BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Mar 2020 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for inaccurate processing of personal data. The bank demanded payment for a debt the complainant did not owe and shared the complainant’s personal data with a debt collection agency. | ES | AEPD | GDPR | €60,000 | ↗ |
| 25 May 2018 | Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the AEPD for sending unsolicited commercial SMS messages to a non-customer without consent. The case concerns a breach of direct marketing rules and the requirement to obtain prior consent. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 10 Jul 2025 | Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the Italian authority Garante in the amount of €100,000. The case concerned an inadequate response to a data access request linked to a fraud incident, which breached Article 15 of the GDPR. | IT | Garante | GDPR | €100,000 | ↗ |
| 03 Apr 2025 | Banca Transilvania S.A.Banca Transilvania S.A. was fined EUR 5,000 by ANSPDCP for processing personal data without a legal basis. The authority found a breach of the GDPR principle of lawfulness, fairness, and transparency. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 03 Apr 2023 | Banca Transilvania SABanca Transilvania SA was fined EUR 2,000 by ANSPDCP for a GDPR breach. The case concerned improperly restricting access to an account in the mobile banking application despite the client's explicit request. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 14 Sept 2006 | Banca Sella S.p.a.Banca Sella S.p.a. was fined EUR 20,000 by the Garante for processing biometric data without the notification required under the privacy code. The authority found this to be a breach of Italian privacy rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 09 Feb 2012 | Banca popolare Sant'Angelo S.C.P.A.The bank was fined for deploying a biometric data collection system without proper notification and without complying with data protection principles. The authority found that the processing did not meet privacy compliance requirements. | IT | Garante | GDPR | €100,000 | ↗ |
| 11 Jun 2015 | Banca Nazionale del Lavoro S.p.a.Banca Nazionale del Lavoro S.p.a. was fined by the Garante 32,000 EUR for processing personal data without first informing the data subjects and without obtaining their consent. The case concerns a breach of core notice and consent obligations in personal data processing. | IT | Garante | GDPR | €32,000 | ↗ |
| 20 Nov 2008 | Banca di Roma S.p.A.Banca di Roma S.p.A. was fined EUR 30,000 by the Garante for unauthorized access to the Bank of Italy's risk center. The authority also found that the company failed to provide adequate information to data subjects, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 07 Mar 2024 | Banca di Credito Cooperativo Appulo Lucana soc. cooperativaThe Garante fined Banca di Credito Cooperativo Appulo Lucana 20,000 EUR for failing to provide adequate access to personal data requested by a former employee. The authority found a breach of GDPR Article 15 on the right of access. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Sept 2022 | Banca Comercială Română SAThe supervisory authority completed an investigation into Banca Comercială Română SA and found a breach of data processing security requirements. The issue was caused by a technical error in the operator’s IT application, which led to improper data processing. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 09 Mar 2023 | Banca Cambiano 1884 S.p.A.Banca Cambiano 1884 S.p.A. was fined by the Garante 10,000 EUR for failing to respond within the required timeframe to a data subject's request for access to personal data. The authority found a breach of GDPR Articles 15 and 12. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Jul 2023 | BALLESPE, S.LBALLESPE, S.L was fined by the AEPD in the amount of 500 EUR for installing surveillance cameras that captured public areas without proper signage. The case concerns a breach of data protection rules and the duty to inform individuals being recorded. | ES | AEPD | GDPR | €500 | ↗ |
| 21 Oct 2010 | Baldomero **** y Jesús ***** CBBaldomero **** y Jesús ***** CB was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent from recipients. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 24 Oct 2013 | Balangero SerenaBalangero Serena was fined by the Garante in the amount of 4,000 EUR for non-compliance with data protection rules in the use of surveillance cameras at Murphy's Bar. The authority found that privacy notices for individuals under surveillance were inadequate. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Mar 2026 | Bakeca s.r.l.Bakeca s.r.l. was fined €5,000 by the Italian data protection authority, Garante. The case concerned the publication of online ads without the required consent, which breached data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 17 Jan 2013 | Bagno sport 70 s.a.s.Bagno sport 70 s.a.s. was fined 8,000 EUR by the Garante for processing customers' biometric data for payments. The company failed to notify the supervisory authority, which breached the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 22 Oct 2015 | Bagni Miramare srlBagni Miramare srl was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned collecting email addresses through its website without providing the required privacy notice, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 16 Dec 2020 | Babaváró kölcsönnel összefüggésben végzett adatkezelés – várandósgondozási könyvekről való másolatkészítés jogszerűségeThe supervisory authority found that the entity processed personal and health data from maternity care records without a legal basis in connection with Babaváró loan applications. It also failed to provide clear and transparent information about the processing, breaching GDPR principles. | HU | NAIH | GDPR | €98,350 | ↗ |
| 01 Jan 2025 | B3C CONSULTORÍA DE SERVICIOS 2010 S.L.B3C CONSULTORÍA DE SERVICIOS 2010 S.L. was fined by the AEPD EUR 800 for subcontracting TELCO without authorization from the data controller, AIRE NETWORKS. The company also failed to impose the required contractual obligations on TELCO, breaching GDPR Articles 28.2 and 28.4. | ES | AEPD | GDPR | €800 | ↗ |