Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Oct 2022CASAL DE L'ESPLUGA DE FRANCOLÍCASAL DE L'ESPLUGA DE FRANCOLÍ was fined by the AEPD for publishing a video on social media without consent. The recording showed a minor during a sports event, which constituted a breach of data protection rules.ESAEPDGDPR€5,000
09 Dec 2022Casa Rusu S.R.L.The company was fined for a data security breach on its online payment section. An unauthorized form was introduced there and collected customers’ card data.ROANSPDCPGDPR€2,000
13 Mar 2025Casatua S.r.l.Casatua S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited communications via WhatsApp without obtaining proper recipient consent. The company also failed to implement adequate procedures to ensure compliance with data protection rules.ITGaranteGDPR€10,000
28 Feb 2019Casinò di Venezia Meeting & Dining S.r.l.Casinò di Venezia Meeting & Dining S.r.l. was fined EUR 4,000 by the Garante. The authority found that adequate security measures had not been implemented, in breach of Article 33 of the Italian Privacy Code.ITGaranteGDPR€4,000
22 Apr 2010Cassine di Pietra s.r.l.Cassine di Pietra s.r.l. was fined by the Garante €10,400 for making unsolicited promotional calls using automated systems. The authority found that proper information was not provided and consent had not been obtained, constituting a data protection breach.ITGaranteGDPR€10,400
22 Apr 2010Cassine di Pietra s.r.l.Cassine di Pietra s.r.l. was fined EUR 10,400 by the Garante for making unsolicited promotional calls using automated systems. The authority found that proper information was not provided and consent had not been obtained.ITGaranteGDPR€10,400
20 Nov 2008Castaldo intermediazione immobiliare di Antonia Romeo e Roberto Castaldo s.n.c.The company was fined by the Garante 6,000 EUR for failing to provide adequate information to data subjects about the processing of personal data collected through its website. The case concerned a breach of the information duties under the Italian Data Protection Code.ITGaranteGDPR€6,000
18 Jul 2023Cat s.r.l.The Garante imposed a EUR 10,000 fine on Cat s.r.l. for operating a video surveillance system near waste bins in breach of the principles of lawfulness, fairness, and transparency. The case concerned the data of residents and non-residents of the Comune di Modica.ITGaranteGDPR€10,000
26 Mar 2020Cavauto s.r.l.Cavauto s.r.l. was fined by the Garante EUR 10,000 for violating GDPR principles on data processing. The case involved improper handling of employee data and failures to ensure proper access and deletion rights.ITGaranteGDPR€10,000
11 Dec 2023C*** Bank AGC*** Bank AG was fined by the DSB EUR 9,500 for breaching Article 15 GDPR. The bank treated an access request as a deletion request and deleted the data instead of providing the requested information.ATDSBGDPR€9,500
30 Nov 2022CBHNOS S.L.CBHNOS S.L. was fined 500 EUR by the AEPD for installing a video surveillance system that could capture images of public areas. The authority considered this a breach of data protection rules.ESAEPDGDPR€500
08 Jan 2021C.C.C.C.C.C. was fined EUR 2,000 by the AEPD. The authority found that the company failed to provide a written contract and did not inform the complainant about the processing of personal data, in breach of Article 13 GDPR.ESAEPDGDPR€2,000
21 Feb 2023C.C.C.The entity was fined by the AEPD in the amount of EUR 300 for installing a video surveillance system that captured public areas. This conduct breached data protection rules.ESAEPDGDPR€300
10 Jul 2023C.C.C.The entity was fined for operating a video surveillance system that captured public areas and neighboring properties without the required authorization. Required informational signage was also not displayed.ESAEPDGDPR€600
15 Oct 2013C.C.C.C.C.C. was fined 600 EUR by the AEPD for sending unsolicited SMS messages without prior consent from recipients. The authority found this conduct breached Article 21 of the LSSI on commercial communications.ESAEPDePrivacy€600
09 Aug 2022CDI Transport Intern și Internațional SRLThe company was fined for failing to provide requested information within the legal deadline. The authority treated this as a breach of GDPR requirements.ROANSPDCPGDPR€7,000
06 Jul 2006Ced di Demartis CarloThe sole proprietorship Ced di Demartis Carlo was fined by the Garante for failing to notify the processing of personal data. This constituted a breach of Article 7 of Law 675/1996.ITGaranteGDPR€5,164
04 Mar 2021CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.CEDICO, a diagnostic imaging center, was fined EUR 30,000 by the AEPD. The authority found that the company unlawfully shared a patient's MRI report with a mutual insurance company, breaching data protection principles.ESAEPDGDPR€30,000
19 Jan 2011Center Gross Sicilia S.r.l.Center Gross Sicilia S.r.l. was fined EUR 9,000 by the Garante. The authority found that the required privacy notice was not provided for three external surveillance cameras, in breach of the Italian Data Protection Code.ITGaranteGDPR€9,000
12 May 2011Centrale Palace HotelCentrale Palace Hotel was fined EUR 6,000 by the Garante. The violation concerned the failure to provide the required privacy notice for its video surveillance system, in breach of the Italian data protection code.ITGaranteGDPR€6,000