BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2024 | SANTANDER CONSUMER FINANCE, S.A.Santander Consumer Finance, S.A. was fined by the AEPD 500,000 EUR for a data protection breach. The incident affected personal identification and contact data of 28,120 individuals. | ES | AEPD | GDPR | €500,000 | ↗ |
| 01 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the original user's consent. The incident led to unauthorized access to personal and banking data. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | CIBERSEO JAÉN, S.L.CIBERSEO JAÉN, S.L. was fined EUR 1,500 by the AEPD for publishing a photograph of an individual without consent on a job search website. The case concerned processing personal data without a lawful basis, contrary to Article 6 of the GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 01 Jan 2024 | B.B.B.B.B.B. was fined by the AEPD in the amount of 10,000 EUR for publishing a patient's medical photos on social media without consent. The conduct breached GDPR Articles 6(1) and 9, which govern lawful processing and special categories of personal data. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD for issuing a duplicate SIM card without proper consent or identity verification. The failure enabled identity theft and fraudulent transactions. | ES | AEPD | GDPR | €300,000 | ↗ |
| 01 Jan 2024 | ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. was fined by the AEPD EUR 140,000 for unauthorized access to personal data. The authority found a breach of GDPR confidentiality and security principles. | ES | AEPD | GDPR | €140,000 | ↗ |
| 01 Jan 2024 | FRESHLY COSMETICS, S.L.FRESHLY COSMETICS, S.L. was fined by the AEPD EUR 10,000 for using advertising cookies on its website without user consent. The authority found this breached Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 01 Jan 2024 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 200,000 EUR by the AEPD for issuing a duplicate SIM card without the customer’s consent. The incident led to unauthorized financial transactions, indicating significant failures in authorization and security controls. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined by the AEPD for failing to ensure the integrity and confidentiality of personal data and for conducting an inadequate risk analysis and impact assessment. The deficiencies led to data breaches involving third-party systems, indicating weaknesses in operational and oversight controls. | ES | AEPD | GDPR | €1,040,000 | ↗ |
| 01 Jan 2024 | ENDESA ENERGIA, S.A.U.ENDESA ENERGIA, S.A.U. was fined €200,000 by the AEPD for changing the contract holder and bank account without consent. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | EMPRENDEDORES ONLINE, LLCEMPRENDEDORES ONLINE, LLC was fined by the AEPD 10,000 EUR for recording and sharing course participants’ personal data without consent. The authority found a breach of GDPR Articles 5(1)(f) and 6(1), indicating unlawful processing and insufficient legal basis. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | B.B.B.The entity “Amor Ideal”, a personal relationship agency, was fined EUR 600 by the AEPD. The authority found that it failed to provide the required information about personal data processing, which constitutes a breach of Article 13 GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 01 Jan 2024 | CAIXABANK, S.A.CAIXABANK was fined by the AEPD for sending a privacy policy update to a non-client. The authority found that the stated legitimate-interest basis for processing did not have proper consent support. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | MAKING SOLUTIONS, S.L. (MY PERFECT WEDDING)MAKING SOLUTIONS, S.L. (MY PERFECT WEDDING) was fined 1,000 EUR by the AEPD. The authority found a breach of Article 15 GDPR for failing to provide an individual with access to their personal data. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 Jan 2024 | GESTERNOVA, S.A.GESTERNOVA, S.A. was fined by the AEPD in the amount of 220,000 EUR for processing personal data without a valid legal basis. The authority also found that the company failed to provide the required information to the data subject, in breach of GDPR Articles 6(1), 13, and 14. | ES | AEPD | GDPR | €220,000 | ↗ |
| 01 Jan 2024 | HIGHCLIFFE ESTATES MARBELLA, S.L.HIGHCLIFFE ESTATES MARBELLA, S.L. was fined by the AEPD 8,500 EUR for publishing personal data, including names and images, on its website without the data subjects’ consent. The authority found this to be a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €8,500 | ↗ |
| 01 Jan 2024 | VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España 200,000 EUR for processing personal data without meeting the legal requirements of Article 6(1) GDPR. The case was linked to a fraudulent SIM card swap that resulted in unauthorized bank transfers. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | BONTECU DISTRIBUCIONES, S.L.U.BONTECU DISTRIBUCIONES, S.L.U. was fined by the AEPD for processing personal data without consent and for failing to have proper data processing agreements in place. The case concerned a complainant who received an unsolicited contract from Factor Energía. | ES | AEPD | GDPR | €25,000 | ↗ |
| 01 Jan 2024 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for processing personal data without consent. The case involved duplicating a SIM card without the user's authorization, which led to unauthorized bank transactions. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2024 | ORANGE BANK, S.A. SUCURSAL EN ESPAÑAOrange Bank was fined for a security breach that exposed personal data. The authority found a violation of Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €1,500,000 | ↗ |