Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Jan 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 200,000 for continuing to send emails to a complainant despite earlier sanctions for similar conduct. The authority treated this as a recurring breach of GDPR Article 6.1, indicating processing without a valid legal basis.ESAEPDGDPR€200,000
30 Jan 2023BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD in the amount of 1,000 EUR for not adequately handling a data subject access request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€1,000
10 Jan 2026DÉCIMAS, S.L.DÉCIMAS, S.L. was fined by the AEPD in the amount of EUR 200,000 for a personal data breach. The incident exposed personal data and breached GDPR Article 5(1)(f).ESAEPDGDPR€200,000
12 Jun 2021MERCEDES GERENCIA, S.L.MERCEDES GERENCIA, S.L. was fined by the AEPD in the amount of 3,000 EUR for breaching Article 58.1 of the GDPR. The case concerned non-compliance with obligations related to the supervisory authority’s powers.ESAEPDGDPR€3,000
15 Oct 2024AFP GESTION DEL COLOR, S.L.AFP GESTION DEL COLOR, S.L. was fined by the AEPD in the amount of €1,000 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits marketing communications without prior consent.ESAEPDePrivacy€1,000
28 Feb 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD 70,000 EUR for processing personal data without consent. The case concerned a mobile line contracted in the complainant’s name without proper identity verification.ESAEPDGDPR€70,000
01 Oct 2024SERVACE, S.L.SERVACE, S.L. was fined by the AEPD EUR 1,400 for using an employee’s personal email address for work purposes without consent. The authority found this breached GDPR Articles 6(1) and 5(1)(f).ESAEPDGDPR€1,400
01 Jan 2024FRUTAS CALISA, S.L.FRUTAS CALISA, S.L. was fined 300 EUR by the AEPD for contacting an individual via WhatsApp without prior consent. The authority found this conduct to be a breach of Article 6(1) GDPR.ESAEPDGDPR€300
12 Apr 2021INSTAPACK, S.L.INSTAPACK, S.L. was fined by the AEPD for sending unsolicited SMS messages without valid consent. The authority also found that the company failed to respond to a deletion request, constituting a breach of GDPR Article 6(1)(a).ESAEPDGDPR€3,000
01 Jan 2017SOCIEDAD AIR FRANCE, S.A.Air France was fined by the AEPD EUR 7,000 for sending emails to a complainant despite a request to delete the personal data. The case concerns a breach of data protection rules and improper processing after a deletion request.ESAEPDePrivacy€7,000
09 Dec 2021***COMUNIDAD.1The entity installed surveillance cameras in a community property without proper authorization from all owners. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,500
22 Feb 2024BLU MANAGEMENT SPAIN, S.L.BLU MANAGEMENT SPAIN, S.L. was fined €2,000 by the AEPD for sharing a job applicant’s contact details without consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€2,000
08 Jun 2022INMUR JOYEROS, S.L.INMUR JOYEROS, S.L. was fined by the AEPD 300 EUR for failing to properly inform individuals about the video surveillance system in its premises. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€300
24 Feb 20254USPORT INSTALACIONES DEPORTIVAS, S.L.4USPORT INSTALACIONES DEPORTIVAS, S.L. was fined by the AEPD in the amount of 600 EUR for failing to provide access. The case concerned Article 58(1) of the GDPR and indicates a failure to cooperate with the supervisory authority.ESAEPDGDPR€600
25 Sept 2019ASOCIACION DE MEDICOS DEMOCRATASASOCIACION DE MEDICOS DEMOCRATAS was fined by the AEPD EUR 10,000 for processing the personal data of medical professionals without their consent. The authority found a breach of Article 6(1)(a) GDPR.ESAEPDGDPR€10,000
28 Oct 2013HERBORISTERÍA TRÉBOL-HIDROLINFA C.B.HERBORISTERÍA TRÉBOL-HIDROLINFA C.B. was fined EUR 600 by the AEPD for sending a commercial email without providing a valid electronic address for recipients to object to the processing of their data for advertising purposes. The authority found a breach of Article 21.2 of the LSSI.ESAEPDePrivacy€600
01 Jan 2020VOLTIMUM, S.A.VOLTIMUM, S.A. was fined EUR 2,000 by the AEPD for sending commercial emails after the recipient had opted out. The authority found this to be a breach of Article 21 of the LSSI on marketing communications.ESAEPDePrivacy€2,000
01 Jul 2022RCI BANQUE, S.A. SUCURSAL EN ESPAÑARCI Banque, S.A. Sucursal en España was fined by the AEPD for failing to properly handle a request for erasure under Article 17 GDPR. As a result, the data subject received unwanted communications about a debt they did not owe.ESAEPDGDPR€20,000
27 Sept 2021B.B.B.The entity was fined by the AEPD for operating a video surveillance system without proper informational signage. The system also captured footage beyond the intended purpose, including public transit areas.ESAEPDGDPR€1,500
01 Jan 2018ADGOALS MEDIA S.L.ADGOALS MEDIA S.L. was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited SMS advertisements without prior recipient consent. The authority also found that no opt-out mechanism was provided, which constitutes a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,500