BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2024 | COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company was fined EUR 80,000 by the AEPD for processing a gas contract without the complainant's consent. It used personal data without authorization, which constitutes a breach of data protection law. | ES | AEPD | GDPR | €80,000 | ↗ |
| 08 Jul 2024 | COMERCIAL GIRONA DE LLIBRES, S.L.COMERCIAL GIRONA DE LLIBRES, S.L. was fined by the AEPD 20,000 EUR for inadequate security measures. The authority cited, among other issues, the sending of credentials by email, which breached Article 32 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 11 Feb 2021 | Comando generale del Corpo delle Capitanerie di porto-Guardia CostieraThe Garante imposed a €5,000 fine on the Comando generale del Corpo delle Capitanerie di porto-Guardia Costiera for inadequate data protection measures. The breach resulted in the unlawful disclosure of personal data on its website. | IT | Garante | GDPR | €5,000 | ↗ |
| 15 Apr 2025 | COLPER BUSINESS 2020 S.L.COLPER BUSINESS 2020 S.L. was fined by the AEPD EUR 20,000 for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 05 Aug 2022 | Colosseo S.r.l.Colosseo S.r.l. was fined EUR 1,000 by the Garante for sending unsolicited promotional emails without prior recipient consent. The authority found this breached GDPR rules on lawful processing and consent. | IT | Garante | GDPR | €1,000 | ↗ |
| 22 May 2014 | Colligo s.r.lColligo s.r.l was fined EUR 40,000 by the Garante for making promotional phone calls while disguising or hiding the caller's identity. The authority found this conduct breached the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Nov 2015 | Collegio professionale dei periti industriali di Roma e provinciaCollegio professionale dei periti industriali di Roma e provincia was fined 10,000 EUR by the Garante for unlawfully publishing judicial data on its website. The publication occurred during an election campaign. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Nov 2025 | COLLECTIVITE TERRITORIALE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on COLLECTIVITE TERRITORIALE under a simplified procedure. The decision concerns a breach of data protection rules. | FR | CNIL | GDPR | €4,000 | ↗ |
| 13 Sept 2017 | Coleman s.p.a.Coleman s.p.a. was fined by the Garante 20,000 EUR for failing to implement minimum security measures for online booking requests. This allowed access to personal data without authentication. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Jun 2023 | COLEGIO VIRGEN DE EUROPA, S.L.The school processed and published images of a 3-year-old child on Facebook and WhatsApp without parental consent. This disregarded the parents’ explicit refusal and led to a fine imposed by the AEPD. | ES | AEPD | GDPR | €15,000 | ↗ |
| 29 Jan 2022 | COLEGIO VILLAEUROPA, S.C.L.The school was fined by the AEPD in the amount of 5,000 EUR for recording a child's image without parental consent. The authority also found that the school failed to provide adequate information about personal data processing. | ES | AEPD | GDPR | €5,000 | ↗ |
| 10 Apr 2023 | COLEGIO OFICIAL DE ARQUITECTOS DE GRANADACOLEGIO OFICIAL DE ARQUITECTOS DE GRANADA was fined €14,000 by the AEPD for data protection breaches. The authority found a conflict of interest in the appointment of the Data Protection Officer, missing required information on data processing in complaint forms, and the use of third-party cookies without user consent. | ES | AEPD | ePrivacy | €14,000 | ↗ |
| 16 May 2023 | COLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRECOLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRE was fined by the AEPD for failing to implement appropriate technical and organizational measures to ensure data security. The deficiency resulted in a breach involving minors’ data stored in cloud services. | ES | AEPD | GDPR | €5,000 | ↗ |
| 30 Oct 2024 | COLEGIO NOTARIAL DE ARAGÓNCOLEGIO NOTARIAL DE ARAGÓN was fined by the AEPD for implementing a fingerprint-based time control system without carrying out a data protection impact assessment. The authority found breaches of GDPR Articles 9 and 35. | ES | AEPD | GDPR | €10,000 | ↗ |
| 29 Jan 2020 | COLEGIO ARENALES CARABANCHELThe school was fined by the AEPD 5,000 EUR for unlawfully sharing and publishing images of children without consent. The case involved a breach of data protection rules and the need for valid consent to process minors’ images. | ES | AEPD | GDPR | €5,000 | ↗ |
| 26 Sept 2023 | COLEGIO ALONAI, S.L.COLEGIO ALONAI, S.L. was fined by the AEPD 5,000 EUR for installing surveillance cameras inside classrooms and outside the school without properly informing employees. The authority also found inadequate signage, constituting a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 27 Oct 2016 | Coledan EmanuelaColedan Emanuela was fined EUR 2,400 by the Garante for failing to inform data subjects about the processing of personal data through a video surveillance system at a private club. The case concerns a breach of transparency and information obligations toward individuals under surveillance. | IT | Garante | GDPR | €2,400 | ↗ |
| 25 Feb 2016 | COF Lanzo Hospital SpaCOF Lanzo Hospital Spa was fined by the Garante for failing to respond to an information request concerning the handling of patient medical records. The authority found a breach of Article 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Nov 2025 | COFIDIS S.A., SUCURSAL EN ESPAÑACOFIDIS S.A., Sucursal en España was fined €5,000 by the AEPD for mixing a complainant’s personal data with unrelated information and sending a third party’s debt statement. The case concerns a breach of the data accuracy principle. | ES | AEPD | GDPR | €5,000 | ↗ |
| 10 Nov 2011 | C.O.E.STRA. S.p.A.C.O.E.STRA. S.p.A. was fined EUR 30,000 by the Italian data protection authority, Garante. The sanction concerned the failure to appoint data processing officers, which breached the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |