Guides

AEPD 2026: multi-million euro fines for Vodafone, Amadeus and Aena over GDPR

Spain's Data Protection Agency is collecting record amounts in 2026. The mistakes behind these fines are, at their core, very common ones.

Published on August 31, 2026 · The mitza.es team

Spain's Data Protection Agency (AEPD) has stepped up its inspection activity in 2026, with annual fines already exceeding €40 million. The latest sanctions show that neither company size nor legal budget protects a business from basic mistakes in how it handles personal data.

The most significant fines of the year

  • Vodafone Spain: €1,050,000 for lacking a valid legal basis to process certain personal data.
  • Amadeus IT Group: €14,400,000, one of the highest fines of the year, for combining two violations common among tech companies that aggregate third-party data: processing data without a legal basis and failing to adequately inform those affected.
  • Aena: more than €10,000,000 for deploying facial recognition systems without first carrying out a Data Protection Impact Assessment (DPIA), as required under Article 35 of the GDPR.
  • A banking institution: €890,000 over its AI-based credit scoring system.

A recurring pattern: it's not just the data, it's the process

None of these fines stem from a data breach like the ones we already covered in our piece on the rise in ransomware this year. They all share the same root cause: internal processes that failed to properly document why certain data was being collected, failed to clearly inform users, or skipped assessing the impact of a new technology (facial recognition, AI scoring) before rolling it out.

Why this matters for SME websites too

Although these figures involve large companies, the underlying mistakes are exactly the ones any website with a contact form, a newsletter system or a chatbot can make: collecting data without a clear legal basis, not explaining what it's used for, or adding an AI tool (such as a WhatsApp Business assistant) without first reviewing what data it processes and how that's communicated to the user.

What to review on your own website

  • That every form clearly states what data it collects and what it's used for.
  • That an identifiable legal basis exists for each data processing activity, not just a generic consent checkbox.
  • That any new tool that processes user data (AI included) is reviewed before it goes live, not after.
  • That your privacy policy is up to date and reflects what the website actually does, rather than a generic template.

Prevention is cheaper than correction

This year's figures make clear that the agency is scrutinising things more closely than ever. If you want to know whether your website has a weak point in how it handles data before it becomes a problem, you can request a technical audit that reviews your project's forms, cookies and data flows.

Not sure if your website handles personal data correctly?

We review your forms, cookies and data handling to reduce the risk of a fine.

No spam. No sales calls. Just your personalised reply.