BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2022 | B.B.B.B.B.B. was fined 2,000 EUR by the AEPD. The authority found that the company forwarded emails containing personal data without proper authorization, in breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 20 Jun 2022 | PLANET COSTA DORADA SOCIEDAD LIMITADAThe company was fined by the AEPD EUR 300 for operating video surveillance that captured public space without proper signage. The authority found a breach of GDPR Articles 5 and 13. | ES | AEPD | GDPR | €300 | ↗ |
| 01 Jan 2023 | CLUB VOLEIBOL ***CLUB.1The club was fined by the AEPD in the amount of EUR 500 for publishing minors' images without proper consent. The authority also found that the club failed to provide access to personal data requested by a parent. | ES | AEPD | GDPR | €500 | ↗ |
| 25 Oct 2016 | CENTROS COMERCIALES CARREFOUR, S.A.CENTROS COMERCIALES CARREFOUR, S.A. was fined EUR 7,000 by the AEPD for sending unsolicited commercial emails. The authority also found that the company failed to provide a proper opt-out mechanism, breaching Article 21 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 06 Mar 2020 | B.B.B.A private individual was fined by the AEPD €1,000 for installing surveillance cameras without the required informational signage. The case concerned a breach of data protection rules linked to proper notice for video surveillance. | ES | AEPD | GDPR | €1,000 | ↗ |
| 12 Jul 2023 | B.B.B.The entity installed a surveillance camera without authorization and captured images of communal areas. This breached Article 6(1) GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 21 Apr 2023 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. EUR 70,000 for allowing a SIM card swap without the user's consent. The incident enabled unauthorized access to the customer's bank information and resulted in a fraudulent bank transfer. | ES | AEPD | GDPR | €70,000 | ↗ |
| 06 Mar 2025 | AVENTURA EN TRAMPOLINES S.L.AVENTURA EN TRAMPOLINES S.L. was fined 900 EUR by the AEPD for failing to comply with data protection authority resolutions. The case concerned Article 58(2) GDPR, which requires cooperation with the supervisory authority. | ES | AEPD | GDPR | €900 | ↗ |
| 12 May 2020 | B.B.B.B.B.B. was fined by the AEPD in the amount of 2,000 EUR for installing a video surveillance system without justified cause. The measure infringed a tenant’s privacy and resulted in unlawful processing of personal data. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2012 | VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined by the AEPD in the amount of EUR 44,001 for sending unsolicited commercial communications to a non-customer. The authority found this conduct to be in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €44,001 | ↗ |
| 03 Feb 2022 | FLORAQUEEN FLOWERING THE WORLD S.L.FLORAQUEEN FLOWERING THE WORLD S.L. was fined 3,000 EUR by the AEPD for failing to provide requested information. The case concerned the duty to cooperate with the Spanish data protection authority under GDPR Article 58(1). | ES | AEPD | GDPR | €3,000 | ↗ |
| 01 Jan 2015 | BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending an unsolicited commercial email to an individual who had not consented to receive such communications. The case concerns a breach of rules on marketing communications and recipient consent. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 10 Jan 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 30,000 for a data protection breach. A customer's data was incorrectly linked to another person, which allowed unauthorized access to personal information. | ES | AEPD | GDPR | €30,000 | ↗ |
| 13 Jul 2023 | EUROPA PRESS DE CATALUNYA, S.A.EUROPA PRESS DE CATALUNYA, S.A. was fined by the AEPD 50,000 EUR for publishing audio of a victim's court statement in a high-profile case. The authority found that the company processed excessive personal data in breach of GDPR Article 5(1)(c). | ES | AEPD | GDPR | €50,000 | ↗ |
| 28 Mar 2022 | VUELING AIRLINES, S.A.Vueling Airlines, S.A. was fined EUR 30,000 by the AEPD for breaching data protection rules. The company required customers to accept commercial data sharing in order to purchase tickets on its website, without providing an option to refuse cookies. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 01 Jul 2010 | TELEFONICA MOVILES ESPAÑA S.A.U.TELEFONICA MOVILES ESPAÑA S.A.U. was fined by the AEPD EUR 50,000 for sending unsolicited SMS advertisements without proper consent. The conduct breached Article 21.2 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €50,000 | ↗ |
| 20 Nov 2024 | B.B.B.B.B.B. was fined by the AEPD EUR 300 for sending a marketing email to multiple recipients without using BCC. This exposed recipients’ email addresses to each other and breached data protection principles. | ES | AEPD | GDPR | €300 | ↗ |
| 11 Oct 2017 | SANTANDER CONSUMER EFC, S.A.SANTANDER CONSUMER EFC, S.A. was fined by the AEPD for sending promotional SMS messages without the recipient’s consent. The authority also noted that the messages were sent despite the recipient’s objection to receiving advertising. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 01 Jan 2022 | MUXERS CONCEPT, S.L.MUXERS CONCEPT, S.L. was fined EUR 20,000 by the AEPD for installing an unauthorized audio recording system in employee areas. The authority found this conduct to be in breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE SALAMANCA, S.C.C.CAJA RURAL DE SALAMANCA, S.C.C. was fined by the AEPD 250,000 EUR for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident. | ES | AEPD | GDPR | €250,000 | ↗ |