Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Oct 2022Codess Sociale, Soc. Coop. socialeCodess Sociale, Soc. Coop. sociale was fined EUR 10,000 by the Garante. The authority found that the company failed to respond to a data subject's request to exercise GDPR rights.ITGaranteGDPR€10,000
15 Aug 2024Coastal Windows & Conservatories (UK) LimitedCoastal Windows & Conservatories (UK) Limited made more than 18,000 unsolicited marketing calls between 1 January and 1 June 2023 to numbers registered with the TPS. The ICO and TPS received numerous complaints from people who said they had not consented to the calls or continued to receive them after asking for the calls to stop.GBICOGDPR€46,720
01 Jan 2023CLUB VOLEIBOL ***CLUB.1The club was fined by the AEPD in the amount of EUR 500 for publishing minors' images without proper consent. The authority also found that the club failed to provide access to personal data requested by a parent.ESAEPDGDPR€500
19 Dec 2024CLUB RÁPIDO DE BOUZASThe club was fined by the AEPD for leaving documents containing players’ personal data, including minors’ data, in a public trash container. The authority found this breached data protection principles, especially confidentiality and security.ESAEPDGDPR€1,000
07 Jun 2021CLUB NÁUTICO EL ESTACIOThe entity published personal data on its website without access restrictions. This breached confidentiality and data security principles.ESAEPDGDPR€3,000
01 Mar 2022CLUB NATACIO LLEIDACLUB NATACIO LLEIDA installed a surveillance camera in a rented bar/restaurant without informing the tenant or displaying the required signage. The AEPD found this to be a breach of data protection rules.ESAEPDGDPR€1,200
04 May 2021CLUB GIMNASIA RÍTMICA SAN ANTONIOThe club was fined by the AEPD for publishing images of minors on social media without proper consent. The authority found a breach of GDPR Article 6 on lawful processing.ESAEPDGDPR€5,000
19 Nov 2024CLUB ESPORTIU VILA OLÍMPICAThe club pressured a parent to obtain consent for collecting images of a minor child. AEPD found this to be a breach of data protection rules.ESAEPDGDPR€1,000
01 Jan 2021CLUB DEPORTIVO RITMO DE ANDALUCÍAThe club was fined by the AEPD 4,000 EUR for failing to adequately inform users about the processing of their personal data. The authority also found that users were not given the opportunity to provide free and voluntary consent for each specific processing purpose.ESAEPDGDPR€4,000
17 Feb 2025CLUB DE GOLF VILLA DE CUÉLLARCLUB DE GOLF VILLA DE CUÉLLAR was fined by the AEPD EUR 400 for failing to inform an employee about the installation and operation of surveillance cameras. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€400
07 Jun 2024Club Balonmano GijónClub Balonmano Gijón was fined EUR 1,000 by the AEPD for unlawfully processing personal data by publishing images of minors on its website without a legal basis. The case indicates a breach of the lawfulness principle and the protection of children's image rights.ESAEPDGDPR€1,000
22 Nov 2024CLUB BALONCESTO TELDEClub Baloncesto Telde was fined for publishing images of a minor on social media without obtaining the required consent. The authority found a breach of Article 6(1) of the GDPR.ESAEPDGDPR€1,000
01 Jan 2026CloudflareAGCOM issued an ordinanza ingiunzione against Cloudflare under the Digital Services Act. The fine is 100,000 EUR and relates to a breach of DSA obligations.ITAGCOMDSA€100,000
26 Jul 2017Cloud Europa s.r.l.Cloud Europa s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unsolicited promotional phone calls, in breach of data protection rules.ITGaranteGDPR€40,000
21 Jul 2022Clio s.r.l.Clio s.r.l. was fined by the Italian Garante in the amount of 10,000 EUR for violations related to personal data processing. The case involved inadequate protection of whistleblower identities, in breach of the GDPR and national privacy code provisions.ITGaranteGDPR€10,000
25 May 2022CLINT IS GOOD DIGITAL CREATIVE TEAM, S.L.CLINT IS GOOD DIGITAL CREATIVE TEAM, S.L. was fined 500 EUR by the AEPD. The case concerned sending unsolicited commercial communications by email without consent, in breach of Article 21 of the LSSI.ESAEPDePrivacy€500
05 Dec 2024CLINIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on CLINIQUE (procédure simplifiée). The case concerns a regulatory breach that resulted in an administrative sanction.FRCNILGDPR€15,000
10 Jul 2014Clinica Siligato s.r.l.Clinica Siligato s.r.l. was fined for failing to notify the Garante of certain processing activities involving health data. The case concerned data used to detect infectious diseases and HIV status, which had to be reported under the Italian Data Protection Code.ITGaranteGDPR€8,000
30 Oct 2023CLÍNICA PARÍS, S.L.CLÍNICA PARÍS, S.L. was fined 1,000 EUR by the AEPD for failing to properly handle a data subject access request. The authority found a breach of GDPR obligations.ESAEPDGDPR€1,000
15 Oct 2010Clinica Luccioni S.p.a.Clinica Luccioni S.p.a. was fined by the Garante for failing to timely notify the authority of personal data processing activities required under the Italian Data Protection Code. The case concerned a breach of the notification obligation to the supervisory authority.ITGaranteGDPR€10,000