Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Dec 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The AEPD imposed a EUR 200,000 fine on Banco Bilbao Vizcaya Argentaria, S.A. for processing personal data without a legal basis. The conduct included signing documents without consent and marking consent checkboxes for commercial purposes without authorization.ESAEPDGDPR€200,000
09 Feb 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined by the AEPD for unlawfully processing personal data and for failing to provide access to personal data requested by a former client. The case concerns non-compliance with data protection obligations.ESAEPDGDPR€140,000
15 Jul 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for requesting a disproportionate amount of personal data, including a copy of the DNI, to process a request for information about account movements. The authority found this to be a breach of the data minimization principle.ESAEPDGDPR€70,000
07 Oct 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for unauthorized remote management of a former employee's personal device. The authority found that the conduct breached the principles of lawful personal data processing.ESAEPDGDPR€200,000
29 Jun 2018BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD EUR 25,000 for sending unsolicited commercial messages. The authority found that recipients were not provided with a free opt-out mechanism.ESAEPDePrivacy€25,000
18 Jun 2020BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD in the amount of EUR 30,000 for consulting personal data in credit files without an existing contractual relationship. The authority found that this conduct breached data processing principles.ESAEPDGDPR€30,000
23 Jan 2017BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€3,300
06 Mar 2020BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for inaccurate processing of personal data. The bank demanded payment for a debt the complainant did not owe and shared the complainant’s personal data with a debt collection agency.ESAEPDGDPR€60,000
29 Nov 2019BANCO BILBAO VIZCAYA ARGENTARIA SLBBVA was fined by the AEPD for sending unsolicited advertising to an individual who was not a customer of the bank. The authority found this to be a breach of data protection rules.ESAEPDePrivacy€10,000
21 May 2024BANCO CETELEM, S.A.Banco Cetelem, S.A. was fined by the AEPD 250,000 EUR for unauthorized processing of personal data. The case included charging the complainant’s bank account for a loan taken out by an unknown third party without consent.ESAEPDGDPR€250,000
23 Jan 2024BANCO COOPERATIVO ESPAÑOL, S.A.Banco Cooperativo Español, S.A. was fined by the AEPD for a personal data breach. The incident allowed unauthorized access to personal data and breached the principles of confidentiality and integrity.ESAEPDGDPR€15,000
18 Feb 2016Banco dell'oro Operatori professionali in oro srlBanco dell'oro Operatori professionali in oro srl was fined by the Garante EUR 2,400 for operating a video surveillance system without the required data protection notice. The case concerned a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
01 Jan 2020BANCO DE SABADELL, S.A.Banco de Sabadell was fined for sending a commercial email to a customer who had previously opted out of such communications. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications.ESAEPDePrivacy€5,000
03 Jul 2025BANCO INVERSIS, S.A.Banco Inversis, S.A. was fined by the AEPD in the amount of 10,000 EUR for a personal data breach. The case involved unauthorized access to personal data, which breached Article 5(1)(f) of the GDPR.ESAEPDGDPR€10,000
01 Jan 2015BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails. The authority found this breached Article 21.1 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€5,000
07 Oct 2014BANCO SANTANDER, S.A.Banco Santander was fined by the AEPD EUR 2,000 for sending commercial emails despite the recipient's objection. The authority found this breached Article 21 of the LSSI on unsolicited electronic communications.ESAEPDePrivacy€2,000
01 Jan 2015BANCO SANTANDER, S.A.Banco Santander was fined EUR 1,500 by the AEPD for sending unsolicited commercial emails to a recipient who had previously opted out. The authority found this to be a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,500
01 Jan 2016BANCO SANTANDER, S.A.Banco Santander, S.A. was fined by the AEPD €8,000 for sending unsolicited commercial emails. The authority found that the messages did not provide a valid email address for recipients to opt out, breaching Article 21 of the LSSI.ESAEPDePrivacy€8,000
01 Jan 2015BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending an unsolicited commercial email to an individual who had not consented to receive such communications. The case concerns a breach of rules on marketing communications and recipient consent.ESAEPDePrivacy€5,000
19 Apr 2021BankThe Bank was fined by NAIH for breaching the principles of purpose limitation and data minimization when transferring personal data without a proper legal basis. The authority also found failures to respect the data subject's rights of access and objection.HUNAIHGDPR€13,900