Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2020JUST LANDED, S.L.JUST LANDED, S.L. was fined EUR 3,000 by the AEPD for failing to provide a privacy policy and a cookie policy on its website. The authority cited a breach of GDPR Article 13 and LSSI Article 22.2.ESAEPDePrivacy€3,000
04 Aug 2014SERVICIOS DE DEPILACION BLOC, S.L.SERVICIOS DE DEPILACION BLOC, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial SMS messages to a former client. The authority found that this conduct breached Article 21 of the LSSI on marketing communications.ESAEPDePrivacy€3,000
31 Jul 2012MEDIASTAY SASMEDIASTAY SAS was fined 30,001 EUR by the AEPD for sending commercial emails to a user despite requests to unsubscribe. The authority found a breach of Article 21.1 of the LSSI on unsolicited electronic communications.ESAEPDePrivacy€30,001
01 Jan 2024COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company was fined EUR 80,000 by the AEPD for processing a gas contract without the complainant's consent. It used personal data without authorization, which constitutes a breach of data protection law.ESAEPDGDPR€80,000
03 Aug 2022Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined EUR 70,000 by the AEPD for providing a SIM card duplicate to a third party without the data subject’s consent. The authority found this conduct to be a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
24 Jul 2024FREE TECHNOLOGIES EXCOM, S.L.FREE TECHNOLOGIES EXCOM, S.L. was fined by the AEPD 10,000 EUR for sending unencrypted emails containing user credentials without prior notice. The authority also noted the absence of two-factor authentication, which constituted a breach of Article 32 GDPR.ESAEPDGDPR€10,000
11 Dec 2019VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide the requested information. The case concerned a breach of obligations under data protection rules.ESAEPDGDPR€5,000
27 Sept 2016SERVIHABITAT SERVICIOS INMOBILIARIOS, S.L.SERVIHABITAT SERVICIOS INMOBILIARIOS, S.L. was fined by the AEPD EUR 2,000 for sending unsolicited commercial communications by email. The authority found this breached Article 21.1 of the LSSI.ESAEPDePrivacy€2,000
13 Sept 2024ARES CAPITAL, S.A.ARES CAPITAL, S.A. was fined by the AEPD for requiring employees to use personal phones for work together with continuous monitoring apps. The authority found that the company did not provide sufficient information about data collection, breaching GDPR rules on lawful basis, transparency, and data processing principles.ESAEPDGDPR€200,000
29 Mar 2023SOLAR PROGRESS, S.L.SOLAR PROGRESS, S.L. was fined 5,000 EUR by the AEPD for displaying an employee’s personal data on a company WhatsApp profile. The authority found a breach of data protection rules.ESAEPDGDPR€5,000
15 Dec 2023TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L.TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L. was fined by the AEPD in the amount of 5,000 EUR for breaching data protection rules. The company failed to honor a request to delete personal data and later sent commercial information to the complainant.ESAEPDGDPR€5,000
19 Sept 2024GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.GACM Seguros was fined 8,000 EUR by the AEPD for improperly sharing personal data related to an insurance claim with another insured party. The authority found a breach of data protection rules.ESAEPDGDPR€8,000
01 Jan 2019CAFE BAR NINA (Nina Cb)CAFE BAR NINA was fined €2,000 by the AEPD for installing an unauthorized surveillance camera. The conduct breached data protection requirements.ESAEPDGDPR€2,000
08 Sept 2014MUCHODESTINO, S.L.MUCHODESTINO, S.L. was fined by the AEPD €2,900 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€2,900
12 Feb 2021KUKIMBIA S.L.KUKIMBIA S.L. was fined EUR 3,000 by the AEPD for leaving documents containing personal data unattended. The authority found this to be a breach of data security obligations under Article 32(1) of the GDPR.ESAEPDGDPR€3,000
08 Oct 2010A.A.A.A.A.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The case concerned continued email marketing despite a request to be removed from the mailing list, in breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
14 Aug 2022INVERTIA TENERIFE 2019, S.L.INVERTIA TENERIFE 2019, S.L. was fined 2,000 EUR by the AEPD for failing to inform data subjects about the processing of their personal data. The authority treated this as a breach of Article 13 GDPR.ESAEPDGDPR€2,000
01 Jan 2024XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD for failing to ensure the security and confidentiality of personal data. The incident resulted in a data breach and created a risk of identity theft.ESAEPDGDPR€4,000,000
09 Jun 2023UNIÓN DE RADIOS LIBRES Y COMUNITARIAS DE MADRIDThe entity did not comply with a data protection authority resolution concerning the right to erasure. As a result, AEPD imposed a fine for breaching Article 58.2 of the GDPR.ESAEPDGDPR€1,000
06 Apr 2011VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD 30,001 EUR for continuing to send commercial emails and SMS messages to a complainant. The conduct continued despite requests to stop and objections to the processing of personal data for advertising purposes.ESAEPDePrivacy€30,001