Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Oct 2020ESTILO 1221, S.C.ESTILO 1221, S.C. was fined by the AEPD EUR 1,500 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21.1 of the LSSI, which prohibits this type of marketing communication without prior consent.ESAEPDePrivacy€1,500
24 May 2023PARTIDO LOCAL DE VILLANUEVA DEL PARDILLOPartido Local de Villanueva del Pardillo was fined EUR 500 by the AEPD for publishing an image on Facebook without the data subject's consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€500
10 Jan 2026MULTISPORTS GALICIA, S.L.MULTISPORTS GALICIA, S.L. was fined by the AEPD EUR 6,000 for failing to implement appropriate technical and organizational measures proportionate to the risk. The weakness allowed easy access to personal data of race participants through its website.ESAEPDGDPR€6,000
21 May 2021COOPERA RC SERVICES, S.L.COOPERA RC SERVICES, S.L. was fined by the AEPD 2,000 EUR for failing to provide the contact details needed to exercise data protection rights. The authority found a breach of the information obligations under Article 13 GDPR.ESAEPDGDPR€2,000
29 May 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España 70,000 EUR for processing call and SMS diversion without the customer's consent. The conduct was linked to a bank fraud incident, indicating a serious failure in data protection and service authorization controls.ESAEPDGDPR€70,000
23 May 202420 AÑOS DE MÚSICA A.I.E.The entity was fined for collecting copies of identity documents and personal data without proper data protection information. The authority found breaches of the data minimization and transparency principles.ESAEPDGDPR€5,000
01 Sept 2022B.B.B.The entity was fined for installing surveillance cameras that captured public areas without prior administrative authorization. This constituted a breach of data protection regulations.ESAEPDGDPR€300
15 Nov 2024AXARQUIA VELEZ DENTAL, S.L.AXARQUIA VELEZ DENTAL, S.L. was fined by the AEPD 5,000 EUR for failing to properly signpost the video surveillance system inside its premises. The authority found a breach of GDPR transparency requirements.ESAEPDGDPR€5,000
20 Apr 2021EB CREATIVE LABEB CREATIVE LAB was fined by the AEPD EUR 5,000 for failing to provide information or obtain consent for cookies on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
19 Jun 2019VF JEANSWEAR ESPAÑA S.L.VF Jeanswear España S.L. was fined by the AEPD 5,000 EUR for using cookies on its website without obtaining user consent. The case concerns a breach of data protection rules and consent requirements for cookies.ESAEPDePrivacy€5,000
25 Apr 2016PARABEBES SERVICIOS INFANTILES Y PREMAMÁ, S.L.The entity was fined by the AEPD for sending unsolicited commercial emails to a complainant. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€2,900
15 Jan 2021VODAFONE ESPAÑA, S.A.U.The Spanish data protection authority imposed a total fine of EUR 8,150,000 on VODAFONE ESPAÑA, S.A.U. The sanction covers breaches of GDPR Articles 28 and 44, as well as additional violations of LSSICE and tax-related rules.ESAgencia Española de Protección de DatosGDPR€8,150,000
05 Jan 2022CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined by the AEPD in the amount of EUR 5,000 for sending commercial SMS messages without the recipient’s consent. The conduct breached Article 21 of the LSSI, which governs unsolicited electronic marketing.ESAEPDePrivacy€5,000
23 Jun 2020COMUNIDAD DE PROPIETAROS R.R.R.The entity was fined for installing video surveillance cameras without the required informational signage. The case concerned a breach of data protection rules and the obligation to properly inform individuals subject to monitoring.ESAEPDGDPR€2,000
18 Jun 2020BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD in the amount of EUR 30,000 for consulting personal data in credit files without an existing contractual relationship. The authority found that this conduct breached data processing principles.ESAEPDGDPR€30,000
10 May 2024EUSKALTEL, S.A.EUSKALTEL, S.A. was fined 400,000 EUR by the AEPD for failing to comply with a resolution requiring access to geolocation data. The authority found a breach of Article 58.2 of the GDPR.ESAEPDGDPR€400,000
01 Jan 2015A.A.A.A.A.A. was fined by the AEPD EUR 600 for sending unsolicited commercial emails advertising airplane insurance. The authority found this breached Article 21.1 of the LSSI on commercial communications without prior consent.ESAEPDePrivacy€600
01 Jan 2015FEVER LABS INCFEVER LABS INC was fined EUR 10,000 by the AEPD for sending unsolicited commercial emails. The authority found that the messages did not include a simple and free way for recipients to opt out of further communications, in breach of the LSSI.ESAEPDePrivacy€10,000
13 Nov 2020B.B.B.The entity was fined EUR 1,500 by the AEPD for improperly installing a surveillance camera. The camera captured images of a public transit area without justified cause, which breached data protection rules.ESAEPDGDPR€1,500
18 Jan 2021MEJORFRESCO TIENDA ONLINE, S.L.MEJORFRESCO TIENDA ONLINE, S.L. was fined by the AEPD EUR 2,000 for sending advertising emails without the recipient's consent. The case concerned Article 21 of the LSSI and reflects unlawful direct marketing practices.ESAEPDePrivacy€2,000