BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Jan 2012 | QUOTATIS ESPAÑA S.L.QUOTATIS ESPAÑA S.L. was fined by the AEPD 30,001 EUR for sending unsolicited commercial emails despite requests to stop. The case concerned Article 21.1 of the LSSI, which prohibits such communications without prior consent. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 21 Nov 2017 | IBERIA LINEAS AEREAS DE ESPAÑA, S.A. OPERADORA, SOCIEDAD UNIPERSONALIberia was fined by the AEPD in the amount of 3,300 EUR for sending commercial emails without the recipient's consent. The authority found a breach of Article 21.1 of the LSSI on unsolicited electronic communications. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 23 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined EUR 70,000 by the AEPD after a third party gained unauthorized access to a customer account. The incident led to changes in personal data and services without the customer’s consent. | ES | AEPD | GDPR | €70,000 | ↗ |
| 04 Dec 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 5,000 by the AEPD for failing to provide requested information. The case concerned a breach of obligations under data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 17 Jun 2024 | FÚTBOL CLUB BARCELONAFútbol Club Barcelona was fined by the AEPD for processing biometric data without explicit consent during a mandatory member census update. The authority found breaches of GDPR Articles 9 and 35, relating to special-category data processing and data protection impact assessment requirements. | ES | AEPD | GDPR | €6,000,000 | ↗ |
| 16 Jun 2020 | SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.U.SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.U. was fined by the AEPD 5,000 EUR for breaching the GDPR information obligations under Article 13. The case followed a complaint from the Madrid City Council's Consumer Unit. | ES | AEPD | GDPR | €5,000 | ↗ |
| 26 May 2010 | MATCHLESS, S.L.MATCHLESS, S.L. was fined by the AEPD 30,001 EUR for sending unsolicited commercial emails without prior recipient consent. The authority also found that the company failed to provide a simple and free mechanism for recipients to object to further communications, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 29 Jan 2024 | JAÉN, SENTIDO Y COMÚNThe entity was fined by the AEPD for failing to comply with a data protection authority resolution. The breach concerned sending emails to multiple recipients without using BCC, contrary to Article 58(2) GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 12 Jul 2021 | B.B.B.B.B.B. was fined by the AEPD EUR 1,200 for operating a video surveillance system without proper signage. The case involved a breach of GDPR Article 13, and a new camera was installed despite prior warnings without correcting the deficiencies. | ES | AEPD | GDPR | €1,200 | ↗ |
| 11 Jun 2024 | DIGITAL FLOW, S.L.DIGITAL FLOW, S.L. was fined EUR 2,000 by the AEPD for sending emails without an unsubscribe option. The authority also found that the company failed to provide a valid contact for exercising data deletion rights. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 01 Jan 2018 | G.L. GISOFT ANÁLISIS Y DISEÑO, S.L.G.L. GISOFT ANÁLISIS Y DISEÑO, S.L. was fined 600 EUR by the AEPD. The case concerned the sending of unsolicited commercial emails, which breaches Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 21 Oct 2010 | Baldomero **** y Jesús ***** CBBaldomero **** y Jesús ***** CB was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent from recipients. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 01 Jan 2022 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for unlawfully duplicating a customer's SIM card without consent. The incident led to unauthorized access to the customer's personal and banking data. | ES | AEPD | GDPR | €70,000 | ↗ |
| 20 May 2021 | B.B.B.The entity did not provide the complainant with information about data processing or the ability to exercise rights after receiving a CV via WhatsApp in response to a job offer. AEPD imposed a fine of EUR 2,000 for breaching transparency obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 06 Nov 2019 | TODOTECNICOS24H S.L.TODOTECNICOS24H S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to the data subjects. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 01 Jan 2015 | TELENAUTO, S.A.TELENAUTO, S.A. was fined EUR 1,300 by the AEPD for sending unsolicited commercial SMS messages to a customer. The authority found a breach of the LSSI because prior consent was not obtained and no opt-out mechanism was provided. | ES | AEPD | ePrivacy | €1,300 | ↗ |
| 26 Oct 2021 | OPEN BANK, S.A.OPEN BANK, S.A. was fined by the AEPD for using non-essential third-party cookies without prior user consent. The authority also found that the cookies could not be removed, which breached Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 15 Nov 2022 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SL.The entity was fined for sending unsolicited commercial emails despite the recipient's explicit objection. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 29 Jul 2022 | COMUNIDAD DE PROPIETARIOSA community of property owners was fined by the AEPD €300 for installing a surveillance camera without proper signage. The notice did not identify the data controller or provide contact details for exercising data subject rights. | ES | AEPD | GDPR | €300 | ↗ |
| 22 Oct 2019 | IBERDROLA COMERCIALIZACIÓN DE ÚLTIMO RECURSO, S.A.U. (CURENERGIA COMERCIALIZADORA DE ULTIMO RECURSO, S.A.U.)CURENERGIA was fined EUR 75,000 by the AEPD for using a former client's personal data without consent. The data was used to carry out a fraudulent contract registration. The case indicates a breach of lawful processing and personal data protection requirements. | ES | AEPD | GDPR | €75,000 | ↗ |