Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Apr 2022CÍTRICOS TANTA, S.L.CÍTRICOS TANTA, S.L. was fined by the AEPD for processing personal data without consent. The case involved registering an individual in the Social Security system without their knowledge or agreement.ESAEPDGDPR€5,000
31 May 2012CITIBANK ESPAÑA, S.A.CITIBANK ESPAÑA, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails despite a prior request to be removed from its mailing list. The conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,001
04 May 2015CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank. The case concerned the bank’s failure to satisfy the complainant’s right of access to personal data.GRHDPAGDPR€8,000
04 May 2015CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank for unlawful processing of the complainant’s creditworthiness data. The case concerned a breach of the rules governing lawful processing of personal data.GRHDPAGDPR€8,000
09 Oct 2014CISPEL Lombardia Services s.r.l.CISPEL Lombardia Services s.r.l. was fined by the Garante for failing to provide the required data protection information to job applicants. The authority also found that personal data was shared with third parties without the data subjects' consent.ITGaranteGDPR€16,000
01 Oct 2013CIRCULO GACELA S.L.U.CIRCULO GACELA S.L.U. was fined by the AEPD EUR 1,800 for sending unsolicited commercial emails without prior consent. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,800
11 Feb 2016Circolo ricreativo D.D. PeckerCircolo ricreativo D.D. Pecker was fined by the Garante for providing inadequate information to data subjects about the processing of their personal data. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
09 Dec 2010Circolo Privato PirliCircolo Privato Pirli was fined EUR 6,000 by the Garante for failing to provide the required privacy notice to individuals entering the premises. The breach concerned the Italian Data Protection Code and the Garante's video surveillance guidelines.ITGaranteGDPR€6,000
29 May 2008Circolo privato 'Astoria'The private club “Astoria” was fined 3,000 EUR by the Garante for failing to provide the required data protection notice to individuals identified through its video surveillance system. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
27 Jan 2022Circolo culturale “Ruian”Circolo culturale “Ruian” was fined EUR 2,000 by the Garante for operating a video surveillance system in breach of data protection rules. The cameras were not properly signposted, which failed to meet the required information obligations toward monitored individuals.ITGaranteGDPR€2,000
11 Mar 2022CINCON S.C.CINCON S.C. was fined EUR 500 by the AEPD for failing to provide adequate information about the retention period of personal data collected through a website form. The authority found a breach of Article 13 GDPR because data subjects were not given the required notice.ESAEPDGDPR€500
16 Mar 2017Cigno d’Argento s.r.l.Cigno d’Argento s.r.l. was fined by the Garante 36,000 EUR for data protection violations. The case concerned the improper use of video surveillance systems without the required authorization.ITGaranteGDPR€36,000
26 Feb 2026Ciemme S.r.l.sThe Italian Data Protection Authority fined Ciemme S.r.l.s EUR 1,000 for failing to respond to a data subject request to exercise rights of access, erasure, and objection. The case arose after unsolicited marketing calls.ITGaranteGDPR€1,000
24 Apr 2024C.I.EL. S.p.A.C.I.EL. S.p.A. was fined 10,000 EUR by the Garante following a complaint from a former employee. The case concerned violations related to the right of access to training certificates.ITGaranteGDPR€10,000
26 Sept 2024CI & DI Food s.r.l.CI & DI Food s.r.l. was fined by the Garante 4,000 EUR for failing to respond to an employee’s request to access personal data related to employment. The request included work attendance records.ITGaranteGDPR€4,000
20 Mar 2008Cid-Centro informazioni didatticoCid-Centro informazioni didattico was fined 3,000 EUR by the Garante for sending advertising material by fax without providing prior and adequate information to recipients. The conduct breached data protection rules.ITGaranteGDPR€3,000
01 Jan 2024CIBERSEO JAÉN, S.L.CIBERSEO JAÉN, S.L. was fined EUR 1,500 by the AEPD for publishing a photograph of an individual without consent on a job search website. The case concerned processing personal data without a lawful basis, contrary to Article 6 of the GDPR.ESAEPDGDPR€1,500
08 Jan 2015CHRYSOS ODIGOS ENTYPH & HLEKTRONIKI PLHROFORISI A.E.The company was fined by the HDPA EUR 10,000 for processing personal data without consent. The authority also found that it failed to respond to data subjects' requests for access and objection.GRHDPAGDPR€10,000
12 May 2023CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed a fine of EUR 4,500 on CHIRURGIEN DENTISTE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€4,500
17 Oct 2024CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on CHIRURGIEN DENTISTE under a simplified procedure. The authority also issued an injunction, indicating that remedial action is required.FRCNILGDPR€3,000