Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Mar 2022Bank of Ireland Group plcThe Irish DPC fined Bank of Ireland Group plc EUR 463,000 in inquiry IN-19-9-5. The penalty status is recorded as collected.IEDPCGDPR€463,000
27 Feb 2023Bank of Ireland 365 (‘BOI’)The Irish DPC fined Bank of Ireland 365 (‘BOI’) €750,000 in inquiry IN-20-7-2. The fine has been collected.IEDPCGDPR€750,000
18 Dec 2013Bank of CyprusBank of Cyprus was fined EUR 5,000 by the HDPA. The authority found illegal access to and disclosure of creditworthiness data from the Tiresias database.GRHDPAGDPR€5,000
16 Dec 2025Bank MillenniumThe Polish Supreme Administrative Court upheld a PLN 350,000 administrative fine imposed on Bank Millennium by the President of the Personal Data Protection Office. The sanction concerned failure to report a personal data breach and failure to notify affected individuals after a courier shipment containing customer data was lost.PLUrząd Ochrony Danych OsobowychGDPR€82,922
13 Oct 2025BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 400,000 EUR for failing to implement adequate technical and organizational measures to ensure data integrity and confidentiality. The deficiency resulted in unauthorized access to personal data.ESAEPDGDPR€400,000
01 Jan 2016BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 10,000 EUR for failing to provide the required cookie information and for not obtaining consent on its website. The case concerns breaches of notice and consent obligations for website cookies.ESAEPDePrivacy€10,000
06 Apr 2022BANKINTER, S.A.BANKINTER, S.A. was fined EUR 70,000 by the AEPD for a data protection breach. The case involved the unauthorized disclosure of sensitive banking information caused by an isolated IT error.ESAEPDGDPR€70,000
30 Jan 2023BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD in the amount of 1,000 EUR for not adequately handling a data subject access request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€1,000
15 Mar 2023BANKINTER CONSUMER FINANCE E.F.C., S.A.Bankinter Consumer Finance issued a duplicate card without the customer's consent and sent it to an incorrect address. This led to unauthorized transactions and indicated a failure in data protection and payment security controls.ESAEPDGDPR€70,000
24 Feb 2020BANKIA, S.A.BANKIA, S.A. was fined by the AEPD EUR 50,000 for sending commercial advertising by postal mail to a customer who had objected to the processing of their data for advertising purposes. The authority found this conduct contrary to GDPR Article 6(1)(f).ESAEPDGDPR€50,000
05 Aug 2020BANKIA, S.A.BANKIA, S.A. was fined by the AEPD 50,000 EUR for retaining a former client’s personal data for more than 16 years without a valid basis. The authority found this to be a breach of data protection principles, especially storage limitation.ESAEPDGDPR€50,000
26 Jun 2019Banki adatkezelés és érintetti joggyakorlásThe controller was fined for processing personal data without a legal basis and for failing to provide adequate information about the right to object. The authority found breaches of core transparency and lawfulness obligations.HUNAIHGDPR€3,090
19 Apr 2021BankThe Bank was fined by NAIH for breaching the principles of purpose limitation and data minimization when transferring personal data without a proper legal basis. The authority also found failures to respect the data subject's rights of access and objection.HUNAIHGDPR€13,900
02 Aug 2022BankThe Bank and the Mortgage Bank processed personal data for credit assessment without a legal basis. They also failed to provide adequate information required under the GDPR.HUNAIHGDPR€75,600
01 Jan 2015BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails. The authority found this breached Article 21.1 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€5,000
07 Oct 2014BANCO SANTANDER, S.A.Banco Santander was fined by the AEPD EUR 2,000 for sending commercial emails despite the recipient's objection. The authority found this breached Article 21 of the LSSI on unsolicited electronic communications.ESAEPDePrivacy€2,000
01 Jan 2015BANCO SANTANDER, S.A.Banco Santander was fined EUR 1,500 by the AEPD for sending unsolicited commercial emails to a recipient who had previously opted out. The authority found this to be a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,500
01 Jan 2016BANCO SANTANDER, S.A.Banco Santander, S.A. was fined by the AEPD €8,000 for sending unsolicited commercial emails. The authority found that the messages did not provide a valid email address for recipients to opt out, breaching Article 21 of the LSSI.ESAEPDePrivacy€8,000
01 Jan 2015BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending an unsolicited commercial email to an individual who had not consented to receive such communications. The case concerns a breach of rules on marketing communications and recipient consent.ESAEPDePrivacy€5,000
03 Jul 2025BANCO INVERSIS, S.A.Banco Inversis, S.A. was fined by the AEPD in the amount of 10,000 EUR for a personal data breach. The case involved unauthorized access to personal data, which breached Article 5(1)(f) of the GDPR.ESAEPDGDPR€10,000