BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 Jul 2024 | CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO, S.A.U.Curenergía was fined by the AEPD for processing personal data without a proper legal basis. The company used former customer data without full consent in connection with a new contract. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 May 2025 | CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.CURENERGÍA was fined EUR 10,000 by the AEPD for sharing personal data with IBERDROLA without the data subject’s consent. The disclosure led to a contract offer at a higher price than requested. | ES | AEPD | GDPR | €10,000 | ↗ |
| 24 Jul 2025 | CURENERGÍACURENERGÍA was fined by the AEPD EUR 1,000,000 for a data protection breach involving improper handling of personal data due to human error. The issue was corrected after notification. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 31 May 2024 | CUMACA MOTOR, S.L.CUMACA MOTOR, S.L. was fined EUR 7,500 by the AEPD for requiring customers to provide a copy of their identity document without a valid justification. The authority found that this breached the GDPR data minimization principle. | ES | AEPD | GDPR | €7,500 | ↗ |
| 28 May 2024 | CUI ZSQ FOOD, S.L.CUI ZSQ FOOD, S.L. was fined by the AEPD 70,000 EUR for using a video surveillance system to intimidate employees. The company shared footage of an employee’s absence in a work chat, which breached data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 26 Nov 2025 | Cucina di Fabio S.R.L.ANSPDCP imposed a fine of EUR 1,000 on Cucina di Fabio S.R.L. for a GDPR violation. The case concerns a confirmed breach of personal data protection rules. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 26 Nov 2025 | Cucina di Fabio S.R.L.ANSPDCP imposed a fine of EUR 2,000 on Cucina di Fabio S.R.L. for a GDPR violation. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 23 Jan 2008 | Cubo società consulenza aziendale s.r.l.Cubo società consulenza aziendale s.r.l. was fined by the Garante 10,000 EUR for violating data protection rules. The case concerned the processing of personal data in the context of personnel search and selection activities. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Mar 2025 | CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD in the amount of 900 EUR for failing to comply with data protection authority resolutions. The breach concerned the absence of required privacy information on the company website and in contracts. | ES | AEPD | GDPR | €900 | ↗ |
| 15 Jan 2024 | CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD 3,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 GDPR, which requires clear notice to data subjects. | ES | AEPD | GDPR | €3,000 | ↗ |
| 22 Sept 2011 | C.T.M. s.p.a.C.T.M. s.p.a. was fined 40,000 EUR by the Italian data protection authority, Garante. The case concerned the failure to formally designate data processors and a breach of minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 01 Jan 2014 | CTI WEB SERVICIOS INFORMATICOS S.L.CTI WEB SERVICIOS INFORMATICOS S.L. was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited commercial emails. This conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jan 2013 | CTI WEB SERVICIOS INFORMATICOS S.L.CTI WEB SERVICIOS INFORMATICOS S.L. was fined €600 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 31 Jan 2019 | CT BARCT BAR was fined by the Garante for unlawful processing of personal data through its video surveillance system. The recordings were retained for 15 days without proper compliance with applicable rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 29 Apr 2024 | Csomagküldő cég adatkezeléseThe controller was fined for sending emails without a proper legal basis and for failing to respond to a data protection complaint. The authority found breaches of GDPR Articles 5 and 13. | HU | NAIH | GDPR | €12,750 | ↗ |
| 18 Jan 2018 | C.S. GROUP S.p.a.C.S. GROUP S.p.a. was fined by the Italian Garante in the amount of €60,000. The case concerned profiling and the processing of personal data without a proper legal basis in connection with vehicle rental services. | IT | Garante | GDPR | €60,000 | ↗ |
| 10 Jan 2025 | CRUZ ROJA ESPAÑOLACRUZ ROJA ESPAÑOLA was fined EUR 50,000 by the AEPD for a personal data protection breach. The case involved the unauthorized disclosure of patient data in a communication about a change in embryo bank management. | ES | AEPD | GDPR | €50,000 | ↗ |
| 29 Apr 2016 | CRUZ ROJA ESPAÑOLACRUZ ROJA ESPAÑOLA was fined by the AEPD EUR 1,100 for sending unsolicited commercial emails to a recipient who had previously requested data cancellation. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,100 | ↗ |
| 08 Jun 2023 | Crown Glazing LtdThe case was part of Operation Tinago, which assessed complaint trends in the energy and home improvements sector. Crown Glazing Ltd made 503,445 unsolicited calls to TPS-registered numbers between 4 January and 11 November 2021, resulting in 37 complaints. | GB | ICO | GDPR | €150,000 | ↗ |
| 28 Apr 2026 | CROWD ENTERTAINMENT LIMITEDCROWD ENTERTAINMENT LIMITED was fined EUR 15,000 by ANSPDCP for GDPR violations. The case concerned non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €15,000 | ↗ |