Yes, European regulators fine companies for marketing emails sent without a valid legal basis. Of the five email cases below, four are under 1 million EUR. The fifth, 50 million EUR, hit France's leading telecom operator.
France's CNIL fined Solocal Marketing Services 900,000 EUR in May 2025 for email and SMS prospecting on data bought from brokers.
The UK's ICO fined ZMLUK Limited 105,000 GBP in January 2026 for almost 68 million emails sent mostly to people whose "consent" came from a third-party website. In Spain, fines across all marketing cases in 2024 and 2025 reportedly average about 12,000 EUR.
Most of these cases were marketing to consumers, and none is described as a plain B2B cold email to a work address. Whether B2B email needs consent at all depends on the country.
The common thread in the email cases is permission: the sender had none, could not prove it, or got it secondhand from another company.
Every decision below links to the regulator's own announcement, or to the named press or legal source where I say so. Checked 27 September 2026. This is not legal advice.
Which companies were fined, and for what?
Sorted by date, with the two Spanish file-number cases at the end. Five involve email. The two Enel rows are phone telemarketing and the Allay row is SMS.
I kept Allay because it was fined in the same ICO action as ZMLUK, and Enel because it shows what can happen to a fine after the headline.
| Date | Regulator | Company | Fine | Channel | What the sender did | Source |
|---|---|---|---|---|---|---|
| Announced 19 Jan 2022 | Garante, Italy | Enel Energia | 26,513,977 EUR | Phone | Promotional calls without consent, including to numbers on the national opt-out register, and poor handling of rights requests. Annulled by the Rome court (reported Feb 2023); annulment set aside by the Court of Cassation on 8 Jul 2025, remand pending. | Garante, CorCom |
| 8 Feb 2024 | Garante, Italy | Enel Energia | 79,107,101 EUR | Phone | Weak protection of customer databases let unauthorized sales agents run telemarketing. At least 9,300 contracts activated. It also acquired 978 contracts from four companies outside its sales network. Upheld in full by the Court of Rome on 18 Sep 2025, appeal pending. | Garante |
| 14 Nov 2024 | CNIL, France | Orange | 50,000,000 EUR | Email inbox | Showed ads styled as emails among real emails in users' webmail inboxes, without consent. Seen by more than 7.8 million people. A separate cookie breach is in the same fine. | CNIL |
| 15 May 2025 | CNIL, France | Solocal Marketing Services | 900,000 EUR | Email and SMS | Ran prospecting campaigns for its customers on data bought from brokers whose forms pushed people to accept. The consent was not valid, and for one main supplier it could not show proof at all. Also ordered to stop, with 10,000 EUR per day if not fixed within 9 months. | CNIL |
| Announced 20 Jan 2026 | ICO, UK | ZMLUK Limited | 105,000 GBP | Sent 67,772,285 marketing emails from January to July 2023, on behalf of another company. The data came mainly from a third-party website that showed people 361 "partner" companies with no way to choose among them. | ICO | |
| Announced 20 Jan 2026 | ICO, UK | Allay Claims Ltd | 120,000 GBP | SMS | Sent 4,046,947 texts promoting PPI tax refund services from February 2023 to February 2024. Later claimed they were service updates. The ICO found they were marketing. | ICO |
| File year 2024 | AEPD, Spain (PS/00220/2024) | Not named in the report | 60,000 EUR | Mass email to a purchased database. | Legiscope | |
| File year 2023 | AEPD, Spain (PS/00345/2023) | Not named in the report | 25,000 EUR | Emailed existing customers about products that were not similar enough to use the existing-customer exception. | Legiscope |
Dates are decision dates unless marked as announced. The two Spanish rows come from a compliance software company's summary of AEPD resolutions by file number, so treat them as reported rather than read from the decision text.
Everything else links to the regulator itself, except the report of the Rome court annulment, which comes from the Italian trade press.
Why Enel is on the list twice
Enel Energia shows why a headline number is not always the final number. The 26.5 million EUR fine announced in January 2022 was annulled by the Rome civil court, as CorCom reported in February 2023.
That was not the end of it. The Garante's own page on the decision records that on 8 July 2025 the Court of Cassation, ruling on the regulator's appeal, set that annulment aside and sent the case back. Those remand proceedings are still pending, so the 2022 fine is neither final nor gone.
Two years after the first fine, the Garante fined the same company 79,107,101 EUR, which the regulator called the highest fine it had ever issued. The Court of Rome upheld that one in full in September 2025, and the Garante's page notes that an appeal is still pending.
