Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2024SANTANDER CONSUMER FINANCE, S.A.Santander Consumer Finance, S.A. was fined by the AEPD 500,000 EUR for a data protection breach. The incident affected personal identification and contact data of 28,120 individuals.ESAEPDGDPR€500,000
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the original user's consent. The incident led to unauthorized access to personal and banking data.ESAEPDGDPR€200,000
01 Jan 2024CIBERSEO JAÉN, S.L.CIBERSEO JAÉN, S.L. was fined EUR 1,500 by the AEPD for publishing a photograph of an individual without consent on a job search website. The case concerned processing personal data without a lawful basis, contrary to Article 6 of the GDPR.ESAEPDGDPR€1,500
01 Jan 2024B.B.B.B.B.B. was fined by the AEPD in the amount of 10,000 EUR for publishing a patient's medical photos on social media without consent. The conduct breached GDPR Articles 6(1) and 9, which govern lawful processing and special categories of personal data.ESAEPDGDPR€10,000
01 Jan 2024TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD for issuing a duplicate SIM card without proper consent or identity verification. The failure enabled identity theft and fraudulent transactions.ESAEPDGDPR€300,000
01 Jan 2024ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. was fined by the AEPD EUR 140,000 for unauthorized access to personal data. The authority found a breach of GDPR confidentiality and security principles.ESAEPDGDPR€140,000
01 Jan 2024FRESHLY COSMETICS, S.L.FRESHLY COSMETICS, S.L. was fined by the AEPD EUR 10,000 for using advertising cookies on its website without user consent. The authority found this breached Article 22.2 of the LSSI.ESAEPDePrivacy€10,000
01 Jan 2024VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 200,000 EUR by the AEPD for issuing a duplicate SIM card without the customer’s consent. The incident led to unauthorized financial transactions, indicating significant failures in authorization and security controls.ESAEPDGDPR€200,000
01 Jan 2024IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined by the AEPD for failing to ensure the integrity and confidentiality of personal data and for conducting an inadequate risk analysis and impact assessment. The deficiencies led to data breaches involving third-party systems, indicating weaknesses in operational and oversight controls.ESAEPDGDPR€1,040,000
01 Jan 2024ENDESA ENERGIA, S.A.U.ENDESA ENERGIA, S.A.U. was fined €200,000 by the AEPD for changing the contract holder and bank account without consent. The authority found a breach of data protection principles.ESAEPDGDPR€200,000
01 Jan 2024EMPRENDEDORES ONLINE, LLCEMPRENDEDORES ONLINE, LLC was fined by the AEPD 10,000 EUR for recording and sharing course participants’ personal data without consent. The authority found a breach of GDPR Articles 5(1)(f) and 6(1), indicating unlawful processing and insufficient legal basis.ESAEPDGDPR€10,000
01 Jan 2024B.B.B.The entity “Amor Ideal”, a personal relationship agency, was fined EUR 600 by the AEPD. The authority found that it failed to provide the required information about personal data processing, which constitutes a breach of Article 13 GDPR.ESAEPDGDPR€600
01 Jan 2024CAIXABANK, S.A.CAIXABANK was fined by the AEPD for sending a privacy policy update to a non-client. The authority found that the stated legitimate-interest basis for processing did not have proper consent support.ESAEPDGDPR€200,000
01 Jan 2024MAKING SOLUTIONS, S.L. (MY PERFECT WEDDING)MAKING SOLUTIONS, S.L. (MY PERFECT WEDDING) was fined 1,000 EUR by the AEPD. The authority found a breach of Article 15 GDPR for failing to provide an individual with access to their personal data.ESAEPDGDPR€1,000
01 Jan 2024GESTERNOVA, S.A.GESTERNOVA, S.A. was fined by the AEPD in the amount of 220,000 EUR for processing personal data without a valid legal basis. The authority also found that the company failed to provide the required information to the data subject, in breach of GDPR Articles 6(1), 13, and 14.ESAEPDGDPR€220,000
01 Jan 2024HIGHCLIFFE ESTATES MARBELLA, S.L.HIGHCLIFFE ESTATES MARBELLA, S.L. was fined by the AEPD 8,500 EUR for publishing personal data, including names and images, on its website without the data subjects’ consent. The authority found this to be a breach of Article 6(1) GDPR.ESAEPDGDPR€8,500
01 Jan 2024VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España 200,000 EUR for processing personal data without meeting the legal requirements of Article 6(1) GDPR. The case was linked to a fraudulent SIM card swap that resulted in unauthorized bank transfers.ESAEPDGDPR€200,000
01 Jan 2024BONTECU DISTRIBUCIONES, S.L.U.BONTECU DISTRIBUCIONES, S.L.U. was fined by the AEPD for processing personal data without consent and for failing to have proper data processing agreements in place. The case concerned a complainant who received an unsolicited contract from Factor Energía.ESAEPDGDPR€25,000
01 Jan 2024VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for processing personal data without consent. The case involved duplicating a SIM card without the user's authorization, which led to unauthorized bank transactions.ESAEPDGDPR€200,000
01 Jan 2024ORANGE BANK, S.A. SUCURSAL EN ESPAÑAOrange Bank was fined for a security breach that exposed personal data. The authority found a violation of Article 5(1)(f) of the GDPR.ESAEPDGDPR€1,500,000