BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Dec 2021 | Federación Estatal de Servicios, Movilidad y Consumo de la UGT (FESMC-UGT)FESMC-UGT was fined 2,000 EUR by the AEPD for sending emails to employees’ corporate addresses without proper authorization. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Oct 2024 | CONSULTORIA INTEGRAL DE ENERGÍA ECOLÓGICA, S.L.The company was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited advertising messages to a complainant. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 29 Nov 2022 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for failing to comply with a data subject access request. The case concerned the company’s failure to provide a requested recording of a contract concluded by telephone. | ES | AEPD | GDPR | €70,000 | ↗ |
| 08 May 2024 | KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined EUR 600 by the AEPD for failing to provide access to personal data and related information. The authority found a breach of Article 58(1) of the GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 01 Jan 2015 | Jazz Telecom SAUJazz Telecom SAU was fined by the AEPD EUR 5,000 for sending an unsolicited commercial SMS. The conduct breached Article 21.1 of the LSSI, which governs commercial communications without prior consent. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 23 Jan 2024 | BANCO COOPERATIVO ESPAÑOL, S.A.Banco Cooperativo Español, S.A. was fined by the AEPD for a personal data breach. The incident allowed unauthorized access to personal data and breached the principles of confidentiality and integrity. | ES | AEPD | GDPR | €15,000 | ↗ |
| 28 Apr 2026 | POSADA DEL LEÓN DE ORO, C.B.POSADA DEL LEÓN DE ORO, C.B. was fined EUR 400 by the AEPD for improper use of a surveillance system that recorded audio and video. The authority found violations of employee privacy and of the duty to inform data subjects about processing, contrary to GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €400 | ↗ |
| 16 Sept 2022 | SUPER 24H LOS ROSALES, S.L.The company was fined EUR 300 by the AEPD for operating an external surveillance camera without visible signage. It also failed to provide information on the data controller and data subject rights required under GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 01 Jan 2020 | ARGAN-LET, S.L.ARGAN-LET, S.L. was fined 900 EUR by the AEPD for sending unsolicited commercial SMS messages without prior consent. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €900 | ↗ |
| 22 Mar 2013 | PUBLIACTIVOS COMUNICACION Y MARKETING, S.L.The entity was fined by the AEPD for sending unsolicited commercial emails. This conduct breached Article 21.1 of the LSSI, which prohibits marketing communications without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 01 Jan 2015 | SERVICIOS VARIOS 8020, S.L.SERVICIOS VARIOS 8020, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails. The messages did not include an unsubscribe option for recipients, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 03 Aug 2022 | LORENT 2013, S.L.LORENT 2013, S.L. was fined EUR 900 by the AEPD for operating video surveillance without proper signage. The cameras were also directed toward public areas without authorization, which breached data protection rules. | ES | AEPD | GDPR | €900 | ↗ |
| 31 Jul 2020 | ASOCIACIÓN DE VIGILANTES DE SEGURIDAD DEL AEROPUERTO DE BARCELONAThe organization was fined by the AEPD in the amount of 3,000 EUR for sending an electoral census of workers to private phones via WhatsApp. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Oct 2013 | C.C.C.C.C.C. was fined 600 EUR by the AEPD for sending unsolicited SMS messages without prior consent from recipients. The authority found this conduct breached Article 21 of the LSSI on commercial communications. | ES | AEPD | ePrivacy | €600 | ↗ |
| 12 Feb 2021 | HIGHCLIFFE ESTATES MARBELLA, S.L.The company was fined by the AEPD for not providing a legal notice, privacy policy, or consent checkbox on its website. The authority also found that it used an individual's image without consent, breaching GDPR Articles 13 and 6(1). | ES | AEPD | GDPR | €8,000 | ↗ |
| 26 Jul 2018 | VILAN DATAMINING, S.L.VILAN DATAMINING, S.L. was fined by the AEPD in the amount of 1,600 EUR for sending unsolicited commercial emails without the required consent. The conduct breached article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,600 | ↗ |
| 13 Jul 2012 | NH HOTELES, S.A.NH HOTELES, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant after confirming the cancellation of their personal data. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €33,001 | ↗ |
| 29 Apr 2022 | RADIO TELEVISION MADRID, S.A.RADIO TELEVISION MADRID, S.A. was fined by the AEPD 50,000 EUR for processing excessive personal data. The case concerned the publication of audio of a victim's court statement in a high-profile case, which breached the data minimization principle. | ES | AEPD | GDPR | €50,000 | ↗ |
| 25 Jul 2019 | SOCIEDAD ESTATAL CORREOS Y TELEGRAFOS. S.A.The entity delivered correspondence to the wrong recipient, which constitutes a breach of the data protection principles in Article 5 of the GDPR. AEPD imposed a fine of EUR 40,000. | ES | AEPD | GDPR | €40,000 | ↗ |
| 01 Jan 2012 | NECESIDADES INFORMATICAS, S.L.NECESIDADES INFORMATICAS, S.L. was fined EUR 600 by the AEPD for sending a commercial email without the recipient’s prior consent. The conduct breached Article 21.1 of the LSSI, which prohibits unsolicited marketing communications. | ES | AEPD | ePrivacy | €600 | ↗ |