BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Jan 2024 | CAJA RURAL DEL SUR, S.C.C.CAJA RURAL DEL SUR, S.C.C. was fined EUR 20,000 by the AEPD for breaching data protection principles. The authority found that confidentiality and integrity of personal data were not adequately ensured, resulting in unauthorized access by third parties. | ES | AEPD | GDPR | €20,000 | ↗ |
| 24 Jan 2024 | CAJA RURAL DE GIJÓN, S.C.A.C.CAJA RURAL DE GIJÓN was fined by the AEPD 95,000 EUR for breaching data protection principles, specifically confidentiality and integrity. The incident resulted in unauthorized access to personal data and indicates a significant compliance failure. | ES | AEPD | GDPR | €95,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE EXTREMADURA S.C.C.CAJA RURAL DE EXTREMADURA S.C.C. was fined by the AEPD 250,000 EUR for a breach that compromised the confidentiality and integrity of personal data. The authority found a violation of Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €250,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE BURGOS, FUENTEPELAYO, SEGOVIA Y CASTELLDANS, S.C.C.CAJABURGOS was fined by the AEPD for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident. | ES | AEPD | GDPR | €15,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE BAENA NTRA. SRA. DE GUADALUPE, S.C.C.A.CAJA RURAL DE BAENA was fined by the AEPD 10,000 EUR for breaching data protection principles. The case involved failures in confidentiality and integrity of personal data, which led to unauthorized access by third parties. | ES | AEPD | GDPR | €10,000 | ↗ |
| 24 Jan 2024 | CAJA RURAL DE ASTURIAS, S.C.C.CAJA RURAL DE ASTURIAS was fined by the AEPD EUR 250,000 for breaching the confidentiality and integrity principles of personal data. The incident allowed unauthorized access to personal data, indicating a failure to protect data appropriately. | ES | AEPD | GDPR | €250,000 | ↗ |
| 08 Aug 2022 | CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. (CASER)CASER was fined 40,000 EUR by the AEPD for modifying insurance policy data without the policyholder’s consent. The authority found that this breached GDPR data processing principles. | ES | AEPD | GDPR | €40,000 | ↗ |
| 24 Jan 2024 | CAIXA RURAL LA VALL SAN ISIDRO, S.C.C.CAIXA RURAL LA VALL SAN ISIDRO was fined by the AEPD 15,000 EUR for a personal data breach. The incident allowed unauthorized third-party access and affected the confidentiality and integrity of the data. | ES | AEPD | GDPR | €15,000 | ↗ |
| 24 Jan 2024 | CAIXA RURAL D'ALGEMESÍ, S.C.V.CCAIXA RURAL D'ALGEMESÍ, S.C.V.C. was fined by the AEPD 15,000 EUR for breaching data protection principles, including confidentiality and integrity. The breach led to unauthorized access to personal data. | ES | AEPD | GDPR | €15,000 | ↗ |
| 23 Jan 2024 | CAIXA RURAL BENICARLÓ, S.C.C.VCAIXA RURAL BENICARLÓ was fined by the AEPD 10,000 EUR for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident. | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Jan 2024 | CAIXA POPULAR - CAIXA RURAL SOC. COOP. DE CRÉDITO VCAIXA POPULAR was fined EUR 35,000 by the AEPD for a personal data breach. The incident allowed unauthorized third-party access and affected the confidentiality and integrity of the data. | ES | AEPD | GDPR | €35,000 | ↗ |
| 11 Apr 2023 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 200,000 for failing to remove personal data from a credit information system after the debt was sold. The authority found that the continued processing of the data was not compliant with data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 18 Jun 2020 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD for using pre-marked consents for data processing and charging customers a fee if they refused data sharing with third parties. The authority found that these practices breached GDPR requirements on valid consent and lawful processing. | ES | AEPD | GDPR | €2,100,000 | ↗ |
| 07 Mar 2024 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,000,000 for pre-setting consent to share data with the Social Security Treasury without giving customers the option to refuse. The authority found this practice breached GDPR requirements for valid consent. | ES | AEPD | GDPR | €2,000,000 | ↗ |
| 01 Jan 2024 | CAIXABANK, S.A.CAIXABANK was fined by the AEPD for sending a privacy policy update to a non-client. The authority found that the stated legitimate-interest basis for processing did not have proper consent support. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2014 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD 5,000 EUR for sending unauthorized commercial emails. The conduct occurred after the complainant had exercised the right to object to the use of their data for advertising purposes. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Feb 2019 | CAIXABANK, S.A.CAIXABANK was fined by the AEPD for introducing new data protection conditions that required consent for sharing data within its group. The authority found the measure disproportionate and lacking a proper legal basis. | ES | AEPD | GDPR | €6,500,000 | ↗ |
| 16 Apr 2025 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 500,000 for failing to implement measures to ensure data integrity and confidentiality. The breach resulted in unauthorized access to personal data, indicating insufficient technical or organizational safeguards. | ES | AEPD | GDPR | €500,000 | ↗ |
| 03 Feb 2017 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,500 for sending a customer an unsolicited advertising SMS. The recipient had not consented to receive commercial communications, which breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 07 Oct 2014 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial communications by email. The conduct breached Article 21 of the LSSI, which restricts unwanted marketing messages. | ES | AEPD | ePrivacy | €5,000 | ↗ |