BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Jul 2020 | CABRERA & GIL ABOGADOS, S.L.P.CABRERA & GIL ABOGADOS, S.L.P. was fined by the AEPD €2,000 for disclosing personal data without consent. The case concerns Article 6 GDPR, which requires a valid legal basis for processing personal data. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2019 | CAFE BAR NINA (Nina Cb)CAFE BAR NINA was fined €2,000 by the AEPD for installing an unauthorized surveillance camera. The conduct breached data protection requirements. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jul 2020 | CAFÉ RESTAURANTE B.B.B.The entity installed a surveillance camera facing a public space, despite recommendations from the local police. This breached data protection regulations. | ES | AEPD | GDPR | €1,500 | ↗ |
| 01 Jan 2018 | CAFETERÍA NAGASAKICAFETERÍA NAGASAKI was fined by the AEPD 1,500 EUR for using surveillance cameras to capture images of public sidewalks without justification. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 09 May 2024 | Caffetteria 77 di Dughetti BarbaraThe Garante fined Caffetteria 77 di Dughetti Barbara EUR 3,000 for operating a video surveillance system without meeting the legal requirements. The system captured both customers and employees, creating a data protection compliance breach. | IT | Garante | GDPR | €3,000 | ↗ |
| 06 Apr 2021 | CAFFE VECCHIO, S.L.CAFFE VECCHIO, S.L. was fined by the AEPD EUR 1,500 for publishing an individual's personal data in response to negative Google reviews. The disclosure included the person's name and details of an employment sanction. | ES | AEPD | GDPR | €1,500 | ↗ |
| 03 Apr 2023 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including an individual's data in a creditworthiness file without a lawful basis. The authority found this conduct violated Article 6 of the GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 07 Jan 2022 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD EUR 70,000 for including personal data in credit information systems without a proper legal basis. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 05 Jul 2022 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined 70,000 EUR by the AEPD. The company continued to demand payment of a debt that had been annulled by a court ruling, which breached data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | CAIXABANK S.A.CaixaBank was fined EUR 25,000 by the AEPD for failing to update a customer's address despite repeated requests. The authority found this to be a breach of the GDPR right to rectification. | ES | AEPD | GDPR | €25,000 | ↗ |
| 26 Mar 2021 | CAIXABANK S.A.CAIXABANK S.A. was fined EUR 60,000 by the AEPD for processing personal data without consent. The case concerned a current account contract signed on behalf of the complainant without proper authorization. | ES | AEPD | GDPR | €60,000 | ↗ |
| 11 Apr 2023 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 200,000 for failing to remove personal data from a credit information system after the debt was sold. The authority found that the continued processing of the data was not compliant with data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 18 Jun 2020 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD for using pre-marked consents for data processing and charging customers a fee if they refused data sharing with third parties. The authority found that these practices breached GDPR requirements on valid consent and lawful processing. | ES | AEPD | GDPR | €2,100,000 | ↗ |
| 07 Mar 2024 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,000,000 for pre-setting consent to share data with the Social Security Treasury without giving customers the option to refuse. The authority found this practice breached GDPR requirements for valid consent. | ES | AEPD | GDPR | €2,000,000 | ↗ |
| 01 Jan 2024 | CAIXABANK, S.A.CAIXABANK was fined by the AEPD for sending a privacy policy update to a non-client. The authority found that the stated legitimate-interest basis for processing did not have proper consent support. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Jan 2014 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD 5,000 EUR for sending unauthorized commercial emails. The conduct occurred after the complainant had exercised the right to object to the use of their data for advertising purposes. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Feb 2019 | CAIXABANK, S.A.CAIXABANK was fined by the AEPD for introducing new data protection conditions that required consent for sharing data within its group. The authority found the measure disproportionate and lacking a proper legal basis. | ES | AEPD | GDPR | €6,500,000 | ↗ |
| 16 Apr 2025 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 500,000 for failing to implement measures to ensure data integrity and confidentiality. The breach resulted in unauthorized access to personal data, indicating insufficient technical or organizational safeguards. | ES | AEPD | GDPR | €500,000 | ↗ |
| 03 Feb 2017 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,500 for sending a customer an unsolicited advertising SMS. The recipient had not consented to receive commercial communications, which breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 07 Oct 2014 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial communications by email. The conduct breached Article 21 of the LSSI, which restricts unwanted marketing messages. | ES | AEPD | ePrivacy | €5,000 | ↗ |