BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Nov 2019 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union CSI-CSIF was fined EUR 3,000 by the AEPD for publishing an electoral census list containing personal data, including DNI numbers, in a public WhatsApp group. The authority found this breached data protection principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 03 Feb 2025 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe labor union CSI-CSIF was fined EUR 4,000 by the AEPD for failing to adequately protect personal data during a voting process. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality. | ES | AEPD | GDPR | €4,000 | ↗ |
| 12 May 2023 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union sent an email containing personal data of election officials and representatives without their consent. AEPD found this to be a breach of data protection rules and imposed a 4,000 EUR fine. | ES | AEPD | GDPR | €4,000 | ↗ |
| 19 Dec 2024 | CENTRE D'APPEL (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on CENTRE D'APPEL under a simplified procedure. The case concerned a confirmed regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €20,000 | ↗ |
| 16 Jan 2025 | CENTRE DE FORMATION A DISTANCE D'APPRENTIS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on CENTRE DE FORMATION A DISTANCE D'APPRENTIS and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 01 Jan 2012 | CENTRE DE REDISTRIBUCIO DE MERCADERIES, S.L.The entity was fined by the AEPD for sending unsolicited commercial emails without prior recipient consent. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €8,200 | ↗ |
| 04 Jun 2015 | Centrex srlCentrex srl was fined by the Garante for conducting telemarketing activities without prior informed consent from individuals. The case involved promotional calls to numbers listed in the public opposition registry. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Feb 2023 | Centric Health Ltd. (“Centric”)The Irish DPC imposed a fine of EUR 460,000 on Centric Health Ltd. in inquiry IN-21-2-4. The fine has been collected. | IE | DPC | GDPR | €460,000 | ↗ |
| 21 Jan 2010 | Centro Chirurgico s.r.l.Centro Chirurgico s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 6,000. The case concerned the collection of personal data through a website contact form without providing the required information notice to data subjects, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 01 Jan 2020 | CENTRO DE DIAGNÓSTICO ***LOCALIDAD.1, S.A.The entity was fined for breaching data confidentiality by improperly sharing medical information between different entities without consent. The case involved sensitive data processing and a lack of a valid legal basis for the disclosure. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2019 | CENTRO DE ESTUDIOS DIRIGIDOS DELTA, S.L.The entity sent a document via WhatsApp containing personal data of three individuals without their consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD. | ES | AEPD | GDPR | €5,000 | ↗ |
| 20 Jul 2020 | CENTRO DE INVESTIGACIÓN Y ESTUDIO PARA LA OBESIDAD, S.L.The entity unlawfully transferred personal data without consent, in breach of Article 6 of the GDPR. The case resulted in an administrative fine of 50,000 EUR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 14 Sept 2006 | Centro diagnostico Helios s.n.c.Centro diagnostico Helios s.n.c. was fined for failing to notify the processing of sensitive health data, including HIV status and other medical conditions. The authority treated this as a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Mar 2021 | Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules. | IT | Garante | GDPR | €50,000 | ↗ |
| 11 Dec 2008 | Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c.Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c. was fined for failing to notify the Garante of personal data processing activities within the required timeframe. The case concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Dec 2021 | Centro di Medicina preventiva s.r.l.Centro di Medicina preventiva s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate measures to prevent unauthorized access to personal data. The deficiency resulted in a data breach. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Jul 2020 | CENTRO INTERNACIONAL DE CRECIMIENTO LABORAL Y PROFESIONAL, S.L.The entity sent unsolicited commercial emails without the recipients’ consent. It also failed to provide a valid unsubscribe option, which breached the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 20 Jul 2017 | Centro Laser s.r.l.Centro Laser s.r.l. was fined EUR 20,400 by the Garante for using inadequate password procedures and failing to provide required information on data processing to users. The case concerns breaches of data protection rules. | IT | Garante | GDPR | €20,400 | ↗ |
| 10 Jul 2025 | Centro Medico Italiano S.r.l.Centro Medico Italiano S.r.l. was fined by the Garante 30,000 EUR for failing to provide an adequate response to a data subject’s request for access to health data and information about its processing. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €30,000 | ↗ |
| 24 Jan 2026 | CENTRO MÉDICO REY FERNANDO, S.L.P.The entity charged a fee for providing a patient with their medical history, which breached the right of access under GDPR Article 12. The AEPD imposed a fine of 1,000 EUR. | ES | AEPD | GDPR | €1,000 | ↗ |