BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Dec 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The AEPD imposed a EUR 200,000 fine on Banco Bilbao Vizcaya Argentaria, S.A. for processing personal data without a legal basis. The conduct included signing documents without consent and marking consent checkboxes for commercial purposes without authorization. | ES | AEPD | GDPR | €200,000 | ↗ |
| 09 Feb 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined by the AEPD for unlawfully processing personal data and for failing to provide access to personal data requested by a former client. The case concerns non-compliance with data protection obligations. | ES | AEPD | GDPR | €140,000 | ↗ |
| 15 Jul 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for requesting a disproportionate amount of personal data, including a copy of the DNI, to process a request for information about account movements. The authority found this to be a breach of the data minimization principle. | ES | AEPD | GDPR | €70,000 | ↗ |
| 07 Oct 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for unauthorized remote management of a former employee's personal device. The authority found that the conduct breached the principles of lawful personal data processing. | ES | AEPD | GDPR | €200,000 | ↗ |
| 29 Jun 2018 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD EUR 25,000 for sending unsolicited commercial messages. The authority found that recipients were not provided with a free opt-out mechanism. | ES | AEPD | ePrivacy | €25,000 | ↗ |
| 18 Jun 2020 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD in the amount of EUR 30,000 for consulting personal data in credit files without an existing contractual relationship. The authority found that this conduct breached data processing principles. | ES | AEPD | GDPR | €30,000 | ↗ |
| 23 Jan 2017 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 06 Mar 2020 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for inaccurate processing of personal data. The bank demanded payment for a debt the complainant did not owe and shared the complainant’s personal data with a debt collection agency. | ES | AEPD | GDPR | €60,000 | ↗ |
| 29 Nov 2019 | BANCO BILBAO VIZCAYA ARGENTARIA SLBBVA was fined by the AEPD for sending unsolicited advertising to an individual who was not a customer of the bank. The authority found this to be a breach of data protection rules. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 21 May 2024 | BANCO CETELEM, S.A.Banco Cetelem, S.A. was fined by the AEPD 250,000 EUR for unauthorized processing of personal data. The case included charging the complainant’s bank account for a loan taken out by an unknown third party without consent. | ES | AEPD | GDPR | €250,000 | ↗ |
| 23 Jan 2024 | BANCO COOPERATIVO ESPAÑOL, S.A.Banco Cooperativo Español, S.A. was fined by the AEPD for a personal data breach. The incident allowed unauthorized access to personal data and breached the principles of confidentiality and integrity. | ES | AEPD | GDPR | €15,000 | ↗ |
| 18 Feb 2016 | Banco dell'oro Operatori professionali in oro srlBanco dell'oro Operatori professionali in oro srl was fined by the Garante EUR 2,400 for operating a video surveillance system without the required data protection notice. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 01 Jan 2020 | BANCO DE SABADELL, S.A.Banco de Sabadell was fined for sending a commercial email to a customer who had previously opted out of such communications. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 03 Jul 2025 | BANCO INVERSIS, S.A.Banco Inversis, S.A. was fined by the AEPD in the amount of 10,000 EUR for a personal data breach. The case involved unauthorized access to personal data, which breached Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2015 | BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails. The authority found this breached Article 21.1 of the LSSI on marketing communications without prior consent. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 07 Oct 2014 | BANCO SANTANDER, S.A.Banco Santander was fined by the AEPD EUR 2,000 for sending commercial emails despite the recipient's objection. The authority found this breached Article 21 of the LSSI on unsolicited electronic communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 01 Jan 2015 | BANCO SANTANDER, S.A.Banco Santander was fined EUR 1,500 by the AEPD for sending unsolicited commercial emails to a recipient who had previously opted out. The authority found this to be a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 01 Jan 2016 | BANCO SANTANDER, S.A.Banco Santander, S.A. was fined by the AEPD €8,000 for sending unsolicited commercial emails. The authority found that the messages did not provide a valid email address for recipients to opt out, breaching Article 21 of the LSSI. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 01 Jan 2015 | BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending an unsolicited commercial email to an individual who had not consented to receive such communications. The case concerns a breach of rules on marketing communications and recipient consent. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 19 Apr 2021 | BankThe Bank was fined by NAIH for breaching the principles of purpose limitation and data minimization when transferring personal data without a proper legal basis. The authority also found failures to respect the data subject's rights of access and objection. | HU | NAIH | GDPR | €13,900 | ↗ |