BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Jan 2016 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 10,500 for sending unsolicited advertising SMS messages without prior recipient consent. The authority also found that no opt-out mechanism was provided, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €10,500 | ↗ |
| 17 Jan 2014 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD in the amount of 30,001 EUR for sending unsolicited commercial SMS messages. The authority also found that the messages did not include information on how to revoke consent, in breach of Article 21.2 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 01 Jan 2022 | CAIXABANK S.A.CaixaBank was fined EUR 25,000 by the AEPD for failing to update a customer's address despite repeated requests. The authority found this to be a breach of the GDPR right to rectification. | ES | AEPD | GDPR | €25,000 | ↗ |
| 26 Mar 2021 | CAIXABANK S.A.CAIXABANK S.A. was fined EUR 60,000 by the AEPD for processing personal data without consent. The case concerned a current account contract signed on behalf of the complainant without proper authorization. | ES | AEPD | GDPR | €60,000 | ↗ |
| 03 Apr 2023 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including an individual's data in a creditworthiness file without a lawful basis. The authority found this conduct violated Article 6 of the GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 07 Jan 2022 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD EUR 70,000 for including personal data in credit information systems without a proper legal basis. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 05 Jul 2022 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined 70,000 EUR by the AEPD. The company continued to demand payment of a debt that had been annulled by a court ruling, which breached data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 06 Apr 2021 | CAFFE VECCHIO, S.L.CAFFE VECCHIO, S.L. was fined by the AEPD EUR 1,500 for publishing an individual's personal data in response to negative Google reviews. The disclosure included the person's name and details of an employment sanction. | ES | AEPD | GDPR | €1,500 | ↗ |
| 09 May 2024 | Caffetteria 77 di Dughetti BarbaraThe Garante fined Caffetteria 77 di Dughetti Barbara EUR 3,000 for operating a video surveillance system without meeting the legal requirements. The system captured both customers and employees, creating a data protection compliance breach. | IT | Garante | GDPR | €3,000 | ↗ |
| 01 Jan 2018 | CAFETERÍA NAGASAKICAFETERÍA NAGASAKI was fined by the AEPD 1,500 EUR for using surveillance cameras to capture images of public sidewalks without justification. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 01 Jul 2020 | CAFÉ RESTAURANTE B.B.B.The entity installed a surveillance camera facing a public space, despite recommendations from the local police. This breached data protection regulations. | ES | AEPD | GDPR | €1,500 | ↗ |
| 01 Jan 2019 | CAFE BAR NINA (Nina Cb)CAFE BAR NINA was fined €2,000 by the AEPD for installing an unauthorized surveillance camera. The conduct breached data protection requirements. | ES | AEPD | GDPR | €2,000 | ↗ |
| 20 Jul 2020 | CABRERA & GIL ABOGADOS, S.L.P.CABRERA & GIL ABOGADOS, S.L.P. was fined by the AEPD €2,000 for disclosing personal data without consent. The case concerns Article 6 GDPR, which requires a valid legal basis for processing personal data. | ES | AEPD | GDPR | €2,000 | ↗ |
| 30 May 2011 | CABLEUROPA, S.A.U.CABLEUROPA, S.A.U. was fined EUR 600 by the AEPD for continuing to send advertising communications to an individual after repeated requests for data cancellation. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 01 Jan 2015 | CABLEUROPA SAUCABLEUROPA SAU was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails and SMS messages to a customer. The recipient had previously exercised the right to cancel and opted out of receiving such communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 05 Nov 2025 | CABINET D'AVOCATS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on CABINET D'AVOCATS (procédure simplifiée). The case was handled under a simplified administrative procedure by the French data protection authority. | FR | CNIL | GDPR | €5,000 | ↗ |
| 11 Jul 2018 | CAA Liberi professionisti s.r.l.CAA Liberi professionisti s.r.l. was fined by the Garante in the amount of 12,400 EUR for failing to properly designate and instruct personnel involved in data processing. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €12,400 | ↗ |
| 17 Mar 2016 | Caaf Consulenti del lavoro srlCaaf Consulenti del lavoro srl was fined EUR 4,800 by the Garante. The authority found that the company failed to provide the required privacy notice for data collected through its website contact form and video surveillance system, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 17 Dec 2015 | Caaf Cgil Sardegna srlCaaf Cgil Sardegna srl was fined by the Garante 12,000 EUR for failing to provide the required privacy notice on its website. The authority found this to be a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €12,000 | ↗ |
| 23 Mar 2023 | CAAF CGIL Lombardia s.r.l.CAAF CGIL Lombardia s.r.l. was fined EUR 30,000 by the Garante for unlawful processing of personal data. The company sent promotional emails despite a prior request to delete the data. | IT | Garante | GDPR | €30,000 | ↗ |