BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Sept 2016 | CONCEPTO ARGENTINO SL (LA VACA ARGENTINA)The AEPD fined CONCEPTO ARGENTINO SL (LA VACA ARGENTINA) 1,500 EUR for sending unsolicited emails despite the recipient's request to unsubscribe. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 04 Feb 2026 | E-RETAIL ADVERTISING, S.L.E-RETAIL ADVERTISING, S.L. was fined by the AEPD in the amount of 5,000 EUR for installing non-exempt cookies on its website without prior user consent. The case concerns non-compliance with cookie consent requirements and user privacy obligations. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 15 Dec 2023 | TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L.TECH EDUCATION, RIGHTS & TECHNOLOGIES, S.L. was fined EUR 5,000 by the AEPD for sending commercial information by email after confirming the deletion of personal data. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 22 Sept 2010 | JET MULTIMEDIA ESPAÑA S.A.JET MULTIMEDIA ESPAÑA S.A. was fined by the AEPD EUR 600 for sending unsolicited commercial SMS messages. Recipients were not given a simple and free way to object to the use of their data for marketing purposes. | ES | AEPD | ePrivacy | €600 | ↗ |
| 09 Jan 2023 | NANDIVALE, S.L.NANDIVALE, S.L. was fined by the AEPD EUR 10,000 for publishing images of minors on Instagram without parental consent. The authority found this conduct to be in breach of GDPR Article 6(1). | ES | AEPD | GDPR | €10,000 | ↗ |
| 11 Jul 2012 | Control Distribución Marketing, S.L.Control Distribución Marketing, S.L. was fined by the AEPD for sending unsolicited commercial emails. The company also failed to honor requests to stop such communications, breaching Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 24 Aug 2022 | B.B.B.The entity installed a video surveillance camera covering common areas without authorization from the homeowners' association. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €600 | ↗ |
| 21 Jan 2016 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 10,500 for sending unsolicited advertising SMS messages without prior recipient consent. The authority also found that no opt-out mechanism was provided, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €10,500 | ↗ |
| 26 Aug 2021 | B.B.B.The entity was fined 1,500 EUR by the AEPD for improperly positioning its video surveillance system. The cameras were directed toward a public path, which breached data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 25 May 2022 | CLINT IS GOOD DIGITAL CREATIVE TEAM, S.L.CLINT IS GOOD DIGITAL CREATIVE TEAM, S.L. was fined 500 EUR by the AEPD. The case concerned sending unsolicited commercial communications by email without consent, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €500 | ↗ |
| 01 Jan 2019 | GESTIÓN DE COBROS, YO COBRO SLThe company was fined EUR 60,000 by the AEPD for unlawfully processing personal data. The breach involved sending debt collection emails to an institutional email address without consent, in violation of data protection rules. | ES | AEPD | GDPR | €60,000 | ↗ |
| 10 Jul 2023 | C.C.C.The entity was fined for operating a video surveillance system that captured public areas and neighboring properties without the required authorization. Required informational signage was also not displayed. | ES | AEPD | GDPR | €600 | ↗ |
| 10 Sept 2021 | LA OFICINA BAR XXXXThe entity installed two surveillance cameras aimed at public areas without justification. This breached data protection principles. | ES | AEPD | GDPR | €1,500 | ↗ |
| 19 Jun 2020 | IBERDROLA CLIENTES, SAUThe AEPD fined IBERDROLA CLIENTES, SAU EUR 40,000 for emailing a customer's electricity bill, which contained sensitive personal data, to an unrelated third party. The incident indicates a breach of confidentiality and personal data protection obligations. | ES | AEPD | GDPR | €40,000 | ↗ |
| 09 Dec 2021 | RESTAURANTE FUENTEBRO, S.C.The entity was fined for operating a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 19 Dec 2025 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 25,000 EUR for sending invoices to a person who was not a customer and for failing to properly delete their data after a request. The authority found breaches of data accuracy and the right to erasure under GDPR Articles 5(1)(d) and 17. | ES | AEPD | GDPR | €25,000 | ↗ |
| 02 Jul 2010 | Antena 3 de Televisión, S.A.Antena 3 de Televisión, S.A. was fined by the AEPD in the amount of 30,001 EUR for sending commercial SMS messages without prior recipient consent. The conduct breached the LSSI rules on marketing communications. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 14 Mar 2017 | GABINETE PARAPSICOLOGICO MYSTIC S.L.GABINETE PARAPSICOLOGICO MYSTIC S.L. was fined by the AEPD for sending unsolicited commercial SMS messages. The authority found that recipients were not given a simple and free opt-out mechanism, in breach of the LSSI. | ES | AEPD | ePrivacy | €7,100 | ↗ |
| 16 May 2023 | COLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRECOLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRE was fined by the AEPD for failing to implement appropriate technical and organizational measures to ensure data security. The deficiency resulted in a breach involving minors’ data stored in cloud services. | ES | AEPD | GDPR | €5,000 | ↗ |
| 26 Mar 2013 | GRUPORUM RESPUESTA DIRECTA, S.L.GRUPORUM RESPUESTA DIRECTA, S.L. was fined by the AEPD for sending unsolicited commercial emails without prior consent from recipients. The conduct breached Article 21.1 of the LSSI, which requires prior consent for direct marketing by email. | ES | AEPD | ePrivacy | €1,800 | ↗ |