Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2024COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company was fined EUR 80,000 by the AEPD for processing a gas contract without the complainant's consent. It used personal data without authorization, which constitutes a breach of data protection law.ESAEPDGDPR€80,000
08 Jul 2024COMERCIAL GIRONA DE LLIBRES, S.L.COMERCIAL GIRONA DE LLIBRES, S.L. was fined by the AEPD 20,000 EUR for inadequate security measures. The authority cited, among other issues, the sending of credentials by email, which breached Article 32 of the GDPR.ESAEPDGDPR€20,000
11 Feb 2021Comando generale del Corpo delle Capitanerie di porto-Guardia CostieraThe Garante imposed a €5,000 fine on the Comando generale del Corpo delle Capitanerie di porto-Guardia Costiera for inadequate data protection measures. The breach resulted in the unlawful disclosure of personal data on its website.ITGaranteGDPR€5,000
15 Apr 2025COLPER BUSINESS 2020 S.L.COLPER BUSINESS 2020 S.L. was fined by the AEPD EUR 20,000 for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR.ESAEPDGDPR€20,000
05 Aug 2022Colosseo S.r.l.Colosseo S.r.l. was fined EUR 1,000 by the Garante for sending unsolicited promotional emails without prior recipient consent. The authority found this breached GDPR rules on lawful processing and consent.ITGaranteGDPR€1,000
22 May 2014Colligo s.r.lColligo s.r.l was fined EUR 40,000 by the Garante for making promotional phone calls while disguising or hiding the caller's identity. The authority found this conduct breached the Italian Data Protection Code.ITGaranteGDPR€40,000
18 Nov 2015Collegio professionale dei periti industriali di Roma e provinciaCollegio professionale dei periti industriali di Roma e provincia was fined 10,000 EUR by the Garante for unlawfully publishing judicial data on its website. The publication occurred during an election campaign.ITGaranteGDPR€10,000
04 Nov 2025COLLECTIVITE TERRITORIALE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on COLLECTIVITE TERRITORIALE under a simplified procedure. The decision concerns a breach of data protection rules.FRCNILGDPR€4,000
13 Sept 2017Coleman s.p.a.Coleman s.p.a. was fined by the Garante 20,000 EUR for failing to implement minimum security measures for online booking requests. This allowed access to personal data without authentication.ITGaranteGDPR€20,000
22 Jun 2023COLEGIO VIRGEN DE EUROPA, S.L.The school processed and published images of a 3-year-old child on Facebook and WhatsApp without parental consent. This disregarded the parents’ explicit refusal and led to a fine imposed by the AEPD.ESAEPDGDPR€15,000
29 Jan 2022COLEGIO VILLAEUROPA, S.C.L.The school was fined by the AEPD in the amount of 5,000 EUR for recording a child's image without parental consent. The authority also found that the school failed to provide adequate information about personal data processing.ESAEPDGDPR€5,000
10 Apr 2023COLEGIO OFICIAL DE ARQUITECTOS DE GRANADACOLEGIO OFICIAL DE ARQUITECTOS DE GRANADA was fined €14,000 by the AEPD for data protection breaches. The authority found a conflict of interest in the appointment of the Data Protection Officer, missing required information on data processing in complaint forms, and the use of third-party cookies without user consent.ESAEPDePrivacy€14,000
16 May 2023COLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRECOLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRE was fined by the AEPD for failing to implement appropriate technical and organizational measures to ensure data security. The deficiency resulted in a breach involving minors’ data stored in cloud services.ESAEPDGDPR€5,000
30 Oct 2024COLEGIO NOTARIAL DE ARAGÓNCOLEGIO NOTARIAL DE ARAGÓN was fined by the AEPD for implementing a fingerprint-based time control system without carrying out a data protection impact assessment. The authority found breaches of GDPR Articles 9 and 35.ESAEPDGDPR€10,000
29 Jan 2020COLEGIO ARENALES CARABANCHELThe school was fined by the AEPD 5,000 EUR for unlawfully sharing and publishing images of children without consent. The case involved a breach of data protection rules and the need for valid consent to process minors’ images.ESAEPDGDPR€5,000
26 Sept 2023COLEGIO ALONAI, S.L.COLEGIO ALONAI, S.L. was fined by the AEPD 5,000 EUR for installing surveillance cameras inside classrooms and outside the school without properly informing employees. The authority also found inadequate signage, constituting a breach of data protection rules.ESAEPDGDPR€5,000
27 Oct 2016Coledan EmanuelaColedan Emanuela was fined EUR 2,400 by the Garante for failing to inform data subjects about the processing of personal data through a video surveillance system at a private club. The case concerns a breach of transparency and information obligations toward individuals under surveillance.ITGaranteGDPR€2,400
25 Feb 2016COF Lanzo Hospital SpaCOF Lanzo Hospital Spa was fined by the Garante for failing to respond to an information request concerning the handling of patient medical records. The authority found a breach of Article 164 of the Italian Data Protection Code.ITGaranteGDPR€4,000
05 Nov 2025COFIDIS S.A., SUCURSAL EN ESPAÑACOFIDIS S.A., Sucursal en España was fined €5,000 by the AEPD for mixing a complainant’s personal data with unrelated information and sending a third party’s debt statement. The case concerns a breach of the data accuracy principle.ESAEPDGDPR€5,000
10 Nov 2011C.O.E.STRA. S.p.A.C.O.E.STRA. S.p.A. was fined EUR 30,000 by the Italian data protection authority, Garante. The sanction concerned the failure to appoint data processing officers, which breached the minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€30,000