Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Jan 2020REAL CLUB NAÚTICO DE RIBADEOREAL CLUB NAÚTICO DE RIBADEO was fined by the AEPD 6,000 EUR for publishing a court judgment containing personal data on its website and Facebook without anonymization. This constituted a breach of data protection rules.ESAEPDGDPR€6,000
07 Feb 2024GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe entity was fined by the AEPD 4,000 EUR for failing to provide access to personal data and the information requested by the data protection authority. The case concerns non-compliance with Article 58.1 of the GDPR.ESAEPDGDPR€4,000
09 Jul 2025REAL SOCIEDAD DE FUTBOL S.A.D.REAL SOCIEDAD DE FUTBOL S.A.D. suffered a ransomware attack that led to a data breach affecting 60,000 individuals, including biometric, identification, financial, and health data. The AEPD fined the company for failing to implement adequate technical and organizational measures to protect data security.ESAEPDGDPR€60,000
07 Jul 2016ORANGE ESPAGNE, S.A.U.Orange Espagne, S.A.U. was fined EUR 4,100 by the AEPD for sending unsolicited advertising calls and SMS messages to a customer who had opted out of such contact. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€4,100
29 Apr 2022EDITORIAL PRENSA CANARIA, S.A.The company was fined by the AEPD 50,000 EUR for publishing audio of a victim's testimony in a high-profile court case. The authority found a breach of data protection principles.ESAEPDGDPR€50,000
06 Mar 2020BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for inaccurate processing of personal data. The bank demanded payment for a debt the complainant did not owe and shared the complainant’s personal data with a debt collection agency.ESAEPDGDPR€60,000
02 Feb 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for changing a customer's contract ownership and activating services without consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€200,000
08 Jun 2017THE PHONE HOUSE SPAIN, S.L.U.THE PHONE HOUSE SPAIN, S.L.U. was fined by the AEPD 2,500 EUR for sending commercial text messages without providing recipients with a simple and free way to object to the processing of their data for promotional purposes. The case concerned non-compliance with the LSSI rules on marketing communications.ESAEPDePrivacy€2,500
27 Jul 2012VIPVENTA, S.L.VIPVENTA, S.L. was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails to the complainant. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,001
06 Jun 2020GLOBAL BUSINESS TRAVEL SPAIN S.L.U.An employee of GLOBAL BUSINESS TRAVEL SPAIN S.L.U. improperly accessed and disclosed an individual's health data. The AEPD found this to be a breach of the integrity and confidentiality principles under data protection law.ESAEPDGDPR€5,000
08 Jul 2024CALLBELL S.A.S.CALLBELL S.A.S. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial messages to a complainant despite a request to stop. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
03 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined EUR 20,000 by the AEPD for continuing to send newsletters to the complainant despite multiple unsubscribe requests. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€20,000
02 Jul 2020CENTRO INTERNACIONAL DE CRECIMIENTO LABORAL Y PROFESIONAL, S.L.The entity sent unsolicited commercial emails without the recipients’ consent. It also failed to provide a valid unsubscribe option, which breached the LSSI.ESAEPDePrivacy€1,000
01 Sept 2020B.B.B.The entity was fined by the AEPD €5,000 for using a webcam to record video and audio without justification. The conduct infringed privacy by monitoring private conversations and activities inside a rented residence.ESAEPDGDPR€5,000
31 May 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 70,000 EUR for failing to implement adequate security measures. This allowed a third party to impersonate a customer, change contact details, and gain unauthorized access to personal and banking data.ESAEPDGDPR€70,000
01 Jun 2021RADIO POPULAR S.A.RADIO POPULAR S.A. was fined EUR 2,000 by the AEPD for not providing users with the option to reject cookies on its website. The authority found this practice non-compliant with data protection rules and consent requirements.ESAEPDePrivacy€2,000
03 May 2016REAL AUTOMOVIL CLUB DE ESPAÑAREAL AUTOMOVIL CLUB DE ESPAÑA was fined by the AEPD EUR 1,000 for sending unsolicited commercial emails despite the recipient's requests to unsubscribe. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
13 Feb 2023FUNDACIÓN PRIVADA UNIVERSITARIA EADAThe entity used a participant’s image in a promotional activity without obtaining consent. This constituted a breach of data protection rules and resulted in a fine imposed by the AEPD.ESAEPDGDPR€2,000
01 Jan 2015WERBUNG INTERNET S.L.WERBUNG INTERNET S.L. was fined by the AEPD €1,000 for sending unsolicited commercial emails without prior consent. The conduct breached Article 21.1 of the LSSI on electronic marketing communications.ESAEPDePrivacy€1,000
17 Nov 2020PEDROSO Y GÓMEZ ASESORÍA DE EMPRESAS, S.L.The company was fined by the AEPD in the amount of 6,000 EUR for sending emails without the recipients' consent. The authority also noted the absence of contact information for exercising data protection rights.ESAEPDGDPR€6,000