Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Jul 2012NH HOTELES, S.A.NH HOTELES, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant after confirming the cancellation of their personal data. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€33,001
29 Apr 2022RADIO TELEVISION MADRID, S.A.RADIO TELEVISION MADRID, S.A. was fined by the AEPD 50,000 EUR for processing excessive personal data. The case concerned the publication of audio of a victim's court statement in a high-profile case, which breached the data minimization principle.ESAEPDGDPR€50,000
25 Jul 2019SOCIEDAD ESTATAL CORREOS Y TELEGRAFOS. S.A.The entity delivered correspondence to the wrong recipient, which constitutes a breach of the data protection principles in Article 5 of the GDPR. AEPD imposed a fine of EUR 40,000.ESAEPDGDPR€40,000
01 Jan 2012NECESIDADES INFORMATICAS, S.L.NECESIDADES INFORMATICAS, S.L. was fined EUR 600 by the AEPD for sending a commercial email without the recipient’s prior consent. The conduct breached Article 21.1 of the LSSI, which prohibits unsolicited marketing communications.ESAEPDePrivacy€600
01 Jan 2013UNIQ IT CONSULTORS S.L.UNIQ IT CONSULTORS S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails without prior consent from recipients. The conduct breached Article 21 of the LSSI on marketing communications.ESAEPDePrivacy€600
10 Jun 2022WATYANA 786, S. L.WATYANA 786, S. L. was fined by the AEPD EUR 400 for failing to inform individuals about the use of video surveillance at its premises. The authority found a breach of Article 13 GDPR because the required information was not provided to data subjects.ESAEPDGDPR€400
13 Feb 2023B.B.B.B.B.B. was fined by the AEPD in the amount of EUR 2,000 for breaching Article 6 of the GDPR. The case concerned the unauthorized dissemination of a video on social media platforms, including Twitter.ESAEPDGDPR€2,000
02 Nov 2010VODAFONE ESPAÑA, S.A.VODAFONE ESPAÑA, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial communications in breach of Article 21 of the LSSI. The infringement was classified as serious because a technical error resulted in 18 such messages being sent.ESAEPDePrivacy€30,001
01 Jan 2019VODAFONE ESPAÑA, S.A.U.The AEPD imposed a fine of EUR 55,000 on Vodafone España, S.A.U. for breaching data protection principles. The case involved sending a customer's personal data to a third party without adequate security measures.ESAEPDGDPR€55,000
31 May 2024MAPFRE INVERSIÓN SOCIEDAD DE VALORES, S.AMAPFRE INVERSIÓN SOCIEDAD DE VALORES, S.A was fined EUR 300,000 by the AEPD. The authority found that the company carried out unauthorized investment transactions using personal data without consent, in breach of data protection rules.ESAEPDGDPR€300,000
01 Jan 2023LOCAL VERTICALS, S.L.The company was fined by the AEPD in the amount of 10,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€10,000
01 Jan 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 100,000 EUR for allowing a third party to impersonate a customer. This led to a mobile line portability request and the purchase of a mobile device without the customer’s consent.ESAEPDGDPR€100,000
01 Jan 2013MIPE COMUNICATION, S.L.MIPE COMUNICATION, S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails without recipient consent. The authority also found that the messages did not include an opt-out mechanism, in breach of Article 21 of the LSSI.ESAEPDePrivacy€600
27 May 2024KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD 10,000 EUR for requiring a customer to provide a photo with their ID to cancel a loan. The authority found that this processing breached GDPR principles of data minimisation and proportionality.ESAEPDGDPR€10,000
31 Mar 2015VACACIONES EDREAMS, S.L.U.VACACIONES EDREAMS, S.L.U. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails despite the recipient’s request to unsubscribe. The case concerned a breach of Article 21.1 of the LSSI and shows failure to respect an opt-out request for direct marketing.ESAEPDePrivacy€2,500
23 Jan 2017BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€3,300
20 Apr 2021B.B.B.The entity was fined for not providing an adequate privacy policy on its website. This constituted a breach of Article 13 of the GDPR, which requires proper information to be provided to data subjects.ESAEPDGDPR€2,000
16 Feb 2016ROCK INTERNET, S.L.ROCK INTERNET, S.L. was fined EUR 30,000 by the AEPD for sending unsolicited commercial emails despite the recipient’s repeated requests to unsubscribe. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,000
13 Sept 2012YVES ROCHER ESPAÑA, S.A.YVES ROCHER ESPAÑA, S.A. was fined EUR 47,001 by the AEPD for continuing to send advertising emails to an individual who had requested data deletion and confirmation of that deletion. The authority found that marketing communications continued despite the request.ESAEPDePrivacy€47,001
09 May 2023TELEFÓNICA SERVICIOS INTEGRALES DE DISTRIBUCIÓN, S.A.ZELERIS, a Telefónica subsidiary, was fined by the AEPD for delivering a package containing personal data to the wrong address without consent. The case indicates a breach of data protection rules in the handling and delivery of shipments.ESAEPDGDPR€70,000