Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONAL was fined by the AEPD EUR 20,000 for sending unsolicited commercial communications by email. The conduct breached Article 21.1 of the LSSI and constituted unlawful marketing communication.ESAEPDePrivacy€20,000
24 Jul 2020IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALThe AEPD fined Iberia Líneas Aéreas de España, S.A. Operadora Unipersonal 30,000 EUR. The authority found that the website did not provide users with an option to reject cookies in line with consent requirements.ESAEPDePrivacy€30,000
31 May 2022B.B.B.The entity was fined for using a surveillance camera with audio to monitor an employee without prior notice. The authority found this to be a breach of data protection rules.ESAEPDGDPR€5,000
04 Jun 2020PRA IBERIA, S.L.PRA IBERIA, S.L. was fined by the AEPD 60,000 EUR for unlawful processing of personal data and for failing to provide access to personal data information. The breaches concerned Articles 6(1) and 15 of the GDPR.ESAEPDGDPR€60,000
06 Apr 2022BANKINTER, S.A.BANKINTER, S.A. was fined EUR 70,000 by the AEPD for a data protection breach. The case involved the unauthorized disclosure of sensitive banking information caused by an isolated IT error.ESAEPDGDPR€70,000
21 Sept 2020CONSEGURIDAD S.L.CONSEGURIDAD S.L. was fined 50,000 EUR by the AEPD for failing to appoint a Data Protection Officer. The authority found a breach of Article 37(1)(b) of the GDPR.ESAEPDGDPR€50,000
18 Aug 2021EULEN SEGURIDAD, S.A.EULEN SEGURIDAD, S.A. was fined by the AEPD 3,000 EUR for disclosing employees' DNI numbers in a workplace notice. The authority found a breach of confidentiality and data security principles.ESAEPDGDPR€3,000
15 Dec 2022B.B.B.The entity was fined for operating surveillance cameras directed at public areas without the required authorization or signage. The authority found this to be a breach of data protection rules.ESAEPDGDPR€3,000
06 Oct 2014TROPIAUTO MOTRIL SATROPIAUTO MOTRIL SA was fined by the AEPD EUR 2,000 for sending unsolicited advertising emails after the recipient had exercised the right to opt out. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€2,000
11 Jun 2024A.A.A.The municipality accessed and disclosed personal data without a legal basis, including full name, ID number, address, and financial details. The authority found a breach of Article 6 GDPR and imposed a EUR 500 fine.ESAEPDGDPR€500
03 Jul 2023ENDESAENDESA was fined by the AEPD EUR 2,500,000 for failing to ensure the integrity and confidentiality of personal data and for inadequate security measures. The authority found breaches of GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€2,500,000
01 Jan 2023ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 200,000 by the AEPD for issuing a duplicate SIM card to a third party without the complainant's consent. The incident enabled unauthorized access to personal and banking data, indicating a serious data protection failure.ESAEPDGDPR€200,000
12 Nov 2021EUSKALTEL, S.A.EUSKALTEL, S.A. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails without the required consent. The conduct breached Article 21 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€5,000
29 Nov 2019BANCO BILBAO VIZCAYA ARGENTARIA SLBBVA was fined by the AEPD for sending unsolicited advertising to an individual who was not a customer of the bank. The authority found this to be a breach of data protection rules.ESAEPDePrivacy€10,000
19 Feb 2016Asociación de Empresarios de Tecnologías de la Información y Comunicaciones de Andalucía (ETICOM)ETICOM was fined €3,400 by the AEPD for sending unsolicited commercial emails without prior consent from recipients. The authority also found that the messages did not include a simple opt-out mechanism, in breach of Article 21 of the LSSI.ESAEPDePrivacy€3,400
01 Jan 2019Don B.B.B.Don B.B.B. was fined by the AEPD in the amount of 1,000 EUR for sending an unsolicited commercial email. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior consent.ESAEPDePrivacy€1,000
22 Mar 2025DINOLIN, S.A.DINOLIN, S.A. was fined EUR 450 by the AEPD for failing to comply with a data subject's request to delete personal data. The case concerns obligations under the GDPR.ESAEPDGDPR€450
03 Jul 2023LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD 5,000 EUR for attempting to install cookies on users' devices without proper consent. The conduct breached data protection rules and electronic commerce requirements.ESAEPDePrivacy€5,000
29 Oct 2013ESPASA CALPE, S.A.ESPASA CALPE, S.A. was fined EUR 35,000 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI despite prior requests to be removed from the mailing list.ESAEPDePrivacy€35,000
01 Apr 2025EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.The AEPD fined EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A. 20,000 EUR for publishing unnecessary personal data in a news article. A video in the article revealed the identity of a minor, which was considered disproportionate and unnecessary for the informational purpose.ESAEPDGDPR€20,000