BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Oct 2023 | COMUNIDAD DE PROPIETARIOS ***COMUNIDAD.1The entity installed a video surveillance system with cameras directed toward public areas without prior administrative authorization. In addition, unauthorized personnel had access to the system, creating a data protection compliance breach. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 Jan 2012 | IBEREXPERT GRUPO CONSULTOR INFORMATICO, S.L.IBEREXPERT GRUPO CONSULTOR INFORMATICO, S.L. was fined by the AEPD in the amount of 6,000 EUR for sending unsolicited commercial communications after a request to stop. The conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 01 Jan 2019 | TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD. The authority found that the company used personal data to fraudulently contract phone lines without the data subjects’ consent. | ES | AEPD | GDPR | €50,000 | ↗ |
| 19 Sept 2016 | CONVERSALES INNOVA, S.L.CONVERSALES INNOVA, S.L. was fined by the AEPD €3,000 for sending unsolicited commercial emails without prior consent from recipients. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jan 2013 | GRUPO FIDES 21 FORMACION, S.L.GRUPO FIDES 21 FORMACION, S.L. was fined EUR 1,200 by the AEPD for sending unsolicited commercial emails. The case concerned a breach of Article 21 of the LSSI, which prohibits such messages without prior consent. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 01 Jan 2013 | SEARCH TASK, S.L.U.SEARCH TASK, S.L.U. was fined by the AEPD EUR 30,001 for sending commercial emails without prior consent from recipients. The conduct breached Article 21 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 01 Jan 2016 | TELE PIZZA S.A.U.TELE PIZZA S.A.U. was fined EUR 2,500 by the AEPD for sending commercial emails without providing a valid electronic address for exercising ARCO rights. This breached Article 21.2 of the LSSI and indicates a failure to meet required recipient information obligations. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 02 Jul 2010 | ANTENA 3 DE TELEVISIÓN S.A.ANTENA 3 DE TELEVISIÓN S.A. was fined by the AEPD in the amount of 1,000 EUR for sending commercial SMS messages without prior recipient consent. The case concerns a breach of direct marketing rules and consent requirements for electronic communications. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 01 Jan 2023 | ENERGÍA COLECTIVA, S.L.ENERGÍA COLECTIVA, S.L. was fined by the AEPD for inaccurately processing personal data. The issue led to incorrect billing and an intrusion into individuals’ privacy. | ES | AEPD | GDPR | €70,000 | ↗ |
| 03 Nov 2022 | FINCAS MARTIN 2, S.L.FINCAS MARTIN 2, S.L. was fined by the AEPD 5,000 EUR for failing to provide the information required under Article 13 GDPR when collecting personal data through a website contact form. The authority found that users were not properly informed about the processing of their data at the time of collection. | ES | AEPD | GDPR | €5,000 | ↗ |
| 11 Jun 2020 | XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined EUR 55,000 by the AEPD for linking a phone number to a third party’s data. This created unauthorized access and a risk of data alteration, breaching data protection rules. | ES | AEPD | GDPR | €55,000 | ↗ |
| 09 Jun 2021 | INMOPISO ZARAGOZA, S.L.INMOPISO ZARAGOZA, S.L. was fined EUR 2,000 by the AEPD for failing to provide data protection information to a customer who made a deposit for a property purchase. The case concerns a breach of the transparency and information duty owed to the data subject. | ES | AEPD | GDPR | €2,000 | ↗ |
| 24 Jan 2024 | CAJA RURAL DE GIJÓN, S.C.A.C.CAJA RURAL DE GIJÓN was fined by the AEPD 95,000 EUR for breaching data protection principles, specifically confidentiality and integrity. The incident resulted in unauthorized access to personal data and indicates a significant compliance failure. | ES | AEPD | GDPR | €95,000 | ↗ |
| 01 Jan 2015 | JAZZ TELECOM, SAUJAZZ TELECOM, SAU was fined by the AEPD in the amount of 7,400 EUR for sending unsolicited commercial emails to a complainant. The conduct occurred after the cancellation of the complainant’s personal data had been confirmed and breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €7,400 | ↗ |
| 04 Dec 2023 | GRIMEY WEAR, S.L.GRIMEY WEAR, S.L. was fined by the AEPD 5,000 EUR for failing to delete a customer's personal data within the legal timeframe. The case concerns a breach of data protection rules and the controller's obligation to comply with a deletion request. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 20 Feb 2023 | B.B.B.B.B.B. installed a surveillance camera aimed at a private property without authorization. The AEPD found this to be a breach of Article 5(1)(c) GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 01 Apr 2019 | EL GYM IBERIA, S.L.EL GYM IBERIA, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited marketing emails. This occurred despite a prior request to cancel personal data. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 11 Sept 2020 | BODEGAS DINASTIA, S.L.BODEGAS DINASTIA, S.L. was fined by the AEPD EUR 2,000 for non-compliance with data protection rules on its websites. The issues concerned the privacy policy and the way cookie consent was obtained. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 28 Jan 2021 | TRES-F-NETWORK, S.A.UTRES-F-NETWORK, S.A.U was fined by the AEPD 4,000 EUR for sending commercial SMS messages without the recipient's consent and without an existing commercial relationship. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 12 Apr 2024 | DATACENTRICDATACENTRIC was fined by the AEPD 60,000 EUR for processing personal data of self-employed individuals without a valid legal basis. The data was also exposed online and used for marketing purposes, breaching GDPR Articles 6(1) and 14. | ES | AEPD | GDPR | €60,000 | ↗ |