Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2022B.B.B.B.B.B. was fined 2,000 EUR by the AEPD. The authority found that the company forwarded emails containing personal data without proper authorization, in breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
20 Jun 2022PLANET COSTA DORADA SOCIEDAD LIMITADAThe company was fined by the AEPD EUR 300 for operating video surveillance that captured public space without proper signage. The authority found a breach of GDPR Articles 5 and 13.ESAEPDGDPR€300
01 Jan 2023CLUB VOLEIBOL ***CLUB.1The club was fined by the AEPD in the amount of EUR 500 for publishing minors' images without proper consent. The authority also found that the club failed to provide access to personal data requested by a parent.ESAEPDGDPR€500
25 Oct 2016CENTROS COMERCIALES CARREFOUR, S.A.CENTROS COMERCIALES CARREFOUR, S.A. was fined EUR 7,000 by the AEPD for sending unsolicited commercial emails. The authority also found that the company failed to provide a proper opt-out mechanism, breaching Article 21 of the LSSI.ESAEPDePrivacy€7,000
06 Mar 2020B.B.B.A private individual was fined by the AEPD €1,000 for installing surveillance cameras without the required informational signage. The case concerned a breach of data protection rules linked to proper notice for video surveillance.ESAEPDGDPR€1,000
12 Jul 2023B.B.B.The entity installed a surveillance camera without authorization and captured images of communal areas. This breached Article 6(1) GDPR.ESAEPDGDPR€300
21 Apr 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. EUR 70,000 for allowing a SIM card swap without the user's consent. The incident enabled unauthorized access to the customer's bank information and resulted in a fraudulent bank transfer.ESAEPDGDPR€70,000
06 Mar 2025AVENTURA EN TRAMPOLINES S.L.AVENTURA EN TRAMPOLINES S.L. was fined 900 EUR by the AEPD for failing to comply with data protection authority resolutions. The case concerned Article 58(2) GDPR, which requires cooperation with the supervisory authority.ESAEPDGDPR€900
12 May 2020B.B.B.B.B.B. was fined by the AEPD in the amount of 2,000 EUR for installing a video surveillance system without justified cause. The measure infringed a tenant’s privacy and resulted in unlawful processing of personal data.ESAEPDGDPR€2,000
01 Jan 2012VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined by the AEPD in the amount of EUR 44,001 for sending unsolicited commercial communications to a non-customer. The authority found this conduct to be in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€44,001
03 Feb 2022FLORAQUEEN FLOWERING THE WORLD S.L.FLORAQUEEN FLOWERING THE WORLD S.L. was fined 3,000 EUR by the AEPD for failing to provide requested information. The case concerned the duty to cooperate with the Spanish data protection authority under GDPR Article 58(1).ESAEPDGDPR€3,000
01 Jan 2015BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending an unsolicited commercial email to an individual who had not consented to receive such communications. The case concerns a breach of rules on marketing communications and recipient consent.ESAEPDePrivacy€5,000
10 Jan 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 30,000 for a data protection breach. A customer's data was incorrectly linked to another person, which allowed unauthorized access to personal information.ESAEPDGDPR€30,000
13 Jul 2023EUROPA PRESS DE CATALUNYA, S.A.EUROPA PRESS DE CATALUNYA, S.A. was fined by the AEPD 50,000 EUR for publishing audio of a victim's court statement in a high-profile case. The authority found that the company processed excessive personal data in breach of GDPR Article 5(1)(c).ESAEPDGDPR€50,000
28 Mar 2022VUELING AIRLINES, S.A.Vueling Airlines, S.A. was fined EUR 30,000 by the AEPD for breaching data protection rules. The company required customers to accept commercial data sharing in order to purchase tickets on its website, without providing an option to refuse cookies.ESAEPDePrivacy€30,000
01 Jul 2010TELEFONICA MOVILES ESPAÑA S.A.U.TELEFONICA MOVILES ESPAÑA S.A.U. was fined by the AEPD EUR 50,000 for sending unsolicited SMS advertisements without proper consent. The conduct breached Article 21.2 of the LSSI on electronic marketing communications.ESAEPDePrivacy€50,000
20 Nov 2024B.B.B.B.B.B. was fined by the AEPD EUR 300 for sending a marketing email to multiple recipients without using BCC. This exposed recipients’ email addresses to each other and breached data protection principles.ESAEPDGDPR€300
11 Oct 2017SANTANDER CONSUMER EFC, S.A.SANTANDER CONSUMER EFC, S.A. was fined by the AEPD for sending promotional SMS messages without the recipient’s consent. The authority also noted that the messages were sent despite the recipient’s objection to receiving advertising.ESAEPDePrivacy€8,000
01 Jan 2022MUXERS CONCEPT, S.L.MUXERS CONCEPT, S.L. was fined EUR 20,000 by the AEPD for installing an unauthorized audio recording system in employee areas. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€20,000
23 Jan 2024CAJA RURAL DE SALAMANCA, S.C.C.CAJA RURAL DE SALAMANCA, S.C.C. was fined by the AEPD 250,000 EUR for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident.ESAEPDGDPR€250,000