Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
25 Feb 2021Mistore Canarias, S.L.U.Mistore Canarias, S.L.U. was fined by the AEPD 5,000 EUR for processing personal data without consent. The conduct resulted in unauthorized charges to a customer's bank account.ESAEPDGDPR€5,000
04 Feb 2020VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 60,000 EUR for a data protection violation. The case involved unauthorized data processing and signature forgery by an employee, which led to a fraudulent service transfer.ESAEPDGDPR€60,000
03 Dec 2019MYMOVILES EUROPA 2000, S.L.MYMOVILES EUROPA 2000, S.L. was fined by the AEPD €1,500 for failing to provide the required privacy information on its website. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€1,500
31 Mar 2017B.B.B.B.B.B. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The emails continued despite repeated requests from the recipient to stop, which breached the LSSI.ESAEPDePrivacy€30,001
01 Jan 2024EXCEL HOTELS & RESORTS, S.A.EXCEL HOTELS & RESORTS, S.A. was fined by the AEPD 40,000 EUR for leaving property owners’ personal data unattended, including ID and passport numbers. The authority found that this created unauthorized access to sensitive personal information and breached data protection principles.ESAEPDGDPR€40,000
04 Feb 2025LÍNEAS FINANCIERAS INTERNACIONALES, S.L.The entity was fined EUR 500 by the AEPD for sending unsolicited commercial communications by email without prior consent. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€500
05 Nov 2019CERRAJERO ONLINE S.L.CERRAJERO ONLINE S.L. was fined EUR 1,500 by the AEPD for collecting personal data without providing the required information to data subjects. The authority treated this as a breach of data protection rules.ESAEPDGDPR€1,500
07 Sept 2023IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORAIberia was fined by the AEPD EUR 50,000 for a breach related to personal data handling during a flight from Quito to Dublin. Passengers were asked to provide identity documents and marriage certificates to justify travel during COVID-19 restrictions.ESAEPDGDPR€50,000
24 Jan 2024CAJA RURAL DE ASTURIAS, S.C.C.CAJA RURAL DE ASTURIAS was fined by the AEPD EUR 250,000 for breaching the confidentiality and integrity principles of personal data. The incident allowed unauthorized access to personal data, indicating a failure to protect data appropriately.ESAEPDGDPR€250,000
27 Nov 2020CERTIME, S.A.CERTIME, S.A. was fined by the AEPD in the amount of 5,000 EUR for processing personal data for a purpose different from the one originally specified. The authority found this to be a breach of Article 5(1)(b) GDPR.ESAEPDGDPR€5,000
22 Feb 2022VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 70,000 EUR for issuing a duplicate SIM card to a third party without proper authorization. This enabled unauthorized access to the complainant’s bank data and resulted in fraudulent transactions.ESAEPDGDPR€70,000
04 Oct 2021SAKBO SPAIN, S.L.SAKBO SPAIN, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€5,000
10 Mar 2023DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the customer's consent. The action enabled unauthorized bank transactions, indicating a serious breach of data protection and authentication security.ESAEPDGDPR€200,000
11 May 20103Emultimedia comunicación en Internet S.L.3Emultimedia comunicación en Internet S.L. was fined €600 by the AEPD for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€600
29 Jun 2023FUNDACIÓN VEDRUNA EDUCACIÓN COLEGIOA teacher publicly disclosed the content of an email concerning a student's issues, breaching the duty of confidentiality. The AEPD found a violation of data protection rules and imposed a 15,000 EUR fine.ESAEPDGDPR€15,000
14 Dec 2022ODRIA COSTAS INTERNACIONAL, S.L.ODRIA COSTAS INTERNACIONAL, S.L. was fined EUR 10,000 by the AEPD for publishing images of minors without consent on a real estate website. The authority found this to be a breach of data protection rules.ESAEPDGDPR€10,000
25 Jun 2024RIVENDELL TECHNOLOGY, S.L.RIVENDELL TECHNOLOGY, S.L. failed to properly handle a data subject access request, which constitutes a breach of Article 15 GDPR. The company was fined for not complying with the data protection authority's resolution.ESAEPDGDPR€900
22 Jun 2023COLEGIO VIRGEN DE EUROPA, S.L.The school processed and published images of a 3-year-old child on Facebook and WhatsApp without parental consent. This disregarded the parents’ explicit refusal and led to a fine imposed by the AEPD.ESAEPDGDPR€15,000
05 May 2026VOX ESPAÑAVOX ESPAÑA was fined by the AEPD 500 EUR for publishing personal data on Facebook without proper consent. The authority found that this breached Article 6 of the GDPR.ESAEPDGDPR€500
05 Jul 2021FUTURE VINLINE SLFUTURE VINLINE SL was fined by the AEPD EUR 10,000 for not having an adequate privacy policy on its website. The authority found that the company failed to provide clear and complete information about data processing under Article 13 GDPR.ESAEPDGDPR€10,000