Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Feb 2022Costampress S.p.A.Costampress S.p.A. was fined EUR 10,000 by the Garante for failing to take required steps after employment ended. The company did not delete the former employee’s email account or transfer the phone number, which breached GDPR requirements.ITGaranteGDPR€10,000
01 Jan 2022CosmoteThe Greek data protection authority imposed a €6 million fine on Cosmote under decision 4/2022. The sanction concerned inadequate security measures and retaining more data than permitted after a 2020 cyberattack.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€6,000,000
09 Oct 2018CosmoteCosmote was fined EUR 150,000 by the HDPA for making unsolicited promotional calls to subscribers who had opted out of such contact. The authority found that this conduct breached privacy and personal data protection rules.GRHDPAePrivacy€150,000
05 Aug 2022Cosmopol Security S.p.A.Cosmopol Security S.p.A. was fined EUR 20,000 by the Garante for failing to respond to a data subject's request to exercise GDPR rights. The case also involved not explaining the origin of the personal data after electronic invoices were received without any contractual relationship.ITGaranteGDPR€20,000
27 Mar 2025Corriere del Giorno 1947 Media Group Soc. Coop. ArlThe Garante imposed a fine of 6,000 EUR on Corriere del Giorno 1947 Media Group Soc. Coop. Arl for violations related to the right to be forgotten. The authority found that certain articles were no longer relevant and were not in the public interest.ITGaranteGDPR€6,000
13 Jan 2023CORREDURÍA DE SEGUROS DE MADRID, S.L.CORREDURÍA DE SEGUROS DE MADRID, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company linked the complainant’s bank account to insurance policies they had not taken out, resulting in unauthorized charges.ESAEPDGDPR€10,000
29 Dec 2023CORPORACIÓN DUAL GRUPO LC, S.L.CORPORACIÓN DUAL GRUPO LC, S.L. was fined €500 by the AEPD for failing to provide access to personal data and information requested by the data protection authority. The case concerns non-compliance with GDPR obligations, including Article 58(1).ESAEPDGDPR€500
26 Apr 2022CORPORACIÓN DE RADIO Y TELEVISIÓN ESPAÑOLA S.A.The company published audio of a victim's court statement in a high-profile case. The authority found a breach of the data minimization principle because excessive personal data was processed.ESAEPDGDPR€50,000
01 Jan 2019CORPORACION DE RADIO Y TELEVISION ESPAÑOLA SACORPORACION DE RADIO Y TELEVISION ESPAÑOLA SA was fined by the AEPD for a security incident involving the loss of unencrypted USB drives containing personal data. The authority found a breach of Article 32 GDPR on appropriate technical and organisational security measures.ESAEPDGDPR€60,000
11 Apr 2023CORPORACION DE MEDIOS DE EXTREMADURA, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. The authority found a breach of the data minimization principle and imposed a 150,000 EUR fine.ESAEPDGDPR€150,000
04 Feb 2022CORON ISLAND SLUCORON ISLAND SLU was fined by the AEPD 2,000 EUR for requiring a customer’s phone number when issuing an invoice. The authority found that the data was not necessary for invoicing, which breached the data minimization principle.ESAEPDGDPR€2,000
30 May 2024Corint Logistic SRLCorint Logistic SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
30 May 2024Corint Logistic SRLCorint Logistic SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliant processing of personal data.ROANSPDCPGDPR€1,000
26 Jun 2014CO.RE.MA. di Gian Luigi Morando & C. s.a.s.CO.RE.MA. was fined by the Garante EUR 12,000 for using an integrated video surveillance system that allowed viewing images from workplaces. Required safeguards were not implemented, including logical separation of recordings from different data controllers.ITGaranteGDPR€12,000
14 Oct 2025CORAL TRAVEL & TOURISM SERVICES S.R.L.The operator was fined for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€982
27 Oct 2022COPY COFFEE, S.L.COPY COFFEE, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails despite the recipient's prior objection. The authority found a breach of Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€5,000
26 Mar 2026Copacabana s.r.l.Copacabana s.r.l. was fined EUR 2,000 by the Garante for installing a video surveillance system without the required informational signage and necessary authorization. The authority cited a breach of GDPR Article 13.ITGaranteGDPR€2,000
22 Feb 2024Coop Italia Società CooperativaCoop Italia Società Cooperativa was fined by the Garante 90,000 EUR for unlawfully processing personal data for marketing purposes without proper consent. The authority found a breach of GDPR principles, including Article 5.ITGaranteGDPR€90,000
14 Jan 2021Coop Finnmark SAThe Norwegian DPA fined Coop Finnmark SA 400,000 NOK for unlawfully sharing a surveillance video from a store. The store manager recorded the footage with a mobile phone and shared it without a legal basis, breaching GDPR principles.NODatatilsynetGDPR€38,796
01 Jun 2023Cooperjob S.p.A.Cooperjob S.p.A. was fined EUR 20,000 by the Garante for failing to respond within the required timeframe to a job applicant’s request to delete personal data. The authority found a breach of GDPR Article 12 on timely handling of data subject requests.ITGaranteGDPR€20,000