was fined by the AEPD in the amount of 1,000 EUR. The case concerned the sending of unsolicited commercial emails, which breaches Article 21 of the LSSI.ESAEPDePrivacy€1,000
08 Aug 2024OAC LOGÍSTICA, S.L.OAC LOGÍSTICA, S.L. was fined by the AEPD in the amount of EUR 600 for failing to provide access. The breach concerned Article 58(1) of the GDPR.ESAEPDGDPR€600
07 Oct 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for unauthorized remote management of a former employee's personal device. The authority found that the conduct breached the principles of lawful personal data processing.ESAEPDGDPR€200,000
11 Apr 2025AIRE NETWORKS DEL MEDITERRÁNEO, S.L.The AEPD fined AIRE NETWORKS DEL MEDITERRÁNEO, S.L. 100,000 EUR for a data security incident. A SIM card duplication enabled unauthorized bank transactions, indicating insufficient safeguards and access controls.ESAEPDGDPR€100,000
25 Apr 2016HAPPY SOCIAL MEDIA LTDHAPPY SOCIAL MEDIA LTD was fined EUR 1,400 by the AEPD. The case concerned sending unsolicited commercial emails without providing a simple and free opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€1,400
04 Feb 2016DIVULGACION DINAMICA, S.L.DIVULGACION DINAMICA, S.L. was fined by the AEPD EUR 600 for sending commercial emails without prior consent from recipients. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€600
17 May 2021TELEFÓNICA DE ESPAÑA, S.A.U.Telefónica de España, S.A.U. was fined by the AEPD for using personal data to contract a service without the data subject’s consent and for listing the complainant in credit information files for a debt that was not recognized. The case concerns processing without a valid legal basis and improper reporting of alleged debt.ESAEPDGDPR€75,000
29 Aug 2014INTERNET OTT CHANNELS S.L.INTERNET OTT CHANNELS S.L. was fined by the AEPD in the amount of 1,400 EUR for sending unsolicited commercial emails to a user who had opted out. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,400