BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Sept 2006 | Centro diagnostico Helios s.n.c.Centro diagnostico Helios s.n.c. was fined for failing to notify the processing of sensitive health data, including HIV status and other medical conditions. The authority treated this as a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Jul 2020 | CENTRO DE INVESTIGACIÓN Y ESTUDIO PARA LA OBESIDAD, S.L.The entity unlawfully transferred personal data without consent, in breach of Article 6 of the GDPR. The case resulted in an administrative fine of 50,000 EUR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2019 | CENTRO DE ESTUDIOS DIRIGIDOS DELTA, S.L.The entity sent a document via WhatsApp containing personal data of three individuals without their consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2020 | CENTRO DE DIAGNÓSTICO ***LOCALIDAD.1, S.A.The entity was fined for breaching data confidentiality by improperly sharing medical information between different entities without consent. The case involved sensitive data processing and a lack of a valid legal basis for the disclosure. | ES | AEPD | GDPR | €10,000 | ↗ |
| 21 Jan 2010 | Centro Chirurgico s.r.l.Centro Chirurgico s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 6,000. The case concerned the collection of personal data through a website contact form without providing the required information notice to data subjects, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 23 Feb 2023 | Centric Health Ltd. (“Centric”)The Irish DPC imposed a fine of EUR 460,000 on Centric Health Ltd. in inquiry IN-21-2-4. The fine has been collected. | IE | DPC | GDPR | €460,000 | ↗ |
| 04 Jun 2015 | Centrex srlCentrex srl was fined by the Garante for conducting telemarketing activities without prior informed consent from individuals. The case involved promotional calls to numbers listed in the public opposition registry. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Jan 2012 | CENTRE DE REDISTRIBUCIO DE MERCADERIES, S.L.The entity was fined by the AEPD for sending unsolicited commercial emails without prior recipient consent. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €8,200 | ↗ |
| 16 Jan 2025 | CENTRE DE FORMATION A DISTANCE D'APPRENTIS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on CENTRE DE FORMATION A DISTANCE D'APPRENTIS and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 19 Dec 2024 | CENTRE D'APPEL (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on CENTRE D'APPEL under a simplified procedure. The case concerned a confirmed regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €20,000 | ↗ |
| 22 Nov 2019 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union CSI-CSIF was fined EUR 3,000 by the AEPD for publishing an electoral census list containing personal data, including DNI numbers, in a public WhatsApp group. The authority found this breached data protection principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 03 Feb 2025 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe labor union CSI-CSIF was fined EUR 4,000 by the AEPD for failing to adequately protect personal data during a voting process. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality. | ES | AEPD | GDPR | €4,000 | ↗ |
| 12 May 2023 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union sent an email containing personal data of election officials and representatives without their consent. AEPD found this to be a breach of data protection rules and imposed a 4,000 EUR fine. | ES | AEPD | GDPR | €4,000 | ↗ |
| 12 May 2011 | Centrale Palace HotelCentrale Palace Hotel was fined EUR 6,000 by the Garante. The violation concerned the failure to provide the required privacy notice for its video surveillance system, in breach of the Italian data protection code. | IT | Garante | GDPR | €6,000 | ↗ |
| 19 Jan 2011 | Center Gross Sicilia S.r.l.Center Gross Sicilia S.r.l. was fined EUR 9,000 by the Garante. The authority found that the required privacy notice was not provided for three external surveillance cameras, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 04 Mar 2021 | CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.CEDICO, a diagnostic imaging center, was fined EUR 30,000 by the AEPD. The authority found that the company unlawfully shared a patient's MRI report with a mutual insurance company, breaching data protection principles. | ES | AEPD | GDPR | €30,000 | ↗ |
| 06 Jul 2006 | Ced di Demartis CarloThe sole proprietorship Ced di Demartis Carlo was fined by the Garante for failing to notify the processing of personal data. This constituted a breach of Article 7 of Law 675/1996. | IT | Garante | GDPR | €5,164 | ↗ |
| 09 Aug 2022 | CDI Transport Intern și Internațional SRLThe company was fined for failing to provide requested information within the legal deadline. The authority treated this as a breach of GDPR requirements. | RO | ANSPDCP | GDPR | €7,000 | ↗ |
| 08 Jan 2021 | C.C.C.C.C.C. was fined EUR 2,000 by the AEPD. The authority found that the company failed to provide a written contract and did not inform the complainant about the processing of personal data, in breach of Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 21 Feb 2023 | C.C.C.The entity was fined by the AEPD in the amount of EUR 300 for installing a video surveillance system that captured public areas. This conduct breached data protection rules. | ES | AEPD | GDPR | €300 | ↗ |