Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Aug 2022BankThe Bank and the Mortgage Bank processed personal data for credit assessment without a legal basis. They also failed to provide adequate information required under the GDPR.HUNAIHGDPR€75,600
26 Jun 2019Banki adatkezelés és érintetti joggyakorlásThe controller was fined for processing personal data without a legal basis and for failing to provide adequate information about the right to object. The authority found breaches of core transparency and lawfulness obligations.HUNAIHGDPR€3,090
24 Feb 2020BANKIA, S.A.BANKIA, S.A. was fined by the AEPD EUR 50,000 for sending commercial advertising by postal mail to a customer who had objected to the processing of their data for advertising purposes. The authority found this conduct contrary to GDPR Article 6(1)(f).ESAEPDGDPR€50,000
05 Aug 2020BANKIA, S.A.BANKIA, S.A. was fined by the AEPD 50,000 EUR for retaining a former client’s personal data for more than 16 years without a valid basis. The authority found this to be a breach of data protection principles, especially storage limitation.ESAEPDGDPR€50,000
15 Mar 2023BANKINTER CONSUMER FINANCE E.F.C., S.A.Bankinter Consumer Finance issued a duplicate card without the customer's consent and sent it to an incorrect address. This led to unauthorized transactions and indicated a failure in data protection and payment security controls.ESAEPDGDPR€70,000
13 Oct 2025BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 400,000 EUR for failing to implement adequate technical and organizational measures to ensure data integrity and confidentiality. The deficiency resulted in unauthorized access to personal data.ESAEPDGDPR€400,000
01 Jan 2016BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 10,000 EUR for failing to provide the required cookie information and for not obtaining consent on its website. The case concerns breaches of notice and consent obligations for website cookies.ESAEPDePrivacy€10,000
06 Apr 2022BANKINTER, S.A.BANKINTER, S.A. was fined EUR 70,000 by the AEPD for a data protection breach. The case involved the unauthorized disclosure of sensitive banking information caused by an isolated IT error.ESAEPDGDPR€70,000
30 Jan 2023BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD in the amount of 1,000 EUR for not adequately handling a data subject access request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€1,000
16 Dec 2025Bank MillenniumThe Polish Supreme Administrative Court upheld a PLN 350,000 administrative fine imposed on Bank Millennium by the President of the Personal Data Protection Office. The sanction concerned failure to report a personal data breach and failure to notify affected individuals after a courier shipment containing customer data was lost.PLUrząd Ochrony Danych OsobowychGDPR€82,922
18 Dec 2013Bank of CyprusBank of Cyprus was fined EUR 5,000 by the HDPA. The authority found illegal access to and disclosure of creditworthiness data from the Tiresias database.GRHDPAGDPR€5,000
27 Feb 2023Bank of Ireland 365 (‘BOI’)The Irish DPC fined Bank of Ireland 365 (‘BOI’) €750,000 in inquiry IN-20-7-2. The fine has been collected.IEDPCGDPR€750,000
14 Mar 2022Bank of Ireland Group plcThe Irish DPC fined Bank of Ireland Group plc EUR 463,000 in inquiry IN-19-9-5. The penalty status is recorded as collected.IEDPCGDPR€463,000
01 Jan 2022BANQUETES SANTA ANA, S.L.BANQUETES SANTA ANA, S.L. was fined EUR 5,000 by the AEPD for collecting personal data, including DNI numbers, from wedding guests without providing information about data processing. The authority found a breach of data minimization and transparency obligations.ESAEPDGDPR€5,000
13 May 2015Barbirato Danilo s.a.s.Barbirato Danilo s.a.s. was fined by the Garante EUR 16,800 for failing to provide the required privacy notice on its website and for improper use of a video surveillance system. The authority cited inadequate CCTV signage and excessive retention of recorded images.ITGaranteGDPR€16,800
13 May 2015Barbirato Danilo s.a.s. di Barbirato Marco e c.Barbirato Danilo s.a.s. was fined by the Garante 16,800 EUR for failing to provide the required privacy notice on its data collection form. The authority also found breaches of CCTV rules, including inadequate signage and excessive retention of recorded images.ITGaranteGDPR€16,800
14 Jul 2017BARCLAYS BANK PLC Sucursal en EspañaBARCLAYS BANK PLC Sucursal en España was fined by the AEPD 5,000 EUR for sending commercial emails without meeting the requirements of Article 21 of the LSSI. The breach occurred despite the recipient's request to cancel their personal data.ESAEPDePrivacy€5,000
08 Jun 2021BAR DA VINCI (SHUANGFENG ZHOU)BAR DA VINCI (SHUANGFENG ZHOU) was fined 500 EUR by the AEPD for operating a surveillance system without proper signage. The authority also found that the system captured excessive footage of public areas, constituting a GDPR breach.ESAEPDGDPR€500
11 Apr 2024BAR DEL PORTICO S.A.S.BAR DEL PORTICO S.A.S. was fined EUR 1,000 by the Garante for operating active video surveillance. The system recorded both customers and employees without meeting GDPR requirements.ITGaranteGDPR€1,000
31 Mar 2025BAR EL ANDÉN M. ROJO, S.L.The entity was fined for recording audio and video in the establishment without proper informational signage. The authority considered this a breach of data protection requirements.ESAEPDGDPR€1,000