Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Sept 2006Centro diagnostico Helios s.n.c.Centro diagnostico Helios s.n.c. was fined for failing to notify the processing of sensitive health data, including HIV status and other medical conditions. The authority treated this as a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
20 Jul 2020CENTRO DE INVESTIGACIÓN Y ESTUDIO PARA LA OBESIDAD, S.L.The entity unlawfully transferred personal data without consent, in breach of Article 6 of the GDPR. The case resulted in an administrative fine of 50,000 EUR.ESAEPDGDPR€50,000
01 Jan 2019CENTRO DE ESTUDIOS DIRIGIDOS DELTA, S.L.The entity sent a document via WhatsApp containing personal data of three individuals without their consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€5,000
01 Jan 2020CENTRO DE DIAGNÓSTICO ***LOCALIDAD.1, S.A.The entity was fined for breaching data confidentiality by improperly sharing medical information between different entities without consent. The case involved sensitive data processing and a lack of a valid legal basis for the disclosure.ESAEPDGDPR€10,000
21 Jan 2010Centro Chirurgico s.r.l.Centro Chirurgico s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 6,000. The case concerned the collection of personal data through a website contact form without providing the required information notice to data subjects, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
23 Feb 2023Centric Health Ltd. (“Centric”)The Irish DPC imposed a fine of EUR 460,000 on Centric Health Ltd. in inquiry IN-21-2-4. The fine has been collected.IEDPCGDPR€460,000
04 Jun 2015Centrex srlCentrex srl was fined by the Garante for conducting telemarketing activities without prior informed consent from individuals. The case involved promotional calls to numbers listed in the public opposition registry.ITGaranteGDPR€4,000
01 Jan 2012CENTRE DE REDISTRIBUCIO DE MERCADERIES, S.L.The entity was fined by the AEPD for sending unsolicited commercial emails without prior recipient consent. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€8,200
16 Jan 2025CENTRE DE FORMATION A DISTANCE D'APPRENTIS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on CENTRE DE FORMATION A DISTANCE D'APPRENTIS and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
19 Dec 2024CENTRE D'APPEL (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on CENTRE D'APPEL under a simplified procedure. The case concerned a confirmed regulatory breach, with no further details provided in the record.FRCNILGDPR€20,000
22 Nov 2019CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union CSI-CSIF was fined EUR 3,000 by the AEPD for publishing an electoral census list containing personal data, including DNI numbers, in a public WhatsApp group. The authority found this breached data protection principles.ESAEPDGDPR€3,000
03 Feb 2025CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe labor union CSI-CSIF was fined EUR 4,000 by the AEPD for failing to adequately protect personal data during a voting process. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality.ESAEPDGDPR€4,000
12 May 2023CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union sent an email containing personal data of election officials and representatives without their consent. AEPD found this to be a breach of data protection rules and imposed a 4,000 EUR fine.ESAEPDGDPR€4,000
12 May 2011Centrale Palace HotelCentrale Palace Hotel was fined EUR 6,000 by the Garante. The violation concerned the failure to provide the required privacy notice for its video surveillance system, in breach of the Italian data protection code.ITGaranteGDPR€6,000
19 Jan 2011Center Gross Sicilia S.r.l.Center Gross Sicilia S.r.l. was fined EUR 9,000 by the Garante. The authority found that the required privacy notice was not provided for three external surveillance cameras, in breach of the Italian Data Protection Code.ITGaranteGDPR€9,000
04 Mar 2021CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.CEDICO, a diagnostic imaging center, was fined EUR 30,000 by the AEPD. The authority found that the company unlawfully shared a patient's MRI report with a mutual insurance company, breaching data protection principles.ESAEPDGDPR€30,000
06 Jul 2006Ced di Demartis CarloThe sole proprietorship Ced di Demartis Carlo was fined by the Garante for failing to notify the processing of personal data. This constituted a breach of Article 7 of Law 675/1996.ITGaranteGDPR€5,164
09 Aug 2022CDI Transport Intern și Internațional SRLThe company was fined for failing to provide requested information within the legal deadline. The authority treated this as a breach of GDPR requirements.ROANSPDCPGDPR€7,000
08 Jan 2021C.C.C.C.C.C. was fined EUR 2,000 by the AEPD. The authority found that the company failed to provide a written contract and did not inform the complainant about the processing of personal data, in breach of Article 13 GDPR.ESAEPDGDPR€2,000
21 Feb 2023C.C.C.The entity was fined by the AEPD in the amount of EUR 300 for installing a video surveillance system that captured public areas. This conduct breached data protection rules.ESAEPDGDPR€300