Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Jul 2024CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO, S.A.U.Curenergía was fined by the AEPD for processing personal data without a proper legal basis. The company used former customer data without full consent in connection with a new contract.ESAEPDGDPR€100,000
01 May 2025CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.CURENERGÍA was fined EUR 10,000 by the AEPD for sharing personal data with IBERDROLA without the data subject’s consent. The disclosure led to a contract offer at a higher price than requested.ESAEPDGDPR€10,000
24 Jul 2025CURENERGÍACURENERGÍA was fined by the AEPD EUR 1,000,000 for a data protection breach involving improper handling of personal data due to human error. The issue was corrected after notification.ESAEPDGDPR€1,000,000
31 May 2024CUMACA MOTOR, S.L.CUMACA MOTOR, S.L. was fined EUR 7,500 by the AEPD for requiring customers to provide a copy of their identity document without a valid justification. The authority found that this breached the GDPR data minimization principle.ESAEPDGDPR€7,500
28 May 2024CUI ZSQ FOOD, S.L.CUI ZSQ FOOD, S.L. was fined by the AEPD 70,000 EUR for using a video surveillance system to intimidate employees. The company shared footage of an employee’s absence in a work chat, which breached data protection rules.ESAEPDGDPR€70,000
26 Nov 2025Cucina di Fabio S.R.L.ANSPDCP imposed a fine of EUR 1,000 on Cucina di Fabio S.R.L. for a GDPR violation. The case concerns a confirmed breach of personal data protection rules.ROANSPDCPGDPR€1,000
26 Nov 2025Cucina di Fabio S.R.L.ANSPDCP imposed a fine of EUR 2,000 on Cucina di Fabio S.R.L. for a GDPR violation. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
23 Jan 2008Cubo società consulenza aziendale s.r.l.Cubo società consulenza aziendale s.r.l. was fined by the Garante 10,000 EUR for violating data protection rules. The case concerned the processing of personal data in the context of personnel search and selection activities.ITGaranteGDPR€10,000
06 Mar 2025CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD in the amount of 900 EUR for failing to comply with data protection authority resolutions. The breach concerned the absence of required privacy information on the company website and in contracts.ESAEPDGDPR€900
15 Jan 2024CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD 3,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 GDPR, which requires clear notice to data subjects.ESAEPDGDPR€3,000
22 Sept 2011C.T.M. s.p.a.C.T.M. s.p.a. was fined 40,000 EUR by the Italian data protection authority, Garante. The case concerned the failure to formally designate data processors and a breach of minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€40,000
01 Jan 2014CTI WEB SERVICIOS INFORMATICOS S.L.CTI WEB SERVICIOS INFORMATICOS S.L. was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited commercial emails. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€3,000
01 Jan 2013CTI WEB SERVICIOS INFORMATICOS S.L.CTI WEB SERVICIOS INFORMATICOS S.L. was fined €600 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior consent.ESAEPDePrivacy€600
31 Jan 2019CT BARCT BAR was fined by the Garante for unlawful processing of personal data through its video surveillance system. The recordings were retained for 15 days without proper compliance with applicable rules.ITGaranteGDPR€12,000
29 Apr 2024Csomagküldő cég adatkezeléseThe controller was fined for sending emails without a proper legal basis and for failing to respond to a data protection complaint. The authority found breaches of GDPR Articles 5 and 13.HUNAIHGDPR€12,750
18 Jan 2018C.S. GROUP S.p.a.C.S. GROUP S.p.a. was fined by the Italian Garante in the amount of €60,000. The case concerned profiling and the processing of personal data without a proper legal basis in connection with vehicle rental services.ITGaranteGDPR€60,000
10 Jan 2025CRUZ ROJA ESPAÑOLACRUZ ROJA ESPAÑOLA was fined EUR 50,000 by the AEPD for a personal data protection breach. The case involved the unauthorized disclosure of patient data in a communication about a change in embryo bank management.ESAEPDGDPR€50,000
29 Apr 2016CRUZ ROJA ESPAÑOLACRUZ ROJA ESPAÑOLA was fined by the AEPD EUR 1,100 for sending unsolicited commercial emails to a recipient who had previously requested data cancellation. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,100
08 Jun 2023Crown Glazing LtdThe case was part of Operation Tinago, which assessed complaint trends in the energy and home improvements sector. Crown Glazing Ltd made 503,445 unsolicited calls to TPS-registered numbers between 4 January and 11 November 2021, resulting in 37 complaints.GBICOGDPR€150,000
28 Apr 2026CROWD ENTERTAINMENT LIMITEDCROWD ENTERTAINMENT LIMITED was fined EUR 15,000 by ANSPDCP for GDPR violations. The case concerned non-compliant processing of personal data.ROANSPDCPGDPR€15,000