Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Oct 2024CONSULTORIA INTEGRAL DE ENERGÍA ECOLÓGICA, S.L.The company was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited advertising messages to a complainant. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
29 May 2008Consulting S.p.A.Consulting S.p.A. was fined for collecting personal data through its website without providing adequate prior information. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
02 Dec 2019CONSULTING DE SEGURIDAD E INVESTIGACION MIRA DP MADRID, S.L.The company was fined by the AEPD for collecting and processing personal data without the data subjects’ consent. The conduct also included sending unsolicited advertising, which breached Article 6 of the GDPR.ESAEPDGDPR€5,000
17 Sept 2024Constanța South Container Terminal SRLConstanța South Container Terminal SRL was fined by ANSPDCP EUR 3,000 after a third party gained unauthorized access to employees’ personal data. The breach resulted from inadequate security measures on a publicly accessible file management platform.ROANSPDCPGDPR€3,000
16 Feb 2017Consorzio unico di bacino per le Province di Napoli e CasertaConsorzio unico di bacino for the Provinces of Naples and Caserta was fined EUR 20,000 by the Garante. The authority found that the employer processed employees' biometric data, including fingerprints, for attendance tracking without a proper legal basis.ITGaranteGDPR€20,000
18 Apr 2018Consorzio “Marte Euroservice”Consorzio “Marte Euroservice” was fined EUR 30,000 by the Garante for sending promotional emails without recipients’ consent. The company also exposed email addresses to multiple recipients, creating an additional data protection breach.ITGaranteGDPR€30,000
09 Nov 2017Consorzio di Polizia locale Valle AgnoConsorzio di Polizia locale Valle Agno was fined EUR 10,400 by the Garante for deploying a mobile video surveillance system and a localization system on employee devices without the required information or prior notification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€10,400
16 Sept 2021Consorzio di Bonifica dell’OristaneseConsorzio di Bonifica dell’Oristanese was fined EUR 5,000 by the Garante for publishing a disciplinary measure on its website that included an employee’s health information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€5,000
09 Mar 2023Consorzio Concessioni Reti Gas S.c.a.r.l.The Garante fined Consorzio Concessioni Reti Gas S.c.a.r.l. EUR 2,000 for GDPR breaches linked to the improper handling of email accounts and the failure to provide data processing information after an internship ended. The case highlights deficiencies in information duties and access control over personal data.ITGaranteGDPR€2,000
01 Jan 2013CONSORCIO PARA LA INNOVACION Y FORMACION EMPRESARIAL S.L.L.The entity was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited commercial emails. This conduct breached Article 21 of the LSSI, which prohibits unwanted marketing communications.ESAEPDePrivacy€1,200
10 Jan 2013Consodata S.p.A.Consodata S.p.A. was fined by the Garante 400,000 EUR for violations linked to unsolicited telemarketing. The authority also found that the company failed to provide individuals with proper data protection information.ITGaranteGDPR€400,000
01 Jan 2013CONSIGNALIA, S.L.CONSIGNALIA, S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited promotional emails. The authority found that this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€600
08 Jul 2021Consiglio Regionale della Valle d’AostaConsiglio Regionale della Valle d’Aosta was fined EUR 1,000 by the Garante for failing to remove personal data from its website after a request. The authority found this to be a breach of data protection rights.ITGaranteGDPR€1,000
23 Mar 2023Consiglio Nazionale dell'Ordine degli Assistenti SocialiConsiglio Nazionale dell'Ordine degli Assistenti Sociali was fined EUR 3,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data during a recruitment process, including disclosure of information about a candidate's exclusion.ITGaranteGDPR€3,000
29 Apr 2026Consiglio Nazionale dei Periti Industriali e dei Periti Industriali LaureatiThe Consiglio Nazionale dei Periti Industriali e dei Periti Industriali Laureati was fined €3,000 by the Garante. The authority found that the organization failed to ensure transparency in data processing, breaching GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€3,000
27 Apr 2010Consiglio dell'ordine degli avvocati di Santa Maria Capua VetereConsiglio dell'ordine degli avvocati di Santa Maria Capua Vetere was fined by the Garante for using a biometric system to verify trainee lawyers' attendance without proper authorization. This constituted a breach of data protection rules.ITGaranteGDPR€10,000
26 Feb 2026Conservatorio “XX” di XXThe Garante fined Conservatorio “XX” di XX EUR 5,000 for processing personal data relating to criminal convictions without a valid legal basis. The authority found breaches of the GDPR and the national privacy code.ITGaranteGDPR€5,000
10 Nov 2022Conservatorio di Musica S. Cecilia di RomaThe Conservatorio di Musica S. Cecilia di Roma was fined €6,000 by the Garante. The authority found unlawful processing of personal data contained in an audio/video recording used in disciplinary proceedings against a student without a lawful basis.ITGaranteGDPR€6,000
18 Jan 2023CONSEJERÍA DE CULTURA DE LA RIOJACONSEJERÍA DE CULTURA DE LA RIOJA was fined for failing to implement corrective measures after the unauthorized recording and dissemination of surveillance footage from the Museo de La Rioja. The authority found a breach of Article 32 GDPR concerning appropriate security measures.ESAEPDGDPR€3,000
21 Sept 2020CONSEGURIDAD S.L.CONSEGURIDAD S.L. was fined 50,000 EUR by the AEPD for failing to appoint a Data Protection Officer. The authority found a breach of Article 37(1)(b) of the GDPR.ESAEPDGDPR€50,000