Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Nov 2019CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union CSI-CSIF was fined EUR 3,000 by the AEPD for publishing an electoral census list containing personal data, including DNI numbers, in a public WhatsApp group. The authority found this breached data protection principles.ESAEPDGDPR€3,000
03 Feb 2025CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe labor union CSI-CSIF was fined EUR 4,000 by the AEPD for failing to adequately protect personal data during a voting process. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality.ESAEPDGDPR€4,000
12 May 2023CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union sent an email containing personal data of election officials and representatives without their consent. AEPD found this to be a breach of data protection rules and imposed a 4,000 EUR fine.ESAEPDGDPR€4,000
19 Dec 2024CENTRE D'APPEL (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on CENTRE D'APPEL under a simplified procedure. The case concerned a confirmed regulatory breach, with no further details provided in the record.FRCNILGDPR€20,000
16 Jan 2025CENTRE DE FORMATION A DISTANCE D'APPRENTIS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on CENTRE DE FORMATION A DISTANCE D'APPRENTIS and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
01 Jan 2012CENTRE DE REDISTRIBUCIO DE MERCADERIES, S.L.The entity was fined by the AEPD for sending unsolicited commercial emails without prior recipient consent. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€8,200
04 Jun 2015Centrex srlCentrex srl was fined by the Garante for conducting telemarketing activities without prior informed consent from individuals. The case involved promotional calls to numbers listed in the public opposition registry.ITGaranteGDPR€4,000
23 Feb 2023Centric Health Ltd. (“Centric”)The Irish DPC imposed a fine of EUR 460,000 on Centric Health Ltd. in inquiry IN-21-2-4. The fine has been collected.IEDPCGDPR€460,000
21 Jan 2010Centro Chirurgico s.r.l.Centro Chirurgico s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 6,000. The case concerned the collection of personal data through a website contact form without providing the required information notice to data subjects, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
01 Jan 2020CENTRO DE DIAGNÓSTICO ***LOCALIDAD.1, S.A.The entity was fined for breaching data confidentiality by improperly sharing medical information between different entities without consent. The case involved sensitive data processing and a lack of a valid legal basis for the disclosure.ESAEPDGDPR€10,000
01 Jan 2019CENTRO DE ESTUDIOS DIRIGIDOS DELTA, S.L.The entity sent a document via WhatsApp containing personal data of three individuals without their consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€5,000
20 Jul 2020CENTRO DE INVESTIGACIÓN Y ESTUDIO PARA LA OBESIDAD, S.L.The entity unlawfully transferred personal data without consent, in breach of Article 6 of the GDPR. The case resulted in an administrative fine of 50,000 EUR.ESAEPDGDPR€50,000
14 Sept 2006Centro diagnostico Helios s.n.c.Centro diagnostico Helios s.n.c. was fined for failing to notify the processing of sensitive health data, including HIV status and other medical conditions. The authority treated this as a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
25 Mar 2021Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules.ITGaranteGDPR€50,000
11 Dec 2008Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c.Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c. was fined for failing to notify the Garante of personal data processing activities within the required timeframe. The case concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
16 Dec 2021Centro di Medicina preventiva s.r.l.Centro di Medicina preventiva s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate measures to prevent unauthorized access to personal data. The deficiency resulted in a data breach.ITGaranteGDPR€10,000
02 Jul 2020CENTRO INTERNACIONAL DE CRECIMIENTO LABORAL Y PROFESIONAL, S.L.The entity sent unsolicited commercial emails without the recipients’ consent. It also failed to provide a valid unsubscribe option, which breached the LSSI.ESAEPDePrivacy€1,000
20 Jul 2017Centro Laser s.r.l.Centro Laser s.r.l. was fined EUR 20,400 by the Garante for using inadequate password procedures and failing to provide required information on data processing to users. The case concerns breaches of data protection rules.ITGaranteGDPR€20,400
10 Jul 2025Centro Medico Italiano S.r.l.Centro Medico Italiano S.r.l. was fined by the Garante 30,000 EUR for failing to provide an adequate response to a data subject’s request for access to health data and information about its processing. The authority found a breach of GDPR Article 15.ITGaranteGDPR€30,000
24 Jan 2026CENTRO MÉDICO REY FERNANDO, S.L.P.The entity charged a fee for providing a patient with their medical history, which breached the right of access under GDPR Article 12. The AEPD imposed a fine of 1,000 EUR.ESAEPDGDPR€1,000