Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Apr 2026CROWD ENTERTAINMENT LIMITEDCROWD ENTERTAINMENT LIMITED was fined EUR 20,000 by the Romanian authority ANSPDCP. The sanction concerned violations of GDPR requirements.ROANSPDCPGDPR€20,000
10 Dec 2025Crowd Entertainment LimitedThe National Supervisory Authority for Personal Data Processing completed an investigation in November 2025 at Crowd Entertainment Limited and found violations of GDPR provisions. As a result, an administrative fine of EUR 15,000 was imposed.ROANSPDCPGDPR€15,000
28 May 2026Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna TorrigianiThe Italian Data Protection Authority imposed a 700 EUR fine on Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna Torrigiani. The case concerned a data protection breach during a patient's hospitalization in the orthopedics department, including improper handling of information about HIV status.ITGaranteGDPR€700
12 Nov 2015Croce Rosa Italiana s.r.l.Croce Rosa Italiana s.r.l. was fined for processing employee personal data using electronic tools for geolocation without adopting minimum security measures. The authority found a breach of Article 33 of the Italian Data Protection Code.ITGaranteGDPR€10,000
22 May 2018C.R.M. S.r.l.C.R.M. S.r.l. was fined EUR 28,000 for using a biometric system to record employee attendance without prior notification to the Garante. The authority found this to be a breach of data protection rules.ITGaranteGDPR€28,000
18 Mar 2018Cristiano PanepintoCristiano Panepinto was fined €26,000 by the Garante for sending promotional emails without obtaining users’ free and specific consent. The conduct breached Article 130 of the Italian Privacy Code.ITGaranteGDPR€26,000
12 Apr 2010CRISER INTERACTIVE, S.L.CRISER INTERACTIVE, S.L. was fined by the AEPD 1,200 EUR for sending unsolicited commercial emails. The authority found that recipients were not given a simple and free way to object to the processing of their data, in breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200
29 Apr 2021CRIQUET PUBLICIDAD, S.L.CRIQUET PUBLICIDAD, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails. The recipient’s address was registered on the Robinson List, which constitutes a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
19 Sept 2024CRIDOLMA BARCELONA S.L.CRIDOLMA BARCELONA S.L. was fined €9,000 by the AEPD for failing to properly handle a data subject access request. The case concerned a breach of Article 15 GDPR and non-compliance with a data protection authority resolution.ESAEPDGDPR€9,000
09 Jun 2022Cribis Credit Management s.r.l.Cribis Credit Management s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company unjustifiably communicated debtor information to third parties, in breach of GDPR Article 5.ITGaranteGDPR€10,000
08 May 2024CREMA GAMES, S.L.CREMA GAMES, S.L. was fined EUR 5,000 by the AEPD for breaching Article 15 of the GDPR. The company obstructed the complainant’s exercise of the right of access to their personal data.ESAEPDGDPR€5,000
27 Jun 2023Creditinfo Lánstraust hf.Creditinfo Lánstraust hf. was fined by Persónuvernd for recording loan default information without meeting the required registration conditions. The authority found breaches of GDPR transparency and lawfulness requirements in the processing of personal data.ISPersónuverndGDPR€254,000
16 Apr 2021CREATOR ENERGY, S.L.CREATOR ENERGY, S.L. was fined by the AEPD 6,000 EUR for using personal data without consent to contract gas, electricity, and maintenance services. The authority found this conduct breached Article 6(1)(b) GDPR.ESAEPDGDPR€6,000
20 Jul 2017Crea Futuro s.r.l.Crea Futuro s.r.l. was fined by the Garante 64,000 EUR for processing personal data without providing adequate information and obtaining consent. The breach affected about 2 million people, indicating a broad compliance impact.ITGaranteGDPR€64,000
16 Feb 2017Crabion s.r.l.Crabion s.r.l. was fined by the Garante in the amount of EUR 20,000 for processing genetic data without the required authorization. The case concerns breaches of the rules governing the lawful processing of sensitive personal data.ITGaranteGDPR€20,000
29 Apr 2022C.P. ***COMUNIDAD.1The entity installed surveillance cameras without informing the property owners. It also failed to provide the required information on the surveillance signs.ESAEPDGDPR€800
19 May 2021CP&A B.V.CP&A B.V. was fined by the AP in the amount of EUR 15,000 for processing employees' health data without a legal basis. The authority also found that adequate security measures were not implemented for this processing.NLAPGDPR€15,000
23 Apr 2023COYARE SLUCOYARE SLU was fined by the AEPD EUR 2,000 for a data protection breach linked to mass email sending. Using CC instead of BCC exposed recipients’ email addresses and could have compromised their identities.ESAEPDGDPR€2,000
11 Jul 2013Cowboys' Guest Ranch S.r.l.Cowboys' Guest Ranch S.r.l. was fined EUR 14,400 by the Garante for failing to provide the required privacy notice when collecting personal data through online forms, paper questionnaires, and dance competition registration forms. The breach concerned the obligation to inform data subjects about the processing of their personal data.ITGaranteGDPR€14,400
21 Sept 2023Cover Appliance LtdCover Appliance Ltd made 511,499 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of 200,000 GBP and issued an enforcement notice.GBICOePrivacy€230,000