Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Jul 2020CABRERA & GIL ABOGADOS, S.L.P.CABRERA & GIL ABOGADOS, S.L.P. was fined by the AEPD €2,000 for disclosing personal data without consent. The case concerns Article 6 GDPR, which requires a valid legal basis for processing personal data.ESAEPDGDPR€2,000
01 Jan 2019CAFE BAR NINA (Nina Cb)CAFE BAR NINA was fined €2,000 by the AEPD for installing an unauthorized surveillance camera. The conduct breached data protection requirements.ESAEPDGDPR€2,000
01 Jul 2020CAFÉ RESTAURANTE B.B.B.The entity installed a surveillance camera facing a public space, despite recommendations from the local police. This breached data protection regulations.ESAEPDGDPR€1,500
01 Jan 2018CAFETERÍA NAGASAKICAFETERÍA NAGASAKI was fined by the AEPD 1,500 EUR for using surveillance cameras to capture images of public sidewalks without justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,500
09 May 2024Caffetteria 77 di Dughetti BarbaraThe Garante fined Caffetteria 77 di Dughetti Barbara EUR 3,000 for operating a video surveillance system without meeting the legal requirements. The system captured both customers and employees, creating a data protection compliance breach.ITGaranteGDPR€3,000
06 Apr 2021CAFFE VECCHIO, S.L.CAFFE VECCHIO, S.L. was fined by the AEPD EUR 1,500 for publishing an individual's personal data in response to negative Google reviews. The disclosure included the person's name and details of an employment sanction.ESAEPDGDPR€1,500
03 Apr 2023CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including an individual's data in a creditworthiness file without a lawful basis. The authority found this conduct violated Article 6 of the GDPR.ESAEPDGDPR€200,000
07 Jan 2022CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD EUR 70,000 for including personal data in credit information systems without a proper legal basis. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
05 Jul 2022CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined 70,000 EUR by the AEPD. The company continued to demand payment of a debt that had been annulled by a court ruling, which breached data protection rules.ESAEPDGDPR€70,000
01 Jan 2022CAIXABANK S.A.CaixaBank was fined EUR 25,000 by the AEPD for failing to update a customer's address despite repeated requests. The authority found this to be a breach of the GDPR right to rectification.ESAEPDGDPR€25,000
26 Mar 2021CAIXABANK S.A.CAIXABANK S.A. was fined EUR 60,000 by the AEPD for processing personal data without consent. The case concerned a current account contract signed on behalf of the complainant without proper authorization.ESAEPDGDPR€60,000
11 Apr 2023CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 200,000 for failing to remove personal data from a credit information system after the debt was sold. The authority found that the continued processing of the data was not compliant with data protection rules.ESAEPDGDPR€200,000
18 Jun 2020CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD for using pre-marked consents for data processing and charging customers a fee if they refused data sharing with third parties. The authority found that these practices breached GDPR requirements on valid consent and lawful processing.ESAEPDGDPR€2,100,000
07 Mar 2024CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,000,000 for pre-setting consent to share data with the Social Security Treasury without giving customers the option to refuse. The authority found this practice breached GDPR requirements for valid consent.ESAEPDGDPR€2,000,000
01 Jan 2024CAIXABANK, S.A.CAIXABANK was fined by the AEPD for sending a privacy policy update to a non-client. The authority found that the stated legitimate-interest basis for processing did not have proper consent support.ESAEPDGDPR€200,000
01 Jan 2014CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD 5,000 EUR for sending unauthorized commercial emails. The conduct occurred after the complainant had exercised the right to object to the use of their data for advertising purposes.ESAEPDePrivacy€5,000
01 Feb 2019CAIXABANK, S.A.CAIXABANK was fined by the AEPD for introducing new data protection conditions that required consent for sharing data within its group. The authority found the measure disproportionate and lacking a proper legal basis.ESAEPDGDPR€6,500,000
16 Apr 2025CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 500,000 for failing to implement measures to ensure data integrity and confidentiality. The breach resulted in unauthorized access to personal data, indicating insufficient technical or organizational safeguards.ESAEPDGDPR€500,000
03 Feb 2017CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,500 for sending a customer an unsolicited advertising SMS. The recipient had not consented to receive commercial communications, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€2,500
07 Oct 2014CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial communications by email. The conduct breached Article 21 of the LSSI, which restricts unwanted marketing messages.ESAEPDePrivacy€5,000