BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Jul 2023 | BALLESPE, S.LBALLESPE, S.L was fined by the AEPD in the amount of 500 EUR for installing surveillance cameras that captured public areas without proper signage. The case concerns a breach of data protection rules and the duty to inform individuals being recorded. | ES | AEPD | GDPR | €500 | ↗ |
| 09 Mar 2023 | Banca Cambiano 1884 S.p.A.Banca Cambiano 1884 S.p.A. was fined by the Garante 10,000 EUR for failing to respond within the required timeframe to a data subject's request for access to personal data. The authority found a breach of GDPR Articles 15 and 12. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Sept 2022 | Banca Comercială Română SAThe supervisory authority completed an investigation into Banca Comercială Română SA and found a breach of data processing security requirements. The issue was caused by a technical error in the operator’s IT application, which led to improper data processing. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 07 Mar 2024 | Banca di Credito Cooperativo Appulo Lucana soc. cooperativaThe Garante fined Banca di Credito Cooperativo Appulo Lucana 20,000 EUR for failing to provide adequate access to personal data requested by a former employee. The authority found a breach of GDPR Article 15 on the right of access. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Nov 2008 | Banca di Roma S.p.A.Banca di Roma S.p.A. was fined EUR 30,000 by the Garante for unauthorized access to the Bank of Italy's risk center. The authority also found that the company failed to provide adequate information to data subjects, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 11 Jun 2015 | Banca Nazionale del Lavoro S.p.a.Banca Nazionale del Lavoro S.p.a. was fined by the Garante 32,000 EUR for processing personal data without first informing the data subjects and without obtaining their consent. The case concerns a breach of core notice and consent obligations in personal data processing. | IT | Garante | GDPR | €32,000 | ↗ |
| 09 Feb 2012 | Banca popolare Sant'Angelo S.C.P.A.The bank was fined for deploying a biometric data collection system without proper notification and without complying with data protection principles. The authority found that the processing did not meet privacy compliance requirements. | IT | Garante | GDPR | €100,000 | ↗ |
| 14 Sept 2006 | Banca Sella S.p.a.Banca Sella S.p.a. was fined EUR 20,000 by the Garante for processing biometric data without the notification required under the privacy code. The authority found this to be a breach of Italian privacy rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 03 Apr 2023 | Banca Transilvania SABanca Transilvania SA was fined EUR 2,000 by ANSPDCP for a GDPR breach. The case concerned improperly restricting access to an account in the mobile banking application despite the client's explicit request. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 03 Apr 2025 | Banca Transilvania S.A.Banca Transilvania S.A. was fined EUR 5,000 by ANSPDCP for processing personal data without a legal basis. The authority found a breach of the GDPR principle of lawfulness, fairness, and transparency. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 25 May 2018 | Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the AEPD for sending unsolicited commercial SMS messages to a non-customer without consent. The case concerns a breach of direct marketing rules and the requirement to obtain prior consent. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 10 Jul 2025 | Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the Italian authority Garante in the amount of €100,000. The case concerned an inadequate response to a data access request linked to a fraud incident, which breached Article 15 of the GDPR. | IT | Garante | GDPR | €100,000 | ↗ |
| 17 Aug 2021 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited SMS messages to the complainant's mobile phone. The company also failed to remove the number from its database after the request, which constituted a data protection breach. | ES | AEPD | GDPR | €100,000 | ↗ |
| 17 Apr 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 100,000 by the AEPD for processing a payment to a new account without the account holder’s explicit consent. The authority found this conduct to be a breach of GDPR Article 6. | ES | AEPD | GDPR | €100,000 | ↗ |
| 15 Apr 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for including personal data in a credit solvency file without proper prior notice. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 02 Jun 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for continuing to send investment reports by postal mail despite the complainant’s request to receive them by email. The authority found a breach of the right to object and to stop data processing. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2023 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for a data breach after an employee accessed a customer's banking information and shared it without consent. The authority found that data security measures were violated. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 70,000 by the AEPD for disclosing one client's personal address to another client. The authority found a breach of personal data confidentiality obligations under the GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 27 Jul 2021 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for failing to implement adequate security measures to verify the identity of customers accessing sensitive information through an automated phone system. The authority found a breach of data integrity and confidentiality principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 24 Jun 2023 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 5,000 by the AEPD for repeatedly sending commercial emails to a client despite requests to unsubscribe. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |