Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Apr 2024GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined €10,000 by the AEPD for sending unsolicited advertising SMS messages without providing an opt-out link. The conduct breached the LSSI rules governing electronic marketing communications.ESAEPDePrivacy€10,000
24 Oct 2023UNIPREX, S.A.UNIPREX, S.A. was fined 50,000 EUR by the AEPD for processing an excessive amount of personal data. The authority found that the data collected went beyond what was necessary for the intended purpose.ESAEPDGDPR€50,000
20 Sept 2023DREAM HOUSE SISTEMAS DE DESCANSO, S.L.DREAM HOUSE SISTEMAS DE DESCANSO, S.L. was fined EUR 2,500 by the AEPD for sending unsolicited advertising SMS messages to a customer who had previously objected. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€2,500
29 Nov 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for sending a customer's personal data to the wrong address. The authority found this to be a breach of data security requirements under GDPR Article 5(1)(f).ESAEPDGDPR€50,000
12 Feb 2021ELECTROTECNIA BASTIDA, S.L.ELECTROTECNIA BASTIDA, S.L. was fined by the AEPD 3,000 EUR for leaving employees’ confidential medical information abandoned in a field. The incident constituted a breach of data protection rules and required supervisory action.ESAEPDGDPR€3,000
30 May 2023B.B.B.The entity was fined for keeping an operational surveillance camera inside a rented apartment without informing the tenants. The authority found this to be a breach of data protection rules.ESAEPDGDPR€6,000
05 Mar 2012NAUTALIA VIAJES, S.L.NAUTALIA VIAJES, S.L. was fined by the AEPD 1,200 EUR for sending unsolicited commercial messages without prior consent from recipients. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€1,200
01 Jan 2022INMOBILIARIA MESLLOC, S.L.INMOBILIARIA MESLLOC, S.L. was fined by the AEPD for unlawfully sharing tenants’ personal data with third-party companies without authorization. The authority found this conduct violated Article 6(1) of the GDPR.ESAEPDGDPR€40,000
08 Jun 2023ALTERNATIVA CORELLANA INDEPENDIENTE (ACI)ALTERNATIVA CORELLANA INDEPENDIENTE (ACI) was fined by the AEPD for failing to respond to information requests. The authority treated this as a breach of Article 58.1 of the GDPR.ESAEPDGDPR€4,000
01 Jan 2019LINEA DIRECTA ASEGURADORA, S.A.LINEA DIRECTA ASEGURADORA, S.A. was fined by the AEPD for sending unsolicited advertising emails without a prior relationship with the recipient. The authority found this breached Article 21 of the LSSI.ESAEPDePrivacy€2,500
27 Apr 2021B.B.B.B.B.B. was fined 500 EUR by the AEPD for installing a surveillance camera. The camera captured common areas and a neighbor's parking space, which breached data protection rules.ESAEPDGDPR€500
19 Jan 2024GEO ALTERNATIVA, S.L.GEO ALTERNATIVA, S.L. was fined by the AEPD for unlawfully processing personal data. The company included a customer's information in a credit file even though an agreement had already been reached regarding the disputed gas bill.ESAEPDGDPR€20,000
01 Jan 2021ASM PRATASM PRAT was fined EUR 5,000 by the AEPD for requiring recipients to submit photos of their ID cards without consent. The company also failed to provide information about the data processing, which breached data protection rules.ESAEPDGDPR€5,000
15 Sept 2022ADENET SYSTEMS, S.L.ADENET SYSTEMS, S.L. was fined by the AEPD for obstructing the data protection authority’s inspection. The conduct breached Article 58(1) GDPR.ESAEPDGDPR€3,000
10 Sept 2024HWM PSI, S.L.HWM PSI, S.L. was fined by the AEPD 100 EUR for sending an email to multiple recipients without using BCC. This exposed recipients’ personal email addresses and breached data protection rules.ESAEPDGDPR€100
26 Apr 2024SANTANDER CONSUMER, S.A.SANTANDER CONSUMER, S.A. was fined by the AEPD in the amount of 50,000 EUR for sending postal advertising after the complainant had exercised the right to object to processing for marketing purposes. The case concerns failure to respect the data subject’s objection to commercial use of personal data.ESAEPDGDPR€50,000
14 Jan 2020REAL CLUB NAÚTICO DE RIBADEOREAL CLUB NAÚTICO DE RIBADEO was fined by the AEPD 6,000 EUR for publishing a court judgment containing personal data on its website and Facebook without anonymization. This constituted a breach of data protection rules.ESAEPDGDPR€6,000
07 Feb 2024GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe entity was fined by the AEPD 4,000 EUR for failing to provide access to personal data and the information requested by the data protection authority. The case concerns non-compliance with Article 58.1 of the GDPR.ESAEPDGDPR€4,000
09 Jul 2025REAL SOCIEDAD DE FUTBOL S.A.D.REAL SOCIEDAD DE FUTBOL S.A.D. suffered a ransomware attack that led to a data breach affecting 60,000 individuals, including biometric, identification, financial, and health data. The AEPD fined the company for failing to implement adequate technical and organizational measures to protect data security.ESAEPDGDPR€60,000
07 Jul 2016ORANGE ESPAGNE, S.A.U.Orange Espagne, S.A.U. was fined EUR 4,100 by the AEPD for sending unsolicited advertising calls and SMS messages to a customer who had opted out of such contact. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€4,100