Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2020BANCO DE SABADELL, S.A.Banco de Sabadell was fined for sending a commercial email to a customer who had previously opted out of such communications. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications.ESAEPDePrivacy€5,000
01 Jan 2020Caja Rural San José de Nules S. Cooperativa de Crédito de la Comunidad ValencianaCaja Rural San José de Nules was fined by the AEPD 5,000 EUR for publicly displaying individuals’ personal data on a notice board. The conduct breached data protection principles by exposing their economic status.ESAEPDGDPR€5,000
01 Jan 2020PERSONAL MARK, S.L.PERSONAL MARK, S.L. was fined by the AEPD 10,000 EUR for failing to diligently delete personal data from its databases despite the complainant’s requests. The case indicates inadequate handling of data erasure obligations.ESAEPDGDPR€10,000
01 Jan 2020DOUGLAS SPAIN, S.A.U.DOUGLAS SPAIN, S.A.U. was fined by the AEPD 2,700 EUR for continuing to send advertising emails to a complainant after confirming deletion of the complainant’s personal data. The authority found this breached Article 21 of the LSSI.ESAEPDePrivacy€2,700
01 Jan 2020XFERA MÓVILES, S.A. (MASMOVIL)XFERA MÓVILES, S.A. (MASMOVIL) was fined by the AEPD for processing personal data without a lawful basis, in breach of Article 6 GDPR. The case indicates that the company lacked a valid legal ground for the processing activity.ESAEPDGDPR€60,000
01 Jan 2020GROUPALIA COMPRA COLECTIVA, S.L.GROUPALIA COMPRA COLECTIVA, S.L. was fined by the AEPD for sending unsolicited advertising emails. The conduct infringed the complainant's rights despite the complainant being listed on the Robinson list and the company having been previously sanctioned for similar conduct.ESAEPDePrivacy€1,800
01 Jan 2020Lycamobile, S.L.Lycamobile, S.L. was fined by the AEPD 60,000 EUR for falsifying the personal data of prepaid card users. The case concerns a breach of data protection rules.ESAEPDGDPR€60,000
01 Jan 2020VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 50,000 EUR for sending unsolicited promotional SMS messages. The messages were sent despite the complainant having exercised the right to object and request deletion of their data, which breached Article 21 of the LSSI.ESAEPDePrivacy€50,000
01 Jan 2020CENTRO DE DIAGNÓSTICO ***LOCALIDAD.1, S.A.The entity was fined for breaching data confidentiality by improperly sharing medical information between different entities without consent. The case involved sensitive data processing and a lack of a valid legal basis for the disclosure.ESAEPDGDPR€10,000
01 Jan 2020GOOGLE LLCGoogle LLC was fined by the AEPD EUR 5,000,000 for the unauthorized communication of personal data to the “Lumen Project”. The authority found breaches of the right to erasure and the GDPR requirement for lawful processing.ESAEPDGDPR€5,000,000
01 Jan 2020Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined EUR 70,000 by the AEPD for unauthorized charges on a customer's account. The authority found a breach of Article 6(1) GDPR, indicating processing without a valid legal basis.ESAEPDGDPR€70,000
01 Jan 2020SIGNALLIA MARKETING DISTRIBUTION, S.A.SIGNALLIA MARKETING DISTRIBUTION, S.A. was fined by the AEPD 100,000 EUR for failing to provide access to servers and data. The authority found a breach of Article 28(3)(g) GDPR.ESAEPDGDPR€100,000
01 Jan 2020JUST LANDED, S.L.JUST LANDED, S.L. was fined EUR 3,000 by the AEPD for failing to provide a privacy policy and a cookie policy on its website. The authority cited a breach of GDPR Article 13 and LSSI Article 22.2.ESAEPDePrivacy€3,000
01 Jan 2020VOLTIMUM, S.A.VOLTIMUM, S.A. was fined EUR 2,000 by the AEPD for sending commercial emails after the recipient had opted out. The authority found this to be a breach of Article 21 of the LSSI on marketing communications.ESAEPDePrivacy€2,000
01 Jan 2020ARGAN-LET, S.L.ARGAN-LET, S.L. was fined 900 EUR by the AEPD for sending unsolicited commercial SMS messages without prior consent. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€900
01 Jan 2020DESOLASOL RESTAURACIÓN, S.L.The restaurant disclosed a customer's complaint form to other patrons, breaching data protection principles. The case involved unauthorized disclosure of personal information contained in the complaint document.ESAEPDGDPR€6,000
01 Jan 2020GROW BEATS SL.GROW BEATS SL. was fined 3,000 EUR by the AEPD for failing to provide required privacy policy information and for improper use of cookies without user consent. The case concerned website practices and indicates deficiencies in notice and consent requirements.ESAEPDePrivacy€3,000
01 Jan 2020RADIOTELEVISIÓN DEL PRINCIPADO DE ASTURIASRADIOTELEVISIÓN DEL PRINCIPADO DE ASTURIAS was fined by the AEPD 20,000 EUR for retaining and processing images without a proper legal basis. The authority found a breach of data protection principles.ESAEPDGDPR€20,000
06 Jan 2020дружество за комунални услугиThe utility company processed the complainant’s personal data without a lawful basis by sharing it with a private bailiff for enforcement proceedings. CPDP imposed a fine of 10,000 BGN for breaching Article 6 GDPR.BGCPDPGDPR€5,113
07 Jan 2020CHENMING YE (BAZAR REAL)CHENMING YE (BAZAR REAL) was fined EUR 900 by the AEPD. The authority found that the required visible notice identifying the data controller was missing, which breached data protection rules.ESAEPDGDPR€900