So when you see a fine quoted without a date or a status, check both, and check them again later.
Three of these were not GDPR fines at all
It is easy to call every fine in this table a GDPR fine. Several were decided under a country's own electronic marketing law instead, or under both.
- Orange: CNIL treated the inbox ads as "direct prospecting by email" under Article L.34-5 of France's Post and Electronic Communications Code, which needs consent. The cookie breach fell under the French Data Protection Act. CNIL's announcement cites no GDPR article.
- ZMLUK and Allay: regulation 22 of the UK's Privacy and Electronic Communications Regulations (PECR), the only law the ICO's announcement cites.
- Solocal: the same French article plus GDPR. The broker forms could not produce valid consent, and Solocal could not prove consent for one main supplier's data (GDPR Article 7).
- The Spanish cases: Legiscope describes email marketing in Spain as a double regime, article 21 of the LSSI-CE plus GDPR.
GDPR itself does give direct marketing an opening. Recital 47 says: "The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest."
The same recital adds that a legitimate interest "would need careful assessment including whether a data subject can reasonably expect" the processing.
The question the regulators asked in the email cases above was about consent: did it exist, was it specific to the sender, and could the sender prove it.
On B2B email, national rules differ, which matters as soon as you plan outbound across several European countries. The UK is one example: in the Data (Use and Access) Act reforms, the government considered extending PECR's requirements to business-to-business marketing and did not, as Mayer Brown notes.
How high can a GDPR fine go?
The GDPR maximum gets quoted a lot, so here is the exact wording of Article 83, checked September 2026.
Article 83(4), the lower tier: "administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher."
Article 83(5), the upper tier: "administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher."
Three rows passed 20 million EUR: the two Enel fines and Orange. Orange's 50 million EUR came under French national law, for the inbox ads and a cookie breach, with no GDPR article cited. All three hit large national energy and telecom companies. The other five are between 25,000 and 900,000, in euros or pounds.
The UK PECR ceiling went up under the Data (Use and Access) Act
Worth knowing if you email UK contacts. Under the old rules, the PECR maximum was 500,000 GBP.
The Data (Use and Access) Act raised it, as Mayer Brown summarized in July 2025: "The maximum fine is raised from £500,000 to £17.5 million or 4% of annual global turnover."
The ICO's statement of 5 February 2026, on the next phase of the Act coming into force, lists among the ICO's new powers the ability to "issue fines of up to £17.5 million or 4% of global turnover under the Privacy and Electronic Communications Regulations (PECR)".
That is 35 times the old fixed cap. The ZMLUK and Allay fines, announced on 20 January 2026, came before that statement.
How big is the risk for a normal sender?
The big numbers tell you what is possible. For what is typical, the Spanish figures are the better guide.
A July 2026 roundup of AEPD marketing sanctions on the Spanish-language blog of Legiscope, a GDPR compliance software company, reports 358 AEPD sanction proceedings on marketing in 2024 and 2025, with an average fine of 12,000 EUR across all channels.
For emails sent without permission, it puts typical fines at 5,000 to 60,000 EUR. The highest marketing fine it records is 350,000 EUR against a data broker in 2024.
For scale, the GDPR Enforcement Tracker showed 7,159,322,834 EUR (about 7.16 billion EUR) across 3,275 cases in 32 countries when it refreshed on 27 September 2026.
That total covers every kind of GDPR fine, marketing or otherwise, so it tells you how active the regulators are. It says little about the size of your own risk.
The fine is also only one of the costs in the table:
- Solocal got an order to stop, backed by 10,000 EUR per day after the deadline.
- Both Enel fines are still in the Italian courts, years after the decisions.
- Orange, Solocal, ZMLUK and Allay were all named publicly by the regulator.
Three email fines trace back to somebody else's list
Put the email rows side by side and the same story keeps coming up.
ZMLUK relied on consent collected by a website that listed 361 partners at once. The ICO found people "could not give informed, specific consent, rendering the consent invalid."
Solocal bought from data brokers whose sign-up forms, in CNIL's words, gave the accept buttons a prominence that "strongly encouraged users to accept." After it learned one main supplier could not prove consent, it waited almost 17 months before it stopped using that data.
The Spanish 60,000 EUR case was a mass email to a purchased database.
In all three, the findings were about where the data came from and what permission came with it. Enel's 2024 fine points the same way from the phone side: it included 978 contracts acquired from four companies outside its own sales network.
