Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Sept 2016CEPSA COMERCIAL PETROLEO, S.A.U.CEPSA COMERCIAL PETROLEO, S.A.U. was fined EUR 4,100 by the AEPD for sending commercial emails to a customer after the customer had requested to unsubscribe. The authority found this to be a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€4,100
25 Oct 2016CEPSA COMERCIAL PETROLEO, SAUCEPSA COMERCIAL PETROLEO, SAU was fined by the AEPD in the amount of 5,700 EUR. The sanction concerned the sending of unauthorized commercial emails in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€5,700
08 May 2024CENTRUL MEDICAL UNIREA SRLCENTRUL MEDICAL UNIREA SRL was fined EUR 5,000 by ANSPDCP for unauthorized disclosure of personal data on the internet. The case indicates a breach of data protection rules and warrants review of security controls and publication procedures.ROANSPDCPGDPR€5,000
13 Jan 2025Centrul Medical Unirea S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation at Centrul Medical Unirea S.R.L. and found a breach of Article 32 of the GDPR. A fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
12 Apr 2024Centrul Medical dr. Furtună DanThe National Supervisory Authority for Personal Data Processing imposed a fine on Centrul Medical dr. Furtună Dan for breaching Article 6 of the GDPR. The infringement concerned the absence of a proper legal basis for personal data processing.ROANSPDCPGDPR€1,500
12 Jan 2017Centro Studi Raffaello s.r.l.Centro Studi Raffaello s.r.l. was fined by the Garante for inadequate data protection measures and improper collection of consent for marketing purposes. The case indicates deficiencies in the company's personal data processing controls and compliance framework.ITGaranteGDPR€20,000
25 Oct 2016CENTROS COMERCIALES CARREFOUR, S.A.CENTROS COMERCIALES CARREFOUR, S.A. was fined EUR 7,000 by the AEPD for sending unsolicited commercial emails. The authority also found that the company failed to provide a proper opt-out mechanism, breaching Article 21 of the LSSI.ESAEPDePrivacy€7,000
01 Mar 2017CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD €10,000 for sending commercial emails without a valid unsubscribe link. The case concerned non-compliance with electronic communications rules and recipients’ right to opt out easily.ESAEPDePrivacy€10,000
01 Jan 2016CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD for sending unsolicited advertising emails. The authority also found that the company did not provide an easy opt-out mechanism, in breach of Article 21 of the LSSI.ESAEPDePrivacy€7,000
01 Jan 2015CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD in the amount of EUR 3,300. The authority found that the company sent unsolicited advertising emails and failed to properly handle unsubscribe requests, in breach of Article 21 of the LSSI.ESAEPDePrivacy€3,300
07 Mar 2024Centro Riparazioni Piacentino S.p.A.Centro Riparazioni Piacentino S.p.A. was fined by the Garante for continuing to operate individual company accounts months after employment ended and for accessing messages without proper deletion. The authority also found inadequate information and insufficient access rights for former employees.ITGaranteGDPR€20,000
20 Nov 2014Centro Nautico Tirreno s.r.l.Centro Nautico Tirreno s.r.l. was fined by the Garante 2,400 EUR for failing to provide the required privacy notice when collecting personal data through a web form. The authority found that individuals were not properly informed before their data was collected.ITGaranteGDPR€2,400
28 Mar 2022CENTRO MÉDICO SALUS BALEARES, S.L.CENTRO MÉDICO SALUS BALEARES, S.L. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned displaying patients’ body temperatures in a way that could be seen by unauthorized third parties, which compromised confidentiality.ESAEPDGDPR€30,000
24 Jan 2026CENTRO MÉDICO REY FERNANDO, S.L.P.The entity charged a fee for providing a patient with their medical history, which breached the right of access under GDPR Article 12. The AEPD imposed a fine of 1,000 EUR.ESAEPDGDPR€1,000
10 Jul 2025Centro Medico Italiano S.r.l.Centro Medico Italiano S.r.l. was fined by the Garante 30,000 EUR for failing to provide an adequate response to a data subject’s request for access to health data and information about its processing. The authority found a breach of GDPR Article 15.ITGaranteGDPR€30,000
20 Jul 2017Centro Laser s.r.l.Centro Laser s.r.l. was fined EUR 20,400 by the Garante for using inadequate password procedures and failing to provide required information on data processing to users. The case concerns breaches of data protection rules.ITGaranteGDPR€20,400
02 Jul 2020CENTRO INTERNACIONAL DE CRECIMIENTO LABORAL Y PROFESIONAL, S.L.The entity sent unsolicited commercial emails without the recipients’ consent. It also failed to provide a valid unsubscribe option, which breached the LSSI.ESAEPDePrivacy€1,000
16 Dec 2021Centro di Medicina preventiva s.r.l.Centro di Medicina preventiva s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate measures to prevent unauthorized access to personal data. The deficiency resulted in a data breach.ITGaranteGDPR€10,000
11 Dec 2008Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c.Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c. was fined for failing to notify the Garante of personal data processing activities within the required timeframe. The case concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
25 Mar 2021Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules.ITGaranteGDPR€50,000