Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Apr 2010CRISER INTERACTIVE, S.L.CRISER INTERACTIVE, S.L. was fined by the AEPD 1,200 EUR for sending unsolicited commercial emails. The authority found that recipients were not given a simple and free way to object to the processing of their data, in breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200
26 Oct 2020***EMPRESA.1.The company was fined by the AEPD 10,000 EUR for sending an email containing personal data of a former employee to a third party without authorization. The case involved a breach of data protection principles and unauthorized disclosure of information.ESAEPDGDPR€10,000
29 Oct 2024AUTOMOCIÓN 1972, S.L.AUTOMOCIÓN 1972, S.L. was fined by the AEPD in the amount of 2,000 EUR for failing to comply with a data access request. The authority found a breach of GDPR obligations.ESAEPDGDPR€2,000
27 Apr 2023ADENET SYSTEMS, S.L.ADENET SYSTEMS, S.L. was fined EUR 6,000 by the AEPD for failing to provide access. The authority treated this as a breach of Article 58(1) GDPR and an obstruction of its investigative functions.ESAEPDGDPR€6,000
15 Feb 2022ASOCIACIÓN DE AFICIONADOS Y PEQUEÑOS ACCIONISTAS UNIDAD HERCULANAThe organization was fined by the AEPD 3,000 EUR for failing to provide a privacy policy compliant with Article 13 of the GDPR on its website. It collected personal data through various forms but did not provide the required information to data subjects.ESAEPDGDPR€3,000
13 Feb 2024DIGIMAN ALICANTE, S.L.DIGIMAN ALICANTE, S.L. was fined by the AEPD 1,000 EUR for operating a video surveillance system without the required signage. The authority found that the lack of notice breached the information obligations under GDPR Article 13.ESAEPDGDPR€1,000
01 Jan 2021MARINS PLAYA, S.A.MARINS PLAYA, S.A. was fined by the AEPD in the amount of EUR 30,000 for unlawfully scanning a customer's passport during hotel registration. The authority found that this breached Article 6 of the GDPR because there was no valid legal basis for the processing.ESAEPDGDPR€30,000
19 Jun 2015TEKOA CANALTV, S.L.TEKOA CANALTV, S.L. was fined by the AEPD in the amount of 55,000 EUR for sending 25 commercial SMS messages without prior consent from recipients. The authority also noted the absence of an opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€55,000
22 Nov 2023ASOCIACIÓN COMUNIDAD DE VECINOS R.R.R.The association unlawfully processed personal data by sending all members a letter containing personal details of a person who was not part of the association. The authority found a breach of Article 6(1) GDPR and imposed a fine.ESAEPDGDPR€1,000
16 Sept 2010VODAFONE ESPAÑA, S.A.Vodafone España, S.A. was fined by the AEPD 30,001 EUR for sending unsolicited advertising SMS messages to a complainant who had opted out of such communications. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
01 Mar 2022VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for failing to adequately prevent unauthorized SIM card duplication. The incident enabled fraudulent access and transactions on a customer's accounts.ESAEPDGDPR€140,000
02 Sept 2022B.B.B.The entity was fined by the AEPD 500 EUR for using a video surveillance system that captured an excessive area of public space. In addition, recordings were published on social media without proper authorization or legal basis.ESAEPDGDPR€500
22 Apr 2022CÍTRICOS TANTA, S.L.CÍTRICOS TANTA, S.L. was fined by the AEPD for processing personal data without consent. The case involved registering an individual in the Social Security system without their knowledge or agreement.ESAEPDGDPR€5,000
28 Nov 2022GAVANOVA DE IMMOBLES, S.L.GAVANOVA DE IMMOBLES, S.L. was fined by the AEPD 2,000 EUR for failing to provide an adequate privacy policy on its website. The authority also found that personal data was shared with a cleaning company without the data subjects’ consent.ESAEPDGDPR€2,000
30 Apr 2014COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD 3,000 EUR for sending unsolicited and misleading commercial messages by electronic means. The authority found a breach of Article 21 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€3,000
09 Jul 2023PROSULTING, S.L.N.E.PROSULTING, S.L.N.E. was fined by the AEPD in the amount of 1,000 EUR for failing to provide data subjects with the information required under Article 13 GDPR. The case concerned a lack of proper notice about the processing of personal data.ESAEPDGDPR€1,000
01 Jan 2021MAX2PROTECT, S.L.MAX2PROTECT, S.L. was fined by the AEPD 4,000 EUR for sending spam emails without recipient consent. The authority also found unlawful processing of personal data collected from public websites without proper legal basis.ESAEPDGDPR€4,000
20 Apr 2016TELEFÓNICA DE ESPAÑA, S.A.U.Telefónica de España, S.A.U. was fined by the AEPD in the amount of 12,000 EUR for continuing to send advertising to a complainant despite repeated requests to stop. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€12,000
22 Jan 2024ASILO DE ANCIANOS SANTO DOMINGO Y SANTA ELOISAThe organization was fined for repeatedly sending emails with visible recipient addresses. The case involved a breach of data protection principles and a failure to implement adequate security measures.ESAEPDGDPR€1,000
25 May 2018Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the AEPD for sending unsolicited commercial SMS messages to a non-customer without consent. The case concerns a breach of direct marketing rules and the requirement to obtain prior consent.ESAEPDePrivacy€3,300