Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Mar 2022CLÍNICA DENTAL SAN FRANCISCO, S.L.The entity continued sending advertising messages to a former patient despite multiple requests to unsubscribe. AEPD found this to be a breach of data protection rules and imposed a EUR 7,000 fine.ESAEPDePrivacy€7,000
12 Jul 2024CLIDEA DESARROLLO, S.A.CLIDEA DESARROLLO, S.A. was fined by the AEPD 3,000 EUR for sending an email to 349 recipients without using the BCC field. This exposed the personal email addresses of all recipients.ESAEPDGDPR€3,000
03 Sept 2024Clearview AI Inc.Clearview AI Inc. was fined by the Dutch data protection authority AP for processing personal data without a legal basis, including biometric data. The authority also cited inadequate notice to data subjects, failure to respond to access requests, and failure to appoint an EU representative.NLAPGDPR€30,500,000
15 Apr 2021Clear Channel Italia S.p.A.Clear Channel Italia S.p.A. was fined by the Garante EUR 75,000 for conducting intrusive checks on employees’ devices without a proper legal basis. The authority found breaches of data minimization and proportionality principles.ITGaranteGDPR€75,000
24 Oct 2013Claudio ContiClaudio Conti was fined EUR 26,000 by the Garante for activating 100 phone cards in the name of an unaware third party. Required information was not provided and consent was not obtained, constituting a data protection breach.ITGaranteGDPR€26,000
13 Feb 2025Claudio BattagliaDr. Claudio Battaglia, an oncologist, was fined for using patient data for electoral propaganda without consent. The case indicates a breach of GDPR principles on lawfulness and purpose limitation.ITGaranteGDPR€10,000
30 Oct 2015CLASE EJECUTIVA, S.L.CLASE EJECUTIVA, S.L. was fined by the AEPD EUR 400 for sending commercial emails without prior consent from recipients. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€400
06 Apr 2017CLARIMARKET S.L.CLARIMARKET S.L. was fined EUR 600 by the AEPD. The sanction concerned sending unsolicited commercial emails in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
12 May 2022CivilstyrelsenThe Danish DPA reported Civilstyrelsen to the police and recommended a fine for failing to implement appropriate security measures and for not reporting a data breach. The case ended with a fine notice of 100,000 DKK.DKDatatilsynetGDPR€13,439
22 Oct 2013CIVESA 2005 SERVICIOS S LCIVESA 2005 SERVICIOS S L was fined EUR 600 by the AEPD for sending commercial emails to a user who had previously opted out. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€600
12 May 2022CIUDAUTO, S.L.CIUDAUTO, S.L. was fined by the AEPD EUR 1,000 for continuing to send advertising emails despite a request to unsubscribe. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,000
01 Jan 2023CIUDAD RESIDENCIAL H.H.H.CIUDAD RESIDENCIAL H.H.H. was fined by the AEPD EUR 2,000 for breaching the data minimization principle. The case concerned capturing and storing photographs of residents collecting packages without informing them about this processing.ESAEPDGDPR€2,000
29 Sept 2022CITY OF SOUND 2010, S.L.CITY OF SOUND 2010, S.L. was fined EUR 800 by the AEPD for sending at least one commercial SMS to the complainant after the complainant had requested removal from the database. The authority found this to be a breach of Article 21 of the LSSI on unsolicited marketing communications.ESAEPDePrivacy€800
23 Jun 2025City of Dublin Education and Training Board (CDETB)The Irish supervisory authority concluded an inquiry into City of Dublin Education and Training Board (CDETB) and found GDPR infringements linked to a personal data breach. It imposed administrative fines totaling EUR 125,000 and issued a reprimand on 23 June 2025.IEData Protection Commission (Ireland)GDPR€125,000
23 Jun 2025City of Dublin Education and Training Board (CDETB)The Irish DPC imposed a fine of EUR 125,000 on City of Dublin Education and Training Board (CDETB) in inquiry IN-19-7-3. The fine status is collected.IEDPCGDPR€125,000
13 Apr 2023Citynews S.p.A.Citynews S.p.A. was fined EUR 15,000 by the Italian data protection authority, Garante. The case concerned the publication of detailed health information about an individual without consent, in breach of GDPR Article 9 on special categories of personal data.ITGaranteGDPR€15,000
07 Apr 2016CityFan s.r.l.CityFan s.r.l. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned the failure to formally designate employees and collaborators as data processors under Article 33 of the Italian Data Protection Code.ITGaranteGDPR€4,000
26 Sept 2024Città metropolitana di TorinoCittà metropolitana di Torino was fined by the Garante 50,000 EUR for publishing personal data on its institutional website about individuals fined by voluntary ecological guards. The disclosure included names and contact details, breaching data protection rules.ITGaranteGDPR€50,000
29 Oct 2020Città Metropolitana di NapoliCittà Metropolitana di Napoli was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found that a disciplinary document was not marked as confidential, which allowed unauthorized access within the administration.ITGaranteGDPR€8,000
19 Feb 2020CITRICOS Y FRUTALES DEL SURESTE, S.L.CITRICOS Y FRUTALES DEL SURESTE, S.L. was fined by the AEPD 3,000 EUR for installing video surveillance in common areas without approval from the property owners' association and without obtaining explicit consent from affected individuals. The authority found breaches of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€3,000