BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Apr 2024 | GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined €10,000 by the AEPD for sending unsolicited advertising SMS messages without providing an opt-out link. The conduct breached the LSSI rules governing electronic marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 24 Oct 2023 | UNIPREX, S.A.UNIPREX, S.A. was fined 50,000 EUR by the AEPD for processing an excessive amount of personal data. The authority found that the data collected went beyond what was necessary for the intended purpose. | ES | AEPD | GDPR | €50,000 | ↗ |
| 20 Sept 2023 | DREAM HOUSE SISTEMAS DE DESCANSO, S.L.DREAM HOUSE SISTEMAS DE DESCANSO, S.L. was fined EUR 2,500 by the AEPD for sending unsolicited advertising SMS messages to a customer who had previously objected. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 29 Nov 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for sending a customer's personal data to the wrong address. The authority found this to be a breach of data security requirements under GDPR Article 5(1)(f). | ES | AEPD | GDPR | €50,000 | ↗ |
| 12 Feb 2021 | ELECTROTECNIA BASTIDA, S.L.ELECTROTECNIA BASTIDA, S.L. was fined by the AEPD 3,000 EUR for leaving employees’ confidential medical information abandoned in a field. The incident constituted a breach of data protection rules and required supervisory action. | ES | AEPD | GDPR | €3,000 | ↗ |
| 30 May 2023 | B.B.B.The entity was fined for keeping an operational surveillance camera inside a rented apartment without informing the tenants. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 05 Mar 2012 | NAUTALIA VIAJES, S.L.NAUTALIA VIAJES, S.L. was fined by the AEPD 1,200 EUR for sending unsolicited commercial messages without prior consent from recipients. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 01 Jan 2022 | INMOBILIARIA MESLLOC, S.L.INMOBILIARIA MESLLOC, S.L. was fined by the AEPD for unlawfully sharing tenants’ personal data with third-party companies without authorization. The authority found this conduct violated Article 6(1) of the GDPR. | ES | AEPD | GDPR | €40,000 | ↗ |
| 08 Jun 2023 | ALTERNATIVA CORELLANA INDEPENDIENTE (ACI)ALTERNATIVA CORELLANA INDEPENDIENTE (ACI) was fined by the AEPD for failing to respond to information requests. The authority treated this as a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 01 Jan 2019 | LINEA DIRECTA ASEGURADORA, S.A.LINEA DIRECTA ASEGURADORA, S.A. was fined by the AEPD for sending unsolicited advertising emails without a prior relationship with the recipient. The authority found this breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 27 Apr 2021 | B.B.B.B.B.B. was fined 500 EUR by the AEPD for installing a surveillance camera. The camera captured common areas and a neighbor's parking space, which breached data protection rules. | ES | AEPD | GDPR | €500 | ↗ |
| 19 Jan 2024 | GEO ALTERNATIVA, S.L.GEO ALTERNATIVA, S.L. was fined by the AEPD for unlawfully processing personal data. The company included a customer's information in a credit file even though an agreement had already been reached regarding the disputed gas bill. | ES | AEPD | GDPR | €20,000 | ↗ |
| 01 Jan 2021 | ASM PRATASM PRAT was fined EUR 5,000 by the AEPD for requiring recipients to submit photos of their ID cards without consent. The company also failed to provide information about the data processing, which breached data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 15 Sept 2022 | ADENET SYSTEMS, S.L.ADENET SYSTEMS, S.L. was fined by the AEPD for obstructing the data protection authority’s inspection. The conduct breached Article 58(1) GDPR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 10 Sept 2024 | HWM PSI, S.L.HWM PSI, S.L. was fined by the AEPD 100 EUR for sending an email to multiple recipients without using BCC. This exposed recipients’ personal email addresses and breached data protection rules. | ES | AEPD | GDPR | €100 | ↗ |
| 26 Apr 2024 | SANTANDER CONSUMER, S.A.SANTANDER CONSUMER, S.A. was fined by the AEPD in the amount of 50,000 EUR for sending postal advertising after the complainant had exercised the right to object to processing for marketing purposes. The case concerns failure to respect the data subject’s objection to commercial use of personal data. | ES | AEPD | GDPR | €50,000 | ↗ |
| 14 Jan 2020 | REAL CLUB NAÚTICO DE RIBADEOREAL CLUB NAÚTICO DE RIBADEO was fined by the AEPD 6,000 EUR for publishing a court judgment containing personal data on its website and Facebook without anonymization. This constituted a breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 07 Feb 2024 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe entity was fined by the AEPD 4,000 EUR for failing to provide access to personal data and the information requested by the data protection authority. The case concerns non-compliance with Article 58.1 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 09 Jul 2025 | REAL SOCIEDAD DE FUTBOL S.A.D.REAL SOCIEDAD DE FUTBOL S.A.D. suffered a ransomware attack that led to a data breach affecting 60,000 individuals, including biometric, identification, financial, and health data. The AEPD fined the company for failing to implement adequate technical and organizational measures to protect data security. | ES | AEPD | GDPR | €60,000 | ↗ |
| 07 Jul 2016 | ORANGE ESPAGNE, S.A.U.Orange Espagne, S.A.U. was fined EUR 4,100 by the AEPD for sending unsolicited advertising calls and SMS messages to a customer who had opted out of such contact. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €4,100 | ↗ |