Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2020BANCO DE SABADELL, S.A.Banco de Sabadell was fined for sending a commercial email to a customer who had previously opted out of such communications. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications.ESAEPDePrivacy€5,000
18 Feb 2016Banco dell'oro Operatori professionali in oro srlBanco dell'oro Operatori professionali in oro srl was fined by the Garante EUR 2,400 for operating a video surveillance system without the required data protection notice. The case concerned a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
23 Jan 2024BANCO COOPERATIVO ESPAÑOL, S.A.Banco Cooperativo Español, S.A. was fined by the AEPD for a personal data breach. The incident allowed unauthorized access to personal data and breached the principles of confidentiality and integrity.ESAEPDGDPR€15,000
21 May 2024BANCO CETELEM, S.A.Banco Cetelem, S.A. was fined by the AEPD 250,000 EUR for unauthorized processing of personal data. The case included charging the complainant’s bank account for a loan taken out by an unknown third party without consent.ESAEPDGDPR€250,000
29 Nov 2019BANCO BILBAO VIZCAYA ARGENTARIA SLBBVA was fined by the AEPD for sending unsolicited advertising to an individual who was not a customer of the bank. The authority found this to be a breach of data protection rules.ESAEPDePrivacy€10,000
17 Aug 2021BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited SMS messages to the complainant's mobile phone. The company also failed to remove the number from its database after the request, which constituted a data protection breach.ESAEPDGDPR€100,000
17 Apr 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 100,000 by the AEPD for processing a payment to a new account without the account holder’s explicit consent. The authority found this conduct to be a breach of GDPR Article 6.ESAEPDGDPR€100,000
15 Apr 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for including personal data in a credit solvency file without proper prior notice. The authority found this to be a breach of data protection rules.ESAEPDGDPR€200,000
02 Jun 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for continuing to send investment reports by postal mail despite the complainant’s request to receive them by email. The authority found a breach of the right to object and to stop data processing.ESAEPDGDPR€70,000
01 Jan 2023BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for a data breach after an employee accessed a customer's banking information and shared it without consent. The authority found that data security measures were violated.ESAEPDGDPR€70,000
01 Jan 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 70,000 by the AEPD for disclosing one client's personal address to another client. The authority found a breach of personal data confidentiality obligations under the GDPR.ESAEPDGDPR€70,000
27 Jul 2021BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for failing to implement adequate security measures to verify the identity of customers accessing sensitive information through an automated phone system. The authority found a breach of data integrity and confidentiality principles.ESAEPDGDPR€200,000
24 Jun 2023BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 5,000 by the AEPD for repeatedly sending commercial emails to a client despite requests to unsubscribe. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€5,000
03 Dec 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The AEPD imposed a EUR 200,000 fine on Banco Bilbao Vizcaya Argentaria, S.A. for processing personal data without a legal basis. The conduct included signing documents without consent and marking consent checkboxes for commercial purposes without authorization.ESAEPDGDPR€200,000
09 Feb 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined by the AEPD for unlawfully processing personal data and for failing to provide access to personal data requested by a former client. The case concerns non-compliance with data protection obligations.ESAEPDGDPR€140,000
15 Jul 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for requesting a disproportionate amount of personal data, including a copy of the DNI, to process a request for information about account movements. The authority found this to be a breach of the data minimization principle.ESAEPDGDPR€70,000
07 Oct 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for unauthorized remote management of a former employee's personal device. The authority found that the conduct breached the principles of lawful personal data processing.ESAEPDGDPR€200,000
29 Jun 2018BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD EUR 25,000 for sending unsolicited commercial messages. The authority found that recipients were not provided with a free opt-out mechanism.ESAEPDePrivacy€25,000
18 Jun 2020BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD in the amount of EUR 30,000 for consulting personal data in credit files without an existing contractual relationship. The authority found that this conduct breached data processing principles.ESAEPDGDPR€30,000
23 Jan 2017BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€3,300