BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Feb 2018 | Car City Club s.r.l.Car City Club s.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to designate data processors among its employees, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Feb 2018 | Car2Go Italia s.r.l.Car2Go Italia s.r.l. was fined EUR 20,000 by the Garante. The authority found a breach of data protection rules for failing to designate employees as data processors in connection with geolocation data processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 06 Jun 2024 | Cappello Giovanni & figli s.r.l.Cappello Giovanni & figli s.r.l. was fined by Garante for unlawful processing of employee personal data using Infinity DMS software and X.-Face 380 hardware. The authority found that the company's practices breached GDPR principles. | IT | Garante | GDPR | €120,000 | ↗ |
| 24 Apr 2013 | Cappellina FedericoCappellina Federico was fined by the Garante in the amount of 2,400 EUR for failing to provide the required privacy notice in a private club's video surveillance system. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Nov 2015 | Capodarco Società Cooperativa Sociale IntegrataCapodarco Società Cooperativa Sociale Integrata was fined EUR 12,000 by the Garante for recording and listening to calls between call center operators and users. The authority found that the required information notice was not provided to worker members, in breach of data protection rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 01 Oct 2023 | Capita plc and CPSLThe Information Commissioner's Office imposed a GBP 2,000,000 fine on Capita plc and CPSL. The case concerned data protection breaches linked to unsolicited marketing calls, indicating improper use of contact data. | GB | Information Commissioner's Office | GDPR | €2,313,000 | ↗ |
| 15 Oct 2025 | Capita plc and Capita Pension Solutions LtdThe UK Information Commissioner’s Office fined Capita plc and Capita Pension Solutions Ltd a combined £14m after a cyber attack in April 2023. Hackers gained access to the data of more than 6 million people. The case highlights serious weaknesses in data protection and incident response. | GB | ICO | GDPR | €16,083,000 | ↗ |
| 10 Oct 2025 | Capita plc and Capita Pension Solutions LimitedThe Information Commissioner's Office imposed a £14 million fine on Capita plc and Capita Pension Solutions Limited for UK GDPR infringements linked to a March 2023 cyber security breach. The case concerned inadequate technical and organisational measures and a delayed response to security alerts. | GB | Information Commissioner's Office | GDPR | €16,074,000 | ↗ |
| 15 Oct 2025 | CapitaThe ICO fined Capita GBP 14 million after a data breach exposed the personal data of more than 6 million people. The case points to failures in security controls, governance, and GDPR compliance. | GB | Information Commissioner's Office | GDPR | €16,083,000 | ↗ |
| 02 Dec 2020 | Capio S:t Görans Sjukhus ABCapio S:t Görans Sjukhus AB was fined by IMY for processing personal data in breach of GDPR. The authority found inadequate needs and risk analyses and insufficient restriction of user access to patient data in the journal systems. | SE | IMY | GDPR | €2,917,000 | ↗ |
| 01 Feb 2024 | Capio A/SThe Danish Data Protection Authority reported Capio A/S to the police and recommended a fine of at least DKK 1,500,000. The case concerned insufficient supervision of data processors, breaching the GDPR accountability principle. | DK | Datatilsynet | GDPR | €201,000 | ↗ |
| 12 Nov 2015 | Cantiere 21 s.r.l.Cantiere 21 s.r.l. was fined by the Garante in the amount of 2,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority treated this as a breach of privacy rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 15 Jan 2026 | CANDIDATS AUX ÉLECTIONS LÉGISLATIVES (procédure simplifiée)CNIL imposed an administrative fine of 2,000 EUR on CANDIDATS AUX ÉLECTIONS LÉGISLATIVES (procédure simplifiée) and issued an injunction. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €2,000 | ↗ |
| 11 Dec 2025 | CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,500 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,500 | ↗ |
| 11 Dec 2025 | CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 11 Dec 2025 | CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of EUR 2,500 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure and concerned a confirmed regulatory breach. | FR | CNIL | GDPR | €2,500 | ↗ |
| 27 Nov 2025 | CANDIDAT AUX ELECTIONS AU PARLEMENT EUROPEEN DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of €8,000 on CANDIDAT AUX ELECTIONS AU PARLEMENT EUROPEEN DE 2024 and issued an injunction. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €8,000 | ↗ |
| 01 Jan 2018 | CANARY ISLANDS CAR S.L.CANARY ISLANDS CAR S.L. was fined by the AEPD 45,000 EUR for inaccurate processing of personal data. As a result, a traffic violation was incorrectly attributed to a person who had not rented the vehicle. | ES | AEPD | GDPR | €45,000 | ↗ |
| 03 Nov 2020 | CANARYCLICK CONSULTING SLCANARYCLICK CONSULTING SL was fined EUR 8,000 by the AEPD for improper management of its cookie policy on its websites. The authority also found that user consent was collected in a generic manner, in breach of data protection rules. | ES | AEPD | GDPR | €8,000 | ↗ |
| 16 Dec 2009 | Campolongo Hospital s.p.a.Campolongo Hospital s.p.a. was fined by the Garante in the amount of 20,000 EUR. The case concerned the processing of personal data without the required notification under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |