BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 Jan 2024 | CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on CHIRURGIEN DENTISTE. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 29 Feb 2024 | CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on CHIRURGIEN DENTISTE under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision. | FR | CNIL | GDPR | €4,000 | ↗ |
| 08 Jul 2015 | Chirco MicheleChirco Michele was fined for processing personal data through a video surveillance system without providing the required information notice to the data subjects. This constituted a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 05 Jun 2023 | CHINA CENTER LLEIDACHINA CENTER LLEIDA was fined EUR 700 by the AEPD for failing to properly sign its video surveillance system and for not providing customers with required data protection information. The authority found a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €700 | ↗ |
| 07 Jan 2020 | CHENMING YE (BAZAR REAL)CHENMING YE (BAZAR REAL) was fined EUR 900 by the AEPD. The authority found that the required visible notice identifying the data controller was missing, which breached data protection rules. | ES | AEPD | GDPR | €900 | ↗ |
| 15 May 2013 | Chen JingChen Jing was fined by the Italian Garante in the amount of EUR 2,400 for providing inadequate information about a video surveillance system at Ottimoda S.a.s. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Sept 2013 | Cheng LiangxiaoCheng Liangxiao was fined by the Italian Garante for failing to provide the required privacy notice for a surveillance camera at his commercial premises. The breach concerned the absence of information on personal data processing for individuals captured by the camera. | IT | Garante | GDPR | €2,400 | ↗ |
| 27 Apr 2023 | Checcoro di Nigro FrancescoThe company was fined EUR 2,000 by the Italian data protection authority, Garante. The sanction concerned the use of surveillance cameras without appropriate informational signage, in breach of GDPR requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 26 Nov 2020 | Charly Mike s.r.l.Charly Mike s.r.l. was fined by the Garante EUR 3,000 for improper use of a video surveillance system at Hotel Olimpo. The system was used for continuous monitoring and remote viewing of employees, in breach of data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 01 Mar 2017 | CGPN, SARLCGPN, SARL was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails without prior consent. This conduct breached Spanish data protection rules. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 02 Oct 2023 | Cez Vânzare S.A.Cez Vânzare S.A. was fined by ANSPDCP EUR 1,000 for a data protection breach. The incident resulted in unauthorized disclosure or access to personal data, including names, correspondence addresses, and customer codes of both individuals and legal entities. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 10 Feb 2021 | CEYLLE SOLUTIONS & DEVELOPMENT S.L.CEYLLE SOLUTIONS & DEVELOPMENT S.L. was fined by the AEPD in the amount of 2,000 EUR for disclosing personal data in emails sent to commercial partners. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 May 2018 | Česká republika – Ministerstvo vnitraThe Ministry of the Interior was fined by UOOU for processing sensitive personal data, including DNA profiles, without explicit consent. The authority found this to be a breach of data protection law. | CZ | UOOU | GDPR | €25,487 | ↗ |
| 12 Apr 2023 | Česká republika – Ministerstvo vnitraThe Czech Ministry of Interior was fined CZK 975,000 by the UOOU for violations of personal data processing rules during COVID-19 measures. The authority found, among other issues, a failure to conduct data protection impact assessments and improper disclosure of processing purposes. | CZ | UOOU | GDPR | €41,633 | ↗ |
| 21 Jun 2016 | Česká republika – Ministerstvo školství, mládeže a tělovýchovyThe Czech Republic’s Ministry of Education, Youth and Sports was fined by the UOOU for processing sensitive personal data about students’ disabilities without a legal basis. The case indicates a breach of personal data protection rules and requires review of the lawful basis and data scope. | CZ | UOOU | GDPR | €7,390 | ↗ |
| 27 Nov 2020 | CERTIME, S.A.CERTIME, S.A. was fined by the AEPD in the amount of 5,000 EUR for processing personal data for a purpose different from the one originally specified. The authority found this to be a breach of Article 5(1)(b) GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 05 Nov 2019 | CERRAJERO ONLINE S.L.CERRAJERO ONLINE S.L. was fined EUR 1,500 by the AEPD for collecting personal data without providing the required information to data subjects. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 23 Oct 2019 | CERRAJERIA VERIN S.L.CERRAJERIA VERIN S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to data subjects. The authority found a breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 23 Oct 2019 | CERRAJERIA CARLOS RODRIGUEZ S.L.CERRAJERIA CARLOS RODRIGUEZ S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to the data subjects. The authority found a breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 19 Sept 2017 | CEPSA COMERCIAL PETRÓLEO, S.A.U.CEPSA was fined by the AEPD 3,300 EUR for sending two unsolicited commercial emails without prior consent from the recipients. The authority found this breached Article 21 of the LSSI on commercial communications. | ES | AEPD | ePrivacy | €3,300 | ↗ |