Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jul 2023C.C.C.The entity was fined for operating a video surveillance system that captured public areas and neighboring properties without the required authorization. Required informational signage was also not displayed.ESAEPDGDPR€600
15 Oct 2013C.C.C.C.C.C. was fined 600 EUR by the AEPD for sending unsolicited SMS messages without prior consent from recipients. The authority found this conduct breached Article 21 of the LSSI on commercial communications.ESAEPDePrivacy€600
30 Nov 2022CBHNOS S.L.CBHNOS S.L. was fined 500 EUR by the AEPD for installing a video surveillance system that could capture images of public areas. The authority considered this a breach of data protection rules.ESAEPDGDPR€500
11 Dec 2023C*** Bank AGC*** Bank AG was fined by the DSB EUR 9,500 for breaching Article 15 GDPR. The bank treated an access request as a deletion request and deleted the data instead of providing the requested information.ATDSBGDPR€9,500
26 Mar 2020Cavauto s.r.l.Cavauto s.r.l. was fined by the Garante EUR 10,000 for violating GDPR principles on data processing. The case involved improper handling of employee data and failures to ensure proper access and deletion rights.ITGaranteGDPR€10,000
18 Jul 2023Cat s.r.l.The Garante imposed a EUR 10,000 fine on Cat s.r.l. for operating a video surveillance system near waste bins in breach of the principles of lawfulness, fairness, and transparency. The case concerned the data of residents and non-residents of the Comune di Modica.ITGaranteGDPR€10,000
20 Nov 2008Castaldo intermediazione immobiliare di Antonia Romeo e Roberto Castaldo s.n.c.The company was fined by the Garante 6,000 EUR for failing to provide adequate information to data subjects about the processing of personal data collected through its website. The case concerned a breach of the information duties under the Italian Data Protection Code.ITGaranteGDPR€6,000
22 Apr 2010Cassine di Pietra s.r.l.Cassine di Pietra s.r.l. was fined by the Garante €10,400 for making unsolicited promotional calls using automated systems. The authority found that proper information was not provided and consent had not been obtained, constituting a data protection breach.ITGaranteGDPR€10,400
22 Apr 2010Cassine di Pietra s.r.l.Cassine di Pietra s.r.l. was fined EUR 10,400 by the Garante for making unsolicited promotional calls using automated systems. The authority found that proper information was not provided and consent had not been obtained.ITGaranteGDPR€10,400
28 Feb 2019Casinò di Venezia Meeting & Dining S.r.l.Casinò di Venezia Meeting & Dining S.r.l. was fined EUR 4,000 by the Garante. The authority found that adequate security measures had not been implemented, in breach of Article 33 of the Italian Privacy Code.ITGaranteGDPR€4,000
13 Mar 2025Casatua S.r.l.Casatua S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited communications via WhatsApp without obtaining proper recipient consent. The company also failed to implement adequate procedures to ensure compliance with data protection rules.ITGaranteGDPR€10,000
09 Dec 2022Casa Rusu S.R.L.The company was fined for a data security breach on its online payment section. An unauthorized form was introduced there and collected customers’ card data.ROANSPDCPGDPR€2,000
21 Oct 2022CASAL DE L'ESPLUGA DE FRANCOLÍCASAL DE L'ESPLUGA DE FRANCOLÍ was fined by the AEPD for publishing a video on social media without consent. The recording showed a minor during a sports event, which constituted a breach of data protection rules.ESAEPDGDPR€5,000
29 Jan 2020CASA GRACIO OPERATION, SLUCASA GRACIO OPERATION, SLU was fined by the AEPD 10,000 EUR for installing a video surveillance system that could capture public areas and access points. The authority found that this processing breached data protection rules.ESAEPDGDPR€10,000
16 Dec 2009Casa di cura Villa Russo s.p.a.Casa di cura Villa Russo s.p.a. was fined by the Garante for processing personal data without proper notification. The authority found violations of articles 37 and 38 of the Italian Data Protection Code.ITGaranteGDPR€30,000
02 Feb 2012Casa di cura Villa Giustina s.r.l.Casa di cura Villa Giustina s.r.l. was fined 40,000 EUR by the Garante. The authority found that the company failed to submit the required notification for personal data processing activities under the Italian Data Protection Code.ITGaranteGDPR€40,000
15 Dec 2011Casa di cura Villa Domelia s.r.l.Casa di cura Villa Domelia s.r.l. was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code.ITGaranteGDPR€20,000
04 Nov 2010Casa di Cura Tortorella S.p.aCasa di Cura Tortorella S.p.a was fined by the Garante for failing to notify certain data processing activities and for providing inadequate information to data subjects. The case concerns breaches of the Italian Data Protection Code and points to deficiencies in basic notification and transparency obligations.ITGaranteGDPR€20,000
27 Mar 2014Casa di cura Scarnati srlCasa di cura Scarnati srl was fined €10,000 by the Garante. The authority found that the company failed to properly designate, in writing, the employees authorized to process personal data.ITGaranteGDPR€10,000
01 Apr 2009Casa di cura Sant'Antonio s.p.a.Casa di cura Sant'Antonio s.p.a. was fined by the Italian data protection authority, Garante. The case concerned processing personal data without the required notification under the Italian Data Protection Code.ITGaranteGDPR€10,000