Tiger Media

Tiger Media’s €72,000 GDPR fine in Spain: advertising cookies installed without consent (2025)

Regulator: AEPD (Spain)Last updated

At a glance

Brought by
Regulator: AEPD (Spain)Regulator
Company
Tiger Media Inc.
Sector
Ad network (adult-content publishers)
Law
GDPR (Arts 6 and 27)
Amount
€72,000
Date
Paid Nov 14, 2025
Status
Resolved, responsibility acknowledged

Summary

In 2025, Spain’s data protection regulator, the AEPD, fined Tiger Media, an ad network serving adult-content publishers, €72,000 under the GDPR for installing persistent advertising cookies on Spanish websites without consent and having no EU representative. The fine was reduced from €120,000 because the company acknowledged responsibility and paid voluntarily.

What happened

The AEPD checked three Spanish websites on June 23, 2025. The ad network’s cookies sent the visitor’s language, IP address, browser and operating system, and the page visited to its domain. The GDPR requires a company outside the EU to have a representative there, which Tiger Media did not. Tiger Media paid on November 14, 2025.

The mechanism

This is the supply-chain version of the problem: the cookies on these publishers’ sites came from a partner, and the AEPD also ordered Tiger Media to show measures so that publishers using its cookie comply with Spain’s cookie law.

Timeline: analytics and marketing tags send data after the page opens, before the visitor accepts or rejects the banner.

Why it was preventable

Non-essential cookies firing without consent is the core cookie check. It applies to the tags your partners bring onto your site as much as your own.

Source

AEPD resolution PS/00480/2025 (in Spanish).

aepd.es

Questions

Who fined Tiger Media, and how much?

Spain’s data protection regulator, the AEPD, fined Tiger Media €72,000 under the GDPR in 2025, reduced from a proposed €120,000 because the company acknowledged responsibility and paid voluntarily. The AEPD is a national data protection authority, separate from the EDPB and the EU as a whole.

What did Tiger Media do?

Its persistent advertising cookies were installed on Spanish publisher websites without consent, and it had no representative in the EU, which the GDPR requires for a company outside the EU.

Why does this matter for a publisher?

Because the cookies were placed by a third-party ad-tech partner. Non-essential cookies firing without consent applies to the tags your partners bring onto your site as much as your own.

30-day free trial

See what your tags send before it becomes a case

DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

DataTrue scan overview showing scan details and page status for a scheduled daily coverage scan
A scheduled daily coverage scan in DataTrue