Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Jun 2022AUDIO STOCK, S.L.AUDIO STOCK, S.L. was fined €2,000 by the AEPD for sending commercial SMS messages despite the recipient's objection. The authority found this conduct breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€2,000
17 Apr 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD 200,000 EUR for a data protection breach involving unauthorized SIM card duplication. The incident led to identity theft and fraudulent bank charges.ESAEPDGDPR€200,000
08 Nov 2024AECORP 005, S.L.AECORP 005, S.L. was fined EUR 6,000 by the AEPD for failing to provide access to information requested during an investigation. The authority found a breach of Article 58.1 GDPR.ESAEPDGDPR€6,000
06 Feb 2024GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe AEPD fined GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADA EUR 2,000 for sending unsolicited commercial communications without the recipient's consent. The authority noted that the messages were sent despite the recipient's opposition.ESAEPDePrivacy€2,000
08 Nov 2012G.L. GISOFT ANALISIS Y DISEÑO S.L.G.L. GISOFT ANALISIS Y DISEÑO S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails without recipient consent. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€600
05 Jul 2022CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined 70,000 EUR by the AEPD. The company continued to demand payment of a debt that had been annulled by a court ruling, which breached data protection rules.ESAEPDGDPR€70,000
24 Feb 2025UNICAJA BANCO, S.A.U.UNICAJA BANCO, S.A.U. was fined by the AEPD EUR 3,500,000 for inadequate security measures in its video surveillance system. The authority found a breach of data protection requirements.ESAEPDGDPR€3,500,000
11 Aug 2025FUNDACIÓN PARA EL DESARROLLO DE LA ENFERMERÍA y SINDICATO DE ENFERMERÍA, SATSESATSE and FUDEN were fined by the AEPD EUR 15,000 after a ransomware incident affected personal data. The authority also found that the parties had not properly formalized a joint controllership agreement under the GDPR.ESAEPDGDPR€15,000
19 May 2021TNT EXPRESS WORLDWIDE SPAIN, S.L.TNT Express Worldwide Spain, S.L. was fined by the AEPD €10,000 for incorrectly linking a personal delivery service to a corporate account. This resulted in the unauthorized sharing of personal data with the complainant’s employer.ESAEPDGDPR€10,000
28 Oct 2013LEGALITAS ASISTENCIA LEGAL, S.L.LEGALITAS ASISTENCIA LEGAL, S.L. was fined by the AEPD 33,000 EUR for sending unsolicited commercial communications. The conduct continued despite requests for data cancellation, which breached Article 21 of the LSSI.ESAEPDePrivacy€33,000
11 Sept 2025ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD for disclosing personal data, including a handwritten signature, in a news broadcast without necessity. The authority found that the disclosure breached data protection principles because it was not proportionate to the purpose of the publication.ESAEPDGDPR€10,000
19 Jul 2011A.A.A.A.A.A. was fined EUR 1,200 by the AEPD. The authority found that the entity sent unsolicited commercial emails without the recipient's prior consent, in breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200
12 Sept 2022ROMESTONE, S.L.ROMESTONE, S.L. was fined by the AEPD 6,000 EUR for installing a surveillance camera in a shared rental property without tenant consent. The case concerns a privacy breach in the context of personal data processing.ESAEPDGDPR€6,000
01 Dec 2023ENDESA, S.A.The Spanish data protection authority imposed a EUR 6.1 million fine on ENDESA in December 2023. The case involved a security breach that led to the sale of customer personal data through Facebook ads.ESAgencia Española de Protección de DatosGDPR€6,100,000
01 Jan 2017ROCK INTERNET, S.L.ROCK INTERNET, S.L. was fined by the AEPD EUR 5,000 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits such communications without prior recipient consent.ESAEPDePrivacy€5,000
06 Mar 2020IBERDROLA CLIENTES, SAUIBERDROLA CLIENTES, SAU was fined by the AEPD in the amount of EUR 5,000 for failing to provide requested information to the data protection authority. The conduct breached Article 58(1) of the GDPR.ESAEPDGDPR€5,000
10 Sept 2012GRUPO ENLACE FOCAM S.L.U.GRUPO ENLACE FOCAM S.L.U. was fined by the AEPD EUR 600 for sending an unsolicited commercial email without the recipient’s consent. The case concerned Article 21.1 of the LSSI, which prohibits this type of marketing communication without prior consent.ESAEPDePrivacy€600
28 Jun 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined EUR 70,000 by the AEPD for a SIM card duplication incident. The incident enabled unauthorized attempts to access the complainant's bank accounts and was treated as a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
01 Jan 2019Vodafone España, S.A.U.Vodafone España, S.A.U. was fined EUR 75,000 by the AEPD for a data protection breach. The case involved unauthorized contract portability using a customer's personal data without consent.ESAEPDGDPR€75,000
01 Jan 2015IMPROCONSULTEX FORMACION INFORMATICA S.L.IMPROCONSULTEX FORMACION INFORMATICA S.L. was fined by the AEPD EUR 1,000 for sending commercial communications by electronic means without prior consent. The case concerns a breach of Article 21.1 of the LSSI and indicates insufficient legal basis for electronic marketing.ESAEPDePrivacy€1,000