That pattern is the part I recognize from the commercial side.
When a US founder came to my team after three earlier agencies had promised a lot and delivered little, the list was one of the things we rebuilt from the ground up: "We spent serious time researching and building custom lists of decision-makers that actually matched their ideal client profile - not random scraped data."
That line was about campaign results. The full rebuild is in my post on fixing the list before the copy.
A list you research and build yourself is also a list where you can say where each contact came from. That is a good starting point, and it is still no substitute for advice on your own setup.
Questions to answer before your next send
Each question comes from something a fined company above could not answer.
- Where did each contact come from? Name the source for every row. A purchased database was the Spanish 60,000 EUR case. A third-party sign-up site was ZMLUK's.
- If the seller says the list has consent, is it consent for you? One sign-up shared across 361 partners did not count for ZMLUK, and the ICO found ZMLUK had not done enough due diligence on how that consent was obtained. Solocal had contract requirements on its suppliers, and CNIL called them clearly insufficient.
- Can you prove it today? Solocal breached GDPR Article 7 because it could not show proof of consent for one main supplier's data.
- If you rely on an existing-customer exception, is the product really similar? One Spanish sender was reportedly fined 25,000 EUR for stretching that exception.
- Does your message look like what it is? Orange's ads sat in the inbox looking like emails. Allay later claimed its marketing texts were service updates. Your sender name, domain and subject line should say who is writing and why. The technical side of proving who you are is covered in my domain and mailbox setup notes.
- Do opt-outs and rights requests actually get handled? Poor handling of rights requests was part of the Enel 2022 decision. Allay gave people no simple way to refuse marketing when it collected their details.
- Who else touches the data? Enel's 2024 fine turned on what sales agents outside its network did with access to its systems.
A contact record you can copy
The questions above only help if the answers are written down before anyone asks. Here is a simple record per contact or per list batch, built from what the fined companies could not produce.
| Field | What to write | Case it answers |
|---|---|---|
| Source | Where the contact came from, by name and URL | ZMLUK, Spanish 60,000 EUR case |
| Date collected | When you got it, and when you last checked it | Solocal (kept using unproven data for almost 17 months) |
| Basis you rely on | Consent, existing customer, or another basis your adviser has signed off | Spanish 25,000 EUR case |
| Proof | Where the evidence sits, if the basis is consent | Solocal, GDPR Article 7 |
| Who else has access | Agency, freelancer, list seller, sales partner | Enel 2024 |
| Opt-out and requests | Date received, date handled | Enel 2022, Allay |
Fill it in for your current list and blank cells show you where to look first.
When an agency sends for you, whose name is on the decision?
It can be either side, and the cases above show both. ZMLUK sent its emails on behalf of another company, Zuru Jersey Ltd, and the ICO still held ZMLUK responsible as the sender.
Solocal ran prospecting for its customers, "in particular companies" in CNIL's words, and it was Solocal that CNIL fined. In the Enel 2024 case, the brand itself was fined over what outside agents did with its systems.
So before any agency, list seller or freelancer sends in your name, settle these points in writing:
- Where the data comes from, and what proof of a lawful basis exists for each contact
- Whose name and domain appear as the sender
- Who handles opt-outs and rights requests, and how fast
- What happens to the data when the work ends
If the answers are vague, treat that as information. More on what to ask is in my notes on hiring a lead generation agency.
Questions founders ask about these fines
Can a small company get fined for cold email?
Yes. Legiscope reports typical Spanish fines of 5,000 to 60,000 EUR for emails sent without permission, and an average of about 12,000 EUR across all AEPD marketing cases in 2024 and 2025. The size of the company changes the ceiling, but the rules apply to small senders too.
Is it GDPR or email marketing law that gets you fined?
Often the email marketing law. Orange, ZMLUK and Allay were fined under France's Post and Electronic Communications Code or the UK's PECR, with no GDPR article cited. Solocal was fined under both, including GDPR Article 7 for failing to prove consent.
What if I bought the list and the seller says it has consent?
That is close to the facts of ZMLUK and Solocal. The ICO ruled consent spread across 361 partners invalid, and CNIL fined Solocal even though it had contract requirements on its suppliers. Check how the consent was collected and keep the proof yourself.
How current is this list?
Every source was checked on 27 September 2026. The UK PECR ceiling went up under the Data (Use and Access) Act, and court cases like Enel's keep moving, so check the date and status on any fine before you rely on it.
