BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Aug 2022 | BankThe Bank and the Mortgage Bank processed personal data for credit assessment without a legal basis. They also failed to provide adequate information required under the GDPR. | HU | NAIH | GDPR | €75,600 | ↗ |
| 26 Jun 2019 | Banki adatkezelés és érintetti joggyakorlásThe controller was fined for processing personal data without a legal basis and for failing to provide adequate information about the right to object. The authority found breaches of core transparency and lawfulness obligations. | HU | NAIH | GDPR | €3,090 | ↗ |
| 24 Feb 2020 | BANKIA, S.A.BANKIA, S.A. was fined by the AEPD EUR 50,000 for sending commercial advertising by postal mail to a customer who had objected to the processing of their data for advertising purposes. The authority found this conduct contrary to GDPR Article 6(1)(f). | ES | AEPD | GDPR | €50,000 | ↗ |
| 05 Aug 2020 | BANKIA, S.A.BANKIA, S.A. was fined by the AEPD 50,000 EUR for retaining a former client’s personal data for more than 16 years without a valid basis. The authority found this to be a breach of data protection principles, especially storage limitation. | ES | AEPD | GDPR | €50,000 | ↗ |
| 15 Mar 2023 | BANKINTER CONSUMER FINANCE E.F.C., S.A.Bankinter Consumer Finance issued a duplicate card without the customer's consent and sent it to an incorrect address. This led to unauthorized transactions and indicated a failure in data protection and payment security controls. | ES | AEPD | GDPR | €70,000 | ↗ |
| 13 Oct 2025 | BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 400,000 EUR for failing to implement adequate technical and organizational measures to ensure data integrity and confidentiality. The deficiency resulted in unauthorized access to personal data. | ES | AEPD | GDPR | €400,000 | ↗ |
| 01 Jan 2016 | BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 10,000 EUR for failing to provide the required cookie information and for not obtaining consent on its website. The case concerns breaches of notice and consent obligations for website cookies. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 06 Apr 2022 | BANKINTER, S.A.BANKINTER, S.A. was fined EUR 70,000 by the AEPD for a data protection breach. The case involved the unauthorized disclosure of sensitive banking information caused by an isolated IT error. | ES | AEPD | GDPR | €70,000 | ↗ |
| 30 Jan 2023 | BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD in the amount of 1,000 EUR for not adequately handling a data subject access request. The authority found a breach of Article 15 of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 16 Dec 2025 | Bank MillenniumThe Polish Supreme Administrative Court upheld a PLN 350,000 administrative fine imposed on Bank Millennium by the President of the Personal Data Protection Office. The sanction concerned failure to report a personal data breach and failure to notify affected individuals after a courier shipment containing customer data was lost. | PL | Urząd Ochrony Danych Osobowych | GDPR | €82,922 | ↗ |
| 18 Dec 2013 | Bank of CyprusBank of Cyprus was fined EUR 5,000 by the HDPA. The authority found illegal access to and disclosure of creditworthiness data from the Tiresias database. | GR | HDPA | GDPR | €5,000 | ↗ |
| 27 Feb 2023 | Bank of Ireland 365 (‘BOI’)The Irish DPC fined Bank of Ireland 365 (‘BOI’) €750,000 in inquiry IN-20-7-2. The fine has been collected. | IE | DPC | GDPR | €750,000 | ↗ |
| 14 Mar 2022 | Bank of Ireland Group plcThe Irish DPC fined Bank of Ireland Group plc EUR 463,000 in inquiry IN-19-9-5. The penalty status is recorded as collected. | IE | DPC | GDPR | €463,000 | ↗ |
| 01 Jan 2022 | BANQUETES SANTA ANA, S.L.BANQUETES SANTA ANA, S.L. was fined EUR 5,000 by the AEPD for collecting personal data, including DNI numbers, from wedding guests without providing information about data processing. The authority found a breach of data minimization and transparency obligations. | ES | AEPD | GDPR | €5,000 | ↗ |
| 13 May 2015 | Barbirato Danilo s.a.s.Barbirato Danilo s.a.s. was fined by the Garante EUR 16,800 for failing to provide the required privacy notice on its website and for improper use of a video surveillance system. The authority cited inadequate CCTV signage and excessive retention of recorded images. | IT | Garante | GDPR | €16,800 | ↗ |
| 13 May 2015 | Barbirato Danilo s.a.s. di Barbirato Marco e c.Barbirato Danilo s.a.s. was fined by the Garante 16,800 EUR for failing to provide the required privacy notice on its data collection form. The authority also found breaches of CCTV rules, including inadequate signage and excessive retention of recorded images. | IT | Garante | GDPR | €16,800 | ↗ |
| 14 Jul 2017 | BARCLAYS BANK PLC Sucursal en EspañaBARCLAYS BANK PLC Sucursal en España was fined by the AEPD 5,000 EUR for sending commercial emails without meeting the requirements of Article 21 of the LSSI. The breach occurred despite the recipient's request to cancel their personal data. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 08 Jun 2021 | BAR DA VINCI (SHUANGFENG ZHOU)BAR DA VINCI (SHUANGFENG ZHOU) was fined 500 EUR by the AEPD for operating a surveillance system without proper signage. The authority also found that the system captured excessive footage of public areas, constituting a GDPR breach. | ES | AEPD | GDPR | €500 | ↗ |
| 11 Apr 2024 | BAR DEL PORTICO S.A.S.BAR DEL PORTICO S.A.S. was fined EUR 1,000 by the Garante for operating active video surveillance. The system recorded both customers and employees without meeting GDPR requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 31 Mar 2025 | BAR EL ANDÉN M. ROJO, S.L.The entity was fined for recording audio and video in the establishment without proper informational signage. The authority considered this a breach of data protection requirements. | ES | AEPD | GDPR | €1,000 | ↗ |