Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Mar 2022CENTRO MÉDICO SALUS BALEARES, S.L.CENTRO MÉDICO SALUS BALEARES, S.L. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned displaying patients’ body temperatures in a way that could be seen by unauthorized third parties, which compromised confidentiality.ESAEPDGDPR€30,000
20 Nov 2014Centro Nautico Tirreno s.r.l.Centro Nautico Tirreno s.r.l. was fined by the Garante 2,400 EUR for failing to provide the required privacy notice when collecting personal data through a web form. The authority found that individuals were not properly informed before their data was collected.ITGaranteGDPR€2,400
07 Mar 2024Centro Riparazioni Piacentino S.p.A.Centro Riparazioni Piacentino S.p.A. was fined by the Garante for continuing to operate individual company accounts months after employment ended and for accessing messages without proper deletion. The authority also found inadequate information and insufficient access rights for former employees.ITGaranteGDPR€20,000
01 Mar 2017CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD €10,000 for sending commercial emails without a valid unsubscribe link. The case concerned non-compliance with electronic communications rules and recipients’ right to opt out easily.ESAEPDePrivacy€10,000
01 Jan 2016CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD for sending unsolicited advertising emails. The authority also found that the company did not provide an easy opt-out mechanism, in breach of Article 21 of the LSSI.ESAEPDePrivacy€7,000
01 Jan 2015CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD in the amount of EUR 3,300. The authority found that the company sent unsolicited advertising emails and failed to properly handle unsubscribe requests, in breach of Article 21 of the LSSI.ESAEPDePrivacy€3,300
25 Oct 2016CENTROS COMERCIALES CARREFOUR, S.A.CENTROS COMERCIALES CARREFOUR, S.A. was fined EUR 7,000 by the AEPD for sending unsolicited commercial emails. The authority also found that the company failed to provide a proper opt-out mechanism, breaching Article 21 of the LSSI.ESAEPDePrivacy€7,000
12 Jan 2017Centro Studi Raffaello s.r.l.Centro Studi Raffaello s.r.l. was fined by the Garante for inadequate data protection measures and improper collection of consent for marketing purposes. The case indicates deficiencies in the company's personal data processing controls and compliance framework.ITGaranteGDPR€20,000
12 Apr 2024Centrul Medical dr. Furtună DanThe National Supervisory Authority for Personal Data Processing imposed a fine on Centrul Medical dr. Furtună Dan for breaching Article 6 of the GDPR. The infringement concerned the absence of a proper legal basis for personal data processing.ROANSPDCPGDPR€1,500
13 Jan 2025Centrul Medical Unirea S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation at Centrul Medical Unirea S.R.L. and found a breach of Article 32 of the GDPR. A fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
08 May 2024CENTRUL MEDICAL UNIREA SRLCENTRUL MEDICAL UNIREA SRL was fined EUR 5,000 by ANSPDCP for unauthorized disclosure of personal data on the internet. The case indicates a breach of data protection rules and warrants review of security controls and publication procedures.ROANSPDCPGDPR€5,000
25 Oct 2016CEPSA COMERCIAL PETROLEO, SAUCEPSA COMERCIAL PETROLEO, SAU was fined by the AEPD in the amount of 5,700 EUR. The sanction concerned the sending of unauthorized commercial emails in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€5,700
20 Sept 2016CEPSA COMERCIAL PETROLEO, S.A.U.CEPSA COMERCIAL PETROLEO, S.A.U. was fined EUR 4,100 by the AEPD for sending commercial emails to a customer after the customer had requested to unsubscribe. The authority found this to be a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€4,100
19 Sept 2017CEPSA COMERCIAL PETRÓLEO, S.A.U.CEPSA was fined by the AEPD 3,300 EUR for sending two unsolicited commercial emails without prior consent from the recipients. The authority found this breached Article 21 of the LSSI on commercial communications.ESAEPDePrivacy€3,300
23 Oct 2019CERRAJERIA CARLOS RODRIGUEZ S.L.CERRAJERIA CARLOS RODRIGUEZ S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to the data subjects. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€1,500
23 Oct 2019CERRAJERIA VERIN S.L.CERRAJERIA VERIN S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to data subjects. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€1,500
05 Nov 2019CERRAJERO ONLINE S.L.CERRAJERO ONLINE S.L. was fined EUR 1,500 by the AEPD for collecting personal data without providing the required information to data subjects. The authority treated this as a breach of data protection rules.ESAEPDGDPR€1,500
27 Nov 2020CERTIME, S.A.CERTIME, S.A. was fined by the AEPD in the amount of 5,000 EUR for processing personal data for a purpose different from the one originally specified. The authority found this to be a breach of Article 5(1)(b) GDPR.ESAEPDGDPR€5,000
21 Jun 2016Česká republika – Ministerstvo školství, mládeže a tělovýchovyThe Czech Republic’s Ministry of Education, Youth and Sports was fined by the UOOU for processing sensitive personal data about students’ disabilities without a legal basis. The case indicates a breach of personal data protection rules and requires review of the lawful basis and data scope.CZUOOUGDPR€7,390
11 May 2018Česká republika – Ministerstvo vnitraThe Ministry of the Interior was fined by UOOU for processing sensitive personal data, including DNA profiles, without explicit consent. The authority found this to be a breach of data protection law.CZUOOUGDPR€25,487