Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jan 2024CAJA RURAL NTRA MADRE DEL SOL S.C.A.C.CAJA RURAL NTRA MADRE DEL SOL S.C.A.C. was fined by the AEPD for a data breach that enabled unauthorized access to personal data. The authority found a violation of the confidentiality and integrity principles for personal data.ESAEPDGDPR€250,000
23 Jan 2024CAJA RURAL REGIONAL SAN AGUSTÍN, S.C.C.CAJA RURAL REGIONAL SAN AGUSTÍN was fined by the AEPD 15,000 EUR for breaching data protection principles. The authority found that unauthorized access to personal data occurred due to a security incident, affecting confidentiality and integrity.ESAEPDGDPR€15,000
01 Jan 2020Caja Rural San José de Nules S. Cooperativa de Crédito de la Comunidad ValencianaCaja Rural San José de Nules was fined by the AEPD 5,000 EUR for publicly displaying individuals’ personal data on a notice board. The conduct breached data protection principles by exposing their economic status.ESAEPDGDPR€5,000
22 Jan 2024CAJASIETE, CAJA RURAL SOCIEDAD COOPERATIVA DE CREDITOCAJASIETE was fined by the AEPD in the amount of 250,000 EUR for a data security incident. The incident compromised the confidentiality and integrity of personal data, breaching GDPR Article 5(1)(f).ESAEPDGDPR€250,000
25 Jul 2021CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L.The company was fined by the AEPD for processing personal data without consent, which breaches Article 6 of the GDPR. The case indicates that no valid legal basis was in place for the processing activity.ESAEPDGDPR€5,000
01 Jun 2025Călin GeorgescuCălin Georgescu was sanctioned by Romania’s data protection authority after an investigation into his website. Two fines totaling about EUR 10,000 were imposed for installing cookies without consent and collecting personal data without proper notice.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€10,000
08 Jul 2024CALLBELL S.A.S.CALLBELL S.A.S. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial messages to a complainant despite a request to stop. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
29 Jul 2020CALLESGARCIA S.C.CALLESGARCIA S.C. was fined by the AEPD €4,000 for using a wedding photo in business advertising without authorization. The authority found a breach of Article 6 GDPR on lawful processing of personal data.ESAEPDGDPR€4,000
24 May 2017Call Solution s.r.l.Call Solution s.r.l. was fined EUR 40,000 by the Garante for making unsolicited promotional calls to numbers listed in the public opt-out registry. The conduct breached data protection rules and the requirements governing telephone marketing.ITGaranteGDPR€40,000
22 May 2018Calvanese RaffaelloCalvanese Raffaello, a general practitioner, was fined for failing to adopt minimum security measures to protect patients’ personal and sensitive data. The deficiencies allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
24 Jul 2024CAMDEN TAPAS C.B.CAMDEN TAPAS C.B. was fined by the AEPD EUR 500 for installing a surveillance camera that captured public areas. The authority also noted the possible sharing of footage on Facebook, which breached data protection rules.ESAEPDGDPR€500
22 Feb 2024Camera di Commercio Industria Artigianato e Agricoltura di XXCamera di Commercio was fined for violating data protection principles by improperly disclosing personal data. The disclosure could have allowed third parties to learn the content of a judicial decision and infringed the privacy of the individual concerned.ITGaranteGDPR€2,000
16 Dec 2009Campolongo Hospital s.p.a.Campolongo Hospital s.p.a. was fined by the Garante in the amount of 20,000 EUR. The case concerned the processing of personal data without the required notification under the Italian Data Protection Code.ITGaranteGDPR€20,000
16 Dec 2009Campolongo Hospital s.p.a.Campolongo Hospital s.p.a. was fined by the Garante for collecting personal data through its website without providing users with the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
03 Nov 2020CANARYCLICK CONSULTING SLCANARYCLICK CONSULTING SL was fined EUR 8,000 by the AEPD for improper management of its cookie policy on its websites. The authority also found that user consent was collected in a generic manner, in breach of data protection rules.ESAEPDGDPR€8,000
01 Jan 2018CANARY ISLANDS CAR S.L.CANARY ISLANDS CAR S.L. was fined by the AEPD 45,000 EUR for inaccurate processing of personal data. As a result, a traffic violation was incorrectly attributed to a person who had not rented the vehicle.ESAEPDGDPR€45,000
27 Nov 2025CANDIDAT AUX ELECTIONS AU PARLEMENT EUROPEEN DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of €8,000 on CANDIDAT AUX ELECTIONS AU PARLEMENT EUROPEEN DE 2024 and issued an injunction. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€8,000
11 Dec 2025CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,500 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure.FRCNILGDPR€5,500
11 Dec 2025CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure.FRCNILGDPR€5,000
11 Dec 2025CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of EUR 2,500 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure and concerned a confirmed regulatory breach.FRCNILGDPR€2,500