BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Sept 2016 | CEPSA COMERCIAL PETROLEO, S.A.U.CEPSA COMERCIAL PETROLEO, S.A.U. was fined EUR 4,100 by the AEPD for sending commercial emails to a customer after the customer had requested to unsubscribe. The authority found this to be a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €4,100 | ↗ |
| 25 Oct 2016 | CEPSA COMERCIAL PETROLEO, SAUCEPSA COMERCIAL PETROLEO, SAU was fined by the AEPD in the amount of 5,700 EUR. The sanction concerned the sending of unauthorized commercial emails in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €5,700 | ↗ |
| 08 May 2024 | CENTRUL MEDICAL UNIREA SRLCENTRUL MEDICAL UNIREA SRL was fined EUR 5,000 by ANSPDCP for unauthorized disclosure of personal data on the internet. The case indicates a breach of data protection rules and warrants review of security controls and publication procedures. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 13 Jan 2025 | Centrul Medical Unirea S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation at Centrul Medical Unirea S.R.L. and found a breach of Article 32 of the GDPR. A fine of EUR 2,000 was imposed. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 12 Apr 2024 | Centrul Medical dr. Furtună DanThe National Supervisory Authority for Personal Data Processing imposed a fine on Centrul Medical dr. Furtună Dan for breaching Article 6 of the GDPR. The infringement concerned the absence of a proper legal basis for personal data processing. | RO | ANSPDCP | GDPR | €1,500 | ↗ |
| 12 Jan 2017 | Centro Studi Raffaello s.r.l.Centro Studi Raffaello s.r.l. was fined by the Garante for inadequate data protection measures and improper collection of consent for marketing purposes. The case indicates deficiencies in the company's personal data processing controls and compliance framework. | IT | Garante | GDPR | €20,000 | ↗ |
| 25 Oct 2016 | CENTROS COMERCIALES CARREFOUR, S.A.CENTROS COMERCIALES CARREFOUR, S.A. was fined EUR 7,000 by the AEPD for sending unsolicited commercial emails. The authority also found that the company failed to provide a proper opt-out mechanism, breaching Article 21 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 01 Mar 2017 | CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD €10,000 for sending commercial emails without a valid unsubscribe link. The case concerned non-compliance with electronic communications rules and recipients’ right to opt out easily. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 01 Jan 2016 | CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD for sending unsolicited advertising emails. The authority also found that the company did not provide an easy opt-out mechanism, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 01 Jan 2015 | CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD in the amount of EUR 3,300. The authority found that the company sent unsolicited advertising emails and failed to properly handle unsubscribe requests, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 07 Mar 2024 | Centro Riparazioni Piacentino S.p.A.Centro Riparazioni Piacentino S.p.A. was fined by the Garante for continuing to operate individual company accounts months after employment ended and for accessing messages without proper deletion. The authority also found inadequate information and insufficient access rights for former employees. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Nov 2014 | Centro Nautico Tirreno s.r.l.Centro Nautico Tirreno s.r.l. was fined by the Garante 2,400 EUR for failing to provide the required privacy notice when collecting personal data through a web form. The authority found that individuals were not properly informed before their data was collected. | IT | Garante | GDPR | €2,400 | ↗ |
| 28 Mar 2022 | CENTRO MÉDICO SALUS BALEARES, S.L.CENTRO MÉDICO SALUS BALEARES, S.L. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned displaying patients’ body temperatures in a way that could be seen by unauthorized third parties, which compromised confidentiality. | ES | AEPD | GDPR | €30,000 | ↗ |
| 24 Jan 2026 | CENTRO MÉDICO REY FERNANDO, S.L.P.The entity charged a fee for providing a patient with their medical history, which breached the right of access under GDPR Article 12. The AEPD imposed a fine of 1,000 EUR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 10 Jul 2025 | Centro Medico Italiano S.r.l.Centro Medico Italiano S.r.l. was fined by the Garante 30,000 EUR for failing to provide an adequate response to a data subject’s request for access to health data and information about its processing. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €30,000 | ↗ |
| 20 Jul 2017 | Centro Laser s.r.l.Centro Laser s.r.l. was fined EUR 20,400 by the Garante for using inadequate password procedures and failing to provide required information on data processing to users. The case concerns breaches of data protection rules. | IT | Garante | GDPR | €20,400 | ↗ |
| 02 Jul 2020 | CENTRO INTERNACIONAL DE CRECIMIENTO LABORAL Y PROFESIONAL, S.L.The entity sent unsolicited commercial emails without the recipients’ consent. It also failed to provide a valid unsubscribe option, which breached the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 16 Dec 2021 | Centro di Medicina preventiva s.r.l.Centro di Medicina preventiva s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate measures to prevent unauthorized access to personal data. The deficiency resulted in a data breach. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Dec 2008 | Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c.Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c. was fined for failing to notify the Garante of personal data processing activities within the required timeframe. The case concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Mar 2021 | Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules. | IT | Garante | GDPR | €50,000 | ↗ |