Spain’s AEPD does not issue the biggest GDPR fines — its all-time record, €10 million against Google, is a rounding error next to Meta’s €1.2 billion in Ireland. What Spain issues is the most fines. Year after year it tops the EU by number of penalties, and in 2022 it accounted for roughly 40% of all GDPR fines across the entire EEA by count (Linklaters).
So the AEPD is the regulator to read if you want to know what gets ordinary companies fined — not the once-a-year billion-euro headline, but the steady stream of mid-size penalties against banks, telecoms operators and credit bureaus that actually defines day-to-day GDPR enforcement. This is the registry of its largest cases, with the amounts, the articles, and what each company did. Every figure links to the regulator or the EU mirror of its decision.
Why Spain fines so much more than everyone else
It is not that Spaniards leak more data. Three structural reasons explain the volume:
- A very low barrier to complain. The AEPD makes it easy for any individual to file a claim, and it is obliged to process them. A high inflow of complaints mechanically produces a high outflow of decisions.
- An enforcement-first culture with a fast track. The AEPD resolves large numbers of cases, including through streamlined procedures for clear-cut matters — so volume scales without each case becoming a multi-year inquiry.
- Heavily targeted sectors. Spanish enforcement clusters around banking, telecoms, energy and debt-collection / credit-reference — sectors that process huge volumes of personal data, market aggressively, and generate constant complaints about consent, marketing calls and inaccurate debt records.
The result: Spain is the EU’s volume leader, and its fine list reads less like a Big Tech rogues’ gallery than a who’s-who of national banks and carriers.
Quick guide to the GDPR articles below:
- Art. 5 — the core principles, including lawfulness, fairness and transparency (5(1)(a)).
- Art. 6 — the six lawful bases; you need one. Most AEPD cases turn on a missing or invalid one.
- Art. 13–14 — the duty to give people clear information about how their data is used.
- Art. 17 — the right to erasure (“right to be forgotten”).
- Art. 32 — security of processing (the basis for breach fines like Air Europa).
- LOPDGDD — Ley Orgánica 3/2018, Spain’s law implementing the GDPR, under which the AEPD operates.
The registry — by amount
1. Google LLC — €10,000,000 — May 2022
The AEPD’s largest fine ever, at €10 million. Google was found to have unlawfully transferred users’ personal data to a third party — the “Lumen” research project, which publishes content-removal requests — and to have obstructed the right to erasure by funnelling deletion requests through Lumen rather than honouring them cleanly.
Articles. Article 6 (no valid legal basis for the transfer) and Article 17 (right to erasure).
Source: Lexology — Spanish DPA’s €10 million fine on Google LLC.
2. Vodafone España — €8,150,000 — 11 March 2021
At the time the largest fine in the AEPD’s history, made public on 11 March 2021. It bundled several infringements across multiple proceedings — chiefly unlawful marketing and failures of consent and data governance in Vodafone’s aggressive telemarketing operation.
Articles. Article 6 (legal basis / consent) and related transparency and processor-control duties.
Source: Four Law — the million-euro Vodafone España sanction.
3. CaixaBank — €6,000,000 — January 2021
The bank was fined for unlawful processing of customers’ personal data and for failing to give adequate information about how that data was used — specifically, deficient requirements for valid consent and a flawed consent-collection process.
Articles. Article 6 (legal basis / consent) and Articles 13–14 (information duties).
Source: EDPB — AEPD imposes €6,000,000 fine on CaixaBank.
4. BBVA — €5,000,000 — December 2020
The bank Banco Bilbao Vizcaya Argentaria used vague, unclear terminology to describe its processing in its privacy policy, and sent marketing communications without valid consent — for which the AEPD imposed €5 million.
Articles. Article 5 (transparency) and Article 6 (legal basis / consent).
Source: Lexology — Spanish regulator imposes its highest fines.
5. Equifax Ibérica — €1,000,000 — 26 April 2021
The Spanish arm of the credit-reference bureau Equifax was fined €1 million for five separate GDPR infringements tied to how it processed people’s credit and debt data — the classic Spanish enforcement target, because inaccurate or unlawfully held debt records generate a steady stream of complaints.
Articles. Multiple — lawfulness, data quality and data-subject rights in credit processing.
Source: RGPDblog — AEPD fines Equifax €1 million for five GDPR infringements.
6. Air Europa — €600,000 — 2021
The airline was fined over a data breach that exposed customers’ bank-card details. An aggravating factor weighed heavily: the people affected were not only Spanish users but travellers from around the world whose payment data was exposed to attackers.
Articles. Article 32 (security of processing) and breach-handling duties.
Source: Civio — Vodafone, BBVA, EDP and Mercadona among Spain’s largest data-protection fines.
The pattern: consent, marketing and debt records
Step back from the names and the AEPD’s enforcement has a clear shape — and it is not the same shape as Ireland’s or France’s:
- Banks and telecoms dominate. CaixaBank, BBVA, Vodafone — and across the wider list, Telefónica, Mercadona, energy firm EDP and others. These are companies that hold data on millions of customers and market to them constantly.
- The recurring sin is consent and transparency, not data transfers. Where Ireland fines Big Tech for sending data to the US and France fines everyone for cookies, Spain fines national champions for marketing without valid consent and opaque privacy policies.
- Debt and credit data is a category of its own. Equifax, debt-collectors and credit bureaus appear repeatedly, because in Spain an inaccurate entry in a credit-default register (a fichero de morosos) is a frequent, well-understood complaint.
- Breaches close out the list — Air Europa being the clearest, where a security failure exposed payment data worldwide.
What this means if you do business in Spain
The AEPD will not single you out for being small — it processes volume, and a single well-founded complaint can open a file. The avoidable mistakes are concrete:
- Don’t market without clean consent. The Vodafone, BBVA and CaixaBank fines are, at bottom, marketing-consent fines. If you call, email or SMS customers for marketing, you need consent you can prove and an easy way out.
- Write a privacy policy a normal person can understand. BBVA was fined partly for vague terminology. “We may process your data for various purposes” is not information — it is an invitation to a fine.
- Honour erasure requests properly. Google’s record fine was, in part, about routing deletion through a side channel instead of just complying. When someone asks to be deleted, delete.
- If you hold debt or credit data, keep it accurate and lawful. This is the single most-complained-about category in Spain.
The structural defence is the same everywhere: a clear lawful basis, plain-language information, consent you can evidence and withdraw, and security that holds. The AEPD fines a lot — but it fines for the same handful of failures, over and over.
Sources for independent verification
- AEPD — resoluciones — the regulator’s searchable database of every sanction decision (in Spanish).
- AEPD — Memoria 2025 (official annual report) — the AEPD’s own account of its enforcement year.
- EDPB national news — EU-level mirrors of the biggest AEPD decisions (CaixaBank, Vodafone).
- enforcementtracker.com — CMS Law’s registry; filtering to Spain shows why it tops the EU by fine count.
Short conclusion
Spain is the EU’s enforcement engine by sheer throughput: it fines more often than anyone, and its list is dominated by banks, telecoms and credit bureaus rather than Big Tech. The amounts are mid-size — €5 million to €10 million at the top — but the lesson scales down to any business: the things that get you fined in Spain are marketing without consent, opaque privacy notices, mishandled erasure and inaccurate debt data. None of them require a billion-euro budget to avoid — only the discipline to do consent and transparency properly.