BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Mar 2022 | Bank of Ireland Group plcThe Irish DPC fined Bank of Ireland Group plc EUR 463,000 in inquiry IN-19-9-5. The penalty status is recorded as collected. | IE | DPC | GDPR | €463,000 | ↗ |
| 27 Feb 2023 | Bank of Ireland 365 (‘BOI’)The Irish DPC fined Bank of Ireland 365 (‘BOI’) €750,000 in inquiry IN-20-7-2. The fine has been collected. | IE | DPC | GDPR | €750,000 | ↗ |
| 18 Dec 2013 | Bank of CyprusBank of Cyprus was fined EUR 5,000 by the HDPA. The authority found illegal access to and disclosure of creditworthiness data from the Tiresias database. | GR | HDPA | GDPR | €5,000 | ↗ |
| 16 Dec 2025 | Bank MillenniumThe Polish Supreme Administrative Court upheld a PLN 350,000 administrative fine imposed on Bank Millennium by the President of the Personal Data Protection Office. The sanction concerned failure to report a personal data breach and failure to notify affected individuals after a courier shipment containing customer data was lost. | PL | Urząd Ochrony Danych Osobowych | GDPR | €82,922 | ↗ |
| 13 Oct 2025 | BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 400,000 EUR for failing to implement adequate technical and organizational measures to ensure data integrity and confidentiality. The deficiency resulted in unauthorized access to personal data. | ES | AEPD | GDPR | €400,000 | ↗ |
| 01 Jan 2016 | BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 10,000 EUR for failing to provide the required cookie information and for not obtaining consent on its website. The case concerns breaches of notice and consent obligations for website cookies. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 06 Apr 2022 | BANKINTER, S.A.BANKINTER, S.A. was fined EUR 70,000 by the AEPD for a data protection breach. The case involved the unauthorized disclosure of sensitive banking information caused by an isolated IT error. | ES | AEPD | GDPR | €70,000 | ↗ |
| 30 Jan 2023 | BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD in the amount of 1,000 EUR for not adequately handling a data subject access request. The authority found a breach of Article 15 of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 15 Mar 2023 | BANKINTER CONSUMER FINANCE E.F.C., S.A.Bankinter Consumer Finance issued a duplicate card without the customer's consent and sent it to an incorrect address. This led to unauthorized transactions and indicated a failure in data protection and payment security controls. | ES | AEPD | GDPR | €70,000 | ↗ |
| 24 Feb 2020 | BANKIA, S.A.BANKIA, S.A. was fined by the AEPD EUR 50,000 for sending commercial advertising by postal mail to a customer who had objected to the processing of their data for advertising purposes. The authority found this conduct contrary to GDPR Article 6(1)(f). | ES | AEPD | GDPR | €50,000 | ↗ |
| 05 Aug 2020 | BANKIA, S.A.BANKIA, S.A. was fined by the AEPD 50,000 EUR for retaining a former client’s personal data for more than 16 years without a valid basis. The authority found this to be a breach of data protection principles, especially storage limitation. | ES | AEPD | GDPR | €50,000 | ↗ |
| 26 Jun 2019 | Banki adatkezelés és érintetti joggyakorlásThe controller was fined for processing personal data without a legal basis and for failing to provide adequate information about the right to object. The authority found breaches of core transparency and lawfulness obligations. | HU | NAIH | GDPR | €3,090 | ↗ |
| 19 Apr 2021 | BankThe Bank was fined by NAIH for breaching the principles of purpose limitation and data minimization when transferring personal data without a proper legal basis. The authority also found failures to respect the data subject's rights of access and objection. | HU | NAIH | GDPR | €13,900 | ↗ |
| 02 Aug 2022 | BankThe Bank and the Mortgage Bank processed personal data for credit assessment without a legal basis. They also failed to provide adequate information required under the GDPR. | HU | NAIH | GDPR | €75,600 | ↗ |
| 01 Jan 2015 | BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails. The authority found this breached Article 21.1 of the LSSI on marketing communications without prior consent. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 07 Oct 2014 | BANCO SANTANDER, S.A.Banco Santander was fined by the AEPD EUR 2,000 for sending commercial emails despite the recipient's objection. The authority found this breached Article 21 of the LSSI on unsolicited electronic communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 01 Jan 2015 | BANCO SANTANDER, S.A.Banco Santander was fined EUR 1,500 by the AEPD for sending unsolicited commercial emails to a recipient who had previously opted out. The authority found this to be a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 01 Jan 2016 | BANCO SANTANDER, S.A.Banco Santander, S.A. was fined by the AEPD €8,000 for sending unsolicited commercial emails. The authority found that the messages did not provide a valid email address for recipients to opt out, breaching Article 21 of the LSSI. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 01 Jan 2015 | BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending an unsolicited commercial email to an individual who had not consented to receive such communications. The case concerns a breach of rules on marketing communications and recipient consent. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 03 Jul 2025 | BANCO INVERSIS, S.A.Banco Inversis, S.A. was fined by the AEPD in the amount of 10,000 EUR for a personal data breach. The case involved unauthorized access to personal data, which breached Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |