BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Feb 2022 | Costampress S.p.A.Costampress S.p.A. was fined EUR 10,000 by the Garante for failing to take required steps after employment ended. The company did not delete the former employee’s email account or transfer the phone number, which breached GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2022 | CosmoteThe Greek data protection authority imposed a €6 million fine on Cosmote under decision 4/2022. The sanction concerned inadequate security measures and retaining more data than permitted after a 2020 cyberattack. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €6,000,000 | ↗ |
| 09 Oct 2018 | CosmoteCosmote was fined EUR 150,000 by the HDPA for making unsolicited promotional calls to subscribers who had opted out of such contact. The authority found that this conduct breached privacy and personal data protection rules. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 05 Aug 2022 | Cosmopol Security S.p.A.Cosmopol Security S.p.A. was fined EUR 20,000 by the Garante for failing to respond to a data subject's request to exercise GDPR rights. The case also involved not explaining the origin of the personal data after electronic invoices were received without any contractual relationship. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Mar 2025 | Corriere del Giorno 1947 Media Group Soc. Coop. ArlThe Garante imposed a fine of 6,000 EUR on Corriere del Giorno 1947 Media Group Soc. Coop. Arl for violations related to the right to be forgotten. The authority found that certain articles were no longer relevant and were not in the public interest. | IT | Garante | GDPR | €6,000 | ↗ |
| 13 Jan 2023 | CORREDURÍA DE SEGUROS DE MADRID, S.L.CORREDURÍA DE SEGUROS DE MADRID, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company linked the complainant’s bank account to insurance policies they had not taken out, resulting in unauthorized charges. | ES | AEPD | GDPR | €10,000 | ↗ |
| 29 Dec 2023 | CORPORACIÓN DUAL GRUPO LC, S.L.CORPORACIÓN DUAL GRUPO LC, S.L. was fined €500 by the AEPD for failing to provide access to personal data and information requested by the data protection authority. The case concerns non-compliance with GDPR obligations, including Article 58(1). | ES | AEPD | GDPR | €500 | ↗ |
| 26 Apr 2022 | CORPORACIÓN DE RADIO Y TELEVISIÓN ESPAÑOLA S.A.The company published audio of a victim's court statement in a high-profile case. The authority found a breach of the data minimization principle because excessive personal data was processed. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2019 | CORPORACION DE RADIO Y TELEVISION ESPAÑOLA SACORPORACION DE RADIO Y TELEVISION ESPAÑOLA SA was fined by the AEPD for a security incident involving the loss of unencrypted USB drives containing personal data. The authority found a breach of Article 32 GDPR on appropriate technical and organisational security measures. | ES | AEPD | GDPR | €60,000 | ↗ |
| 11 Apr 2023 | CORPORACION DE MEDIOS DE EXTREMADURA, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. The authority found a breach of the data minimization principle and imposed a 150,000 EUR fine. | ES | AEPD | GDPR | €150,000 | ↗ |
| 04 Feb 2022 | CORON ISLAND SLUCORON ISLAND SLU was fined by the AEPD 2,000 EUR for requiring a customer’s phone number when issuing an invoice. The authority found that the data was not necessary for invoicing, which breached the data minimization principle. | ES | AEPD | GDPR | €2,000 | ↗ |
| 30 May 2024 | Corint Logistic SRLCorint Logistic SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 30 May 2024 | Corint Logistic SRLCorint Logistic SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 26 Jun 2014 | CO.RE.MA. di Gian Luigi Morando & C. s.a.s.CO.RE.MA. was fined by the Garante EUR 12,000 for using an integrated video surveillance system that allowed viewing images from workplaces. Required safeguards were not implemented, including logical separation of recordings from different data controllers. | IT | Garante | GDPR | €12,000 | ↗ |
| 14 Oct 2025 | CORAL TRAVEL & TOURISM SERVICES S.R.L.The operator was fined for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €982 | ↗ |
| 27 Oct 2022 | COPY COFFEE, S.L.COPY COFFEE, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails despite the recipient's prior objection. The authority found a breach of Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 26 Mar 2026 | Copacabana s.r.l.Copacabana s.r.l. was fined EUR 2,000 by the Garante for installing a video surveillance system without the required informational signage and necessary authorization. The authority cited a breach of GDPR Article 13. | IT | Garante | GDPR | €2,000 | ↗ |
| 22 Feb 2024 | Coop Italia Società CooperativaCoop Italia Società Cooperativa was fined by the Garante 90,000 EUR for unlawfully processing personal data for marketing purposes without proper consent. The authority found a breach of GDPR principles, including Article 5. | IT | Garante | GDPR | €90,000 | ↗ |
| 14 Jan 2021 | Coop Finnmark SAThe Norwegian DPA fined Coop Finnmark SA 400,000 NOK for unlawfully sharing a surveillance video from a store. The store manager recorded the footage with a mobile phone and shared it without a legal basis, breaching GDPR principles. | NO | Datatilsynet | GDPR | €38,796 | ↗ |
| 01 Jun 2023 | Cooperjob S.p.A.Cooperjob S.p.A. was fined EUR 20,000 by the Garante for failing to respond within the required timeframe to a job applicant’s request to delete personal data. The authority found a breach of GDPR Article 12 on timely handling of data subject requests. | IT | Garante | GDPR | €20,000 | ↗ |