BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Jan 2014 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD in the amount of 30,001 EUR for sending unsolicited commercial SMS messages. The authority also found that the messages did not include information on how to revoke consent, in breach of Article 21.2 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 31 Mar 2017 | B.B.B.B.B.B. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The emails continued despite repeated requests from the recipient to stop, which breached the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 03 Jun 2013 | BBVA SERVICIOS, S.A.BBVA SERVICIOS, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent. This conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 02 Nov 2010 | VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial communications in breach of Article 21 of the LSSI. The infringement was classified as serious because a technical error resulted in 18 such messages being sent. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 13 Jan 2012 | QUOTATIS ESPAÑA S.L.QUOTATIS ESPAÑA S.L. was fined by the AEPD 30,001 EUR for sending unsolicited commercial emails despite requests to stop. The case concerned Article 21.1 of the LSSI, which prohibits such communications without prior consent. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 26 May 2010 | MATCHLESS, S.L.MATCHLESS, S.L. was fined by the AEPD 30,001 EUR for sending unsolicited commercial emails without prior recipient consent. The authority also found that the company failed to provide a simple and free mechanism for recipients to object to further communications, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 21 Oct 2010 | Baldomero **** y Jesús ***** CBBaldomero **** y Jesús ***** CB was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent from recipients. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 16 Sept 2010 | VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD 30,001 EUR for sending advertising messages to a customer who had previously opted out. The authority found this breached Article 21 of the LSSI on marketing communications without the recipient’s consent. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 27 Jul 2012 | VIPVENTA, S.L.VIPVENTA, S.L. was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails to the complainant. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 19 Jan 2023 | Sąd Rejonowy Szczecin-Centrum z siedzibą w Szczecinie przy ul.The UODO imposed an administrative fine of PLN 30,000 on the Szczecin-Centrum District Court. The authority found that appropriate technical and organizational measures were not implemented to match the risk of processing data using portable storage devices. | PL | UODO | GDPR | €6,374 | ↗ |
| 16 May 2023 | Dane anonimowe (Burmistrza Miasta Z.)UODO imposed an administrative fine of PLN 30,000 on the Mayor of City Z. and ordered the processing operations to be brought into compliance with the GDPR. The authority required appropriate technical and organizational measures, including regular testing, measuring, and evaluating their effectiveness to ensure processing security. | PL | UODO | GDPR | €6,687 | ↗ |
| 01 Jan 2023 | THE RED KIWI, S.L.THE RED KIWI, S.L. was fined 30,000 EUR by the AEPD. The breach involved adding clients’ phone numbers to a WhatsApp group without consent, which enabled unauthorized access to personal data. | ES | AEPD | GDPR | €30,000 | ↗ |
| 18 Apr 2022 | SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.The company changed the electricity and gas supplier without the customer's consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD. | ES | AEPD | GDPR | €30,000 | ↗ |
| 09 Sept 2022 | MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD for processing personal data without a lawful basis. The company failed to respond properly to a data access request and incorrectly linked an individual to insurance policies and claims. | ES | AEPD | GDPR | €30,000 | ↗ |
| 25 Oct 2021 | Anonymizováno (ÚOOÚ UOOU-00288/20-21)The entity was fined by the UOOU for sending unsolicited commercial communications by email without prior recipient consent. The conduct breached Czech rules on information society services. | CZ | UOOU | ePrivacy | €1,166 | ↗ |
| 18 Apr 2018 | Consorzio “Marte Euroservice”Consorzio “Marte Euroservice” was fined EUR 30,000 by the Garante for sending promotional emails without recipients’ consent. The company also exposed email addresses to multiple recipients, creating an additional data protection breach. | IT | Garante | GDPR | €30,000 | ↗ |
| 12 Feb 2026 | Sportitalia Società Sportiva Dilettantistica a.r.l.Sportitalia Società Sportiva Dilettantistica a.r.l. was fined EUR 30,000 by the Garante for violations related to the processing of personal data in promotional emails. The authority found that the company did not comply with GDPR requirements in connection with these marketing communications. | IT | Garante | GDPR | €30,000 | ↗ |
| 16 Feb 2012 | Amiat s.p.a.Amiat s.p.a. was fined EUR 30,000 by the Garante for failing to designate Allsystems s.p.a. as a data processor and for not providing the necessary instructions. The authority found that the company did not adopt the minimum security measures required for data processing. | IT | Garante | GDPR | €30,000 | ↗ |
| 30 Mar 2017 | Acantho s.p.a.Acantho s.p.a. was fined by the Garante in the amount of EUR 30,000 for retaining telephone and telematic traffic data longer than legally permitted. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 01 Jan 2021 | MARINS PLAYA, S.A.MARINS PLAYA, S.A. was fined by the AEPD in the amount of EUR 30,000 for unlawfully scanning a customer's passport during hotel registration. The authority found that this breached Article 6 of the GDPR because there was no valid legal basis for the processing. | ES | AEPD | GDPR | €30,000 | ↗ |