BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Apr 2026 | CROWD ENTERTAINMENT LIMITEDCROWD ENTERTAINMENT LIMITED was fined EUR 20,000 by the Romanian authority ANSPDCP. The sanction concerned violations of GDPR requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 10 Dec 2025 | Crowd Entertainment LimitedThe National Supervisory Authority for Personal Data Processing completed an investigation in November 2025 at Crowd Entertainment Limited and found violations of GDPR provisions. As a result, an administrative fine of EUR 15,000 was imposed. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 28 May 2026 | Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna TorrigianiThe Italian Data Protection Authority imposed a 700 EUR fine on Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna Torrigiani. The case concerned a data protection breach during a patient's hospitalization in the orthopedics department, including improper handling of information about HIV status. | IT | Garante | GDPR | €700 | ↗ |
| 12 Nov 2015 | Croce Rosa Italiana s.r.l.Croce Rosa Italiana s.r.l. was fined for processing employee personal data using electronic tools for geolocation without adopting minimum security measures. The authority found a breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | C.R.M. S.r.l.C.R.M. S.r.l. was fined EUR 28,000 for using a biometric system to record employee attendance without prior notification to the Garante. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €28,000 | ↗ |
| 18 Mar 2018 | Cristiano PanepintoCristiano Panepinto was fined €26,000 by the Garante for sending promotional emails without obtaining users’ free and specific consent. The conduct breached Article 130 of the Italian Privacy Code. | IT | Garante | GDPR | €26,000 | ↗ |
| 12 Apr 2010 | CRISER INTERACTIVE, S.L.CRISER INTERACTIVE, S.L. was fined by the AEPD 1,200 EUR for sending unsolicited commercial emails. The authority found that recipients were not given a simple and free way to object to the processing of their data, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 29 Apr 2021 | CRIQUET PUBLICIDAD, S.L.CRIQUET PUBLICIDAD, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails. The recipient’s address was registered on the Robinson List, which constitutes a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 19 Sept 2024 | CRIDOLMA BARCELONA S.L.CRIDOLMA BARCELONA S.L. was fined €9,000 by the AEPD for failing to properly handle a data subject access request. The case concerned a breach of Article 15 GDPR and non-compliance with a data protection authority resolution. | ES | AEPD | GDPR | €9,000 | ↗ |
| 09 Jun 2022 | Cribis Credit Management s.r.l.Cribis Credit Management s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company unjustifiably communicated debtor information to third parties, in breach of GDPR Article 5. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 May 2024 | CREMA GAMES, S.L.CREMA GAMES, S.L. was fined EUR 5,000 by the AEPD for breaching Article 15 of the GDPR. The company obstructed the complainant’s exercise of the right of access to their personal data. | ES | AEPD | GDPR | €5,000 | ↗ |
| 27 Jun 2023 | Creditinfo Lánstraust hf.Creditinfo Lánstraust hf. was fined by Persónuvernd for recording loan default information without meeting the required registration conditions. The authority found breaches of GDPR transparency and lawfulness requirements in the processing of personal data. | IS | Persónuvernd | GDPR | €254,000 | ↗ |
| 16 Apr 2021 | CREATOR ENERGY, S.L.CREATOR ENERGY, S.L. was fined by the AEPD 6,000 EUR for using personal data without consent to contract gas, electricity, and maintenance services. The authority found this conduct breached Article 6(1)(b) GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 20 Jul 2017 | Crea Futuro s.r.l.Crea Futuro s.r.l. was fined by the Garante 64,000 EUR for processing personal data without providing adequate information and obtaining consent. The breach affected about 2 million people, indicating a broad compliance impact. | IT | Garante | GDPR | €64,000 | ↗ |
| 16 Feb 2017 | Crabion s.r.l.Crabion s.r.l. was fined by the Garante in the amount of EUR 20,000 for processing genetic data without the required authorization. The case concerns breaches of the rules governing the lawful processing of sensitive personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Apr 2022 | C.P. ***COMUNIDAD.1The entity installed surveillance cameras without informing the property owners. It also failed to provide the required information on the surveillance signs. | ES | AEPD | GDPR | €800 | ↗ |
| 19 May 2021 | CP&A B.V.CP&A B.V. was fined by the AP in the amount of EUR 15,000 for processing employees' health data without a legal basis. The authority also found that adequate security measures were not implemented for this processing. | NL | AP | GDPR | €15,000 | ↗ |
| 23 Apr 2023 | COYARE SLUCOYARE SLU was fined by the AEPD EUR 2,000 for a data protection breach linked to mass email sending. Using CC instead of BCC exposed recipients’ email addresses and could have compromised their identities. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Jul 2013 | Cowboys' Guest Ranch S.r.l.Cowboys' Guest Ranch S.r.l. was fined EUR 14,400 by the Garante for failing to provide the required privacy notice when collecting personal data through online forms, paper questionnaires, and dance competition registration forms. The breach concerned the obligation to inform data subjects about the processing of their personal data. | IT | Garante | GDPR | €14,400 | ↗ |
| 21 Sept 2023 | Cover Appliance LtdCover Appliance Ltd made 511,499 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of 200,000 GBP and issued an enforcement notice. | GB | ICO | ePrivacy | €230,000 | ↗ |