BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Dec 2009 | Campolongo Hospital s.p.a.Campolongo Hospital s.p.a. was fined by the Garante for collecting personal data through its website without providing users with the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 22 Feb 2024 | Camera di Commercio Industria Artigianato e Agricoltura di XXCamera di Commercio was fined for violating data protection principles by improperly disclosing personal data. The disclosure could have allowed third parties to learn the content of a judicial decision and infringed the privacy of the individual concerned. | IT | Garante | GDPR | €2,000 | ↗ |
| 24 Jul 2024 | CAMDEN TAPAS C.B.CAMDEN TAPAS C.B. was fined by the AEPD EUR 500 for installing a surveillance camera that captured public areas. The authority also noted the possible sharing of footage on Facebook, which breached data protection rules. | ES | AEPD | GDPR | €500 | ↗ |
| 22 May 2018 | Calvanese RaffaelloCalvanese Raffaello, a general practitioner, was fined for failing to adopt minimum security measures to protect patients’ personal and sensitive data. The deficiencies allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 May 2017 | Call Solution s.r.l.Call Solution s.r.l. was fined EUR 40,000 by the Garante for making unsolicited promotional calls to numbers listed in the public opt-out registry. The conduct breached data protection rules and the requirements governing telephone marketing. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 Jul 2020 | CALLESGARCIA S.C.CALLESGARCIA S.C. was fined by the AEPD €4,000 for using a wedding photo in business advertising without authorization. The authority found a breach of Article 6 GDPR on lawful processing of personal data. | ES | AEPD | GDPR | €4,000 | ↗ |
| 08 Jul 2024 | CALLBELL S.A.S.CALLBELL S.A.S. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial messages to a complainant despite a request to stop. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jun 2025 | Călin GeorgescuCălin Georgescu was sanctioned by Romania’s data protection authority after an investigation into his website. Two fines totaling about EUR 10,000 were imposed for installing cookies without consent and collecting personal data without proper notice. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €10,000 | ↗ |
| 25 Jul 2021 | CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L.The company was fined by the AEPD for processing personal data without consent, which breaches Article 6 of the GDPR. The case indicates that no valid legal basis was in place for the processing activity. | ES | AEPD | GDPR | €5,000 | ↗ |
| 22 Jan 2024 | CAJASIETE, CAJA RURAL SOCIEDAD COOPERATIVA DE CREDITOCAJASIETE was fined by the AEPD in the amount of 250,000 EUR for a data security incident. The incident compromised the confidentiality and integrity of personal data, breaching GDPR Article 5(1)(f). | ES | AEPD | GDPR | €250,000 | ↗ |
| 01 Jan 2020 | Caja Rural San José de Nules S. Cooperativa de Crédito de la Comunidad ValencianaCaja Rural San José de Nules was fined by the AEPD 5,000 EUR for publicly displaying individuals’ personal data on a notice board. The conduct breached data protection principles by exposing their economic status. | ES | AEPD | GDPR | €5,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL REGIONAL SAN AGUSTÍN, S.C.C.CAJA RURAL REGIONAL SAN AGUSTÍN was fined by the AEPD 15,000 EUR for breaching data protection principles. The authority found that unauthorized access to personal data occurred due to a security incident, affecting confidentiality and integrity. | ES | AEPD | GDPR | €15,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL NTRA MADRE DEL SOL S.C.A.C.CAJA RURAL NTRA MADRE DEL SOL S.C.A.C. was fined by the AEPD for a data breach that enabled unauthorized access to personal data. The authority found a violation of the confidentiality and integrity principles for personal data. | ES | AEPD | GDPR | €250,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL GRANADA, S.C.C.CAJA RURAL GRANADA was fined by the AEPD EUR 15,000 for breaching data protection principles. The authority found that unauthorized access to personal data occurred due to a security incident, affecting confidentiality and integrity. | ES | AEPD | GDPR | €15,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE ZAMORA COOPERATIVA DE CRÉDITOCAJA RURAL DE ZAMORA was fined by the AEPD EUR 15,000 for a personal data breach. The incident affected the confidentiality and integrity of personal data, breaching GDPR Article 5(1)(f). | ES | AEPD | GDPR | €15,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE TERUEL, S.C.C.CAJA RURAL DE TERUEL was fined by the AEPD EUR 250,000 for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident. | ES | AEPD | GDPR | €250,000 | ↗ |
| 22 Jan 2024 | CAJA RURAL DE SORIA, S.C.C.CAJA RURAL DE SORIA, S.C.C. was fined by the AEPD 15,000 EUR for breaching personal data protection principles. The case involved a failure to protect confidentiality and integrity, resulting in unauthorized access following a data breach. | ES | AEPD | GDPR | €15,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE SALAMANCA, S.C.C.CAJA RURAL DE SALAMANCA, S.C.C. was fined by the AEPD 250,000 EUR for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident. | ES | AEPD | GDPR | €250,000 | ↗ |
| 24 Jan 2024 | CAJA RURAL DE ONDA, S.C.C.CAJA RURAL DE ONDA, S.C.C. was fined by the AEPD 15,000 EUR for violating data protection principles, including confidentiality and integrity. The breach resulted in unauthorized access to personal data. | ES | AEPD | GDPR | €15,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE NAVARRA, S.C.C.CAJA RURAL DE NAVARRA was fined EUR 20,000 by the AEPD for a personal data breach. The incident compromised the confidentiality and integrity of personal data, breaching Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |