Tiger Media’s €72,000 GDPR fine in Spain: advertising cookies installed without consent (2025)
At a glance
- Brought by
- Regulator: AEPD (Spain)Regulator
- Company
- Tiger Media Inc.
- Sector
- Ad network (adult-content publishers)
- Law
- GDPR (Arts 6 and 27)
- Amount
- €72,000
- Date
- Paid Nov 14, 2025
- Status
- Resolved, responsibility acknowledged
Summary
In 2025, Spain’s data protection regulator, the AEPD, fined Tiger Media, an ad network serving adult-content publishers, €72,000 under the GDPR for installing persistent advertising cookies on Spanish websites without consent and having no EU representative. The fine was reduced from €120,000 because the company acknowledged responsibility and paid voluntarily.
What happened
The AEPD checked three Spanish websites on June 23, 2025. The ad network’s cookies sent the visitor’s language, IP address, browser and operating system, and the page visited to its domain. The GDPR requires a company outside the EU to have a representative there, which Tiger Media did not. Tiger Media paid on November 14, 2025.
The mechanism
This is the supply-chain version of the problem: the cookies on these publishers’ sites came from a partner, and the AEPD also ordered Tiger Media to show measures so that publishers using its cookie comply with Spain’s cookie law.

Why it was preventable
Non-essential cookies firing without consent is the core cookie check. It applies to the tags your partners bring onto your site as much as your own.
Source
AEPD resolution PS/00480/2025 (in Spanish).
aepd.esQuestions
Who fined Tiger Media, and how much?
Spain’s data protection regulator, the AEPD, fined Tiger Media €72,000 under the GDPR in 2025, reduced from a proposed €120,000 because the company acknowledged responsibility and paid voluntarily. The AEPD is a national data protection authority, separate from the EDPB and the EU as a whole.
What did Tiger Media do?
Its persistent advertising cookies were installed on Spanish publisher websites without consent, and it had no representative in the EU, which the GDPR requires for a company outside the EU.
Why does this matter for a publisher?
Because the cookies were placed by a third-party ad-tech partner. Non-essential cookies firing without consent applies to the tags your partners bring onto your site as much as your own.
Related cases
Shein’s €150M CNIL fine
Cookies before the banner; kept after “refuse all”
CNIL’s €750,000 fine against Condé Nast
Cookies on arrival; “reject” did not stop tracking
Google’s €325M CNIL fine
Cookies steered during signup; Gmail inbox ads
See what your tags send before it becomes a case
DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
