BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Mar 2022 | CENTRO MÉDICO SALUS BALEARES, S.L.CENTRO MÉDICO SALUS BALEARES, S.L. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned displaying patients’ body temperatures in a way that could be seen by unauthorized third parties, which compromised confidentiality. | ES | AEPD | GDPR | €30,000 | ↗ |
| 20 Nov 2014 | Centro Nautico Tirreno s.r.l.Centro Nautico Tirreno s.r.l. was fined by the Garante 2,400 EUR for failing to provide the required privacy notice when collecting personal data through a web form. The authority found that individuals were not properly informed before their data was collected. | IT | Garante | GDPR | €2,400 | ↗ |
| 07 Mar 2024 | Centro Riparazioni Piacentino S.p.A.Centro Riparazioni Piacentino S.p.A. was fined by the Garante for continuing to operate individual company accounts months after employment ended and for accessing messages without proper deletion. The authority also found inadequate information and insufficient access rights for former employees. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Mar 2017 | CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD €10,000 for sending commercial emails without a valid unsubscribe link. The case concerned non-compliance with electronic communications rules and recipients’ right to opt out easily. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 01 Jan 2016 | CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD for sending unsolicited advertising emails. The authority also found that the company did not provide an easy opt-out mechanism, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 01 Jan 2015 | CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD in the amount of EUR 3,300. The authority found that the company sent unsolicited advertising emails and failed to properly handle unsubscribe requests, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 25 Oct 2016 | CENTROS COMERCIALES CARREFOUR, S.A.CENTROS COMERCIALES CARREFOUR, S.A. was fined EUR 7,000 by the AEPD for sending unsolicited commercial emails. The authority also found that the company failed to provide a proper opt-out mechanism, breaching Article 21 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 12 Jan 2017 | Centro Studi Raffaello s.r.l.Centro Studi Raffaello s.r.l. was fined by the Garante for inadequate data protection measures and improper collection of consent for marketing purposes. The case indicates deficiencies in the company's personal data processing controls and compliance framework. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Apr 2024 | Centrul Medical dr. Furtună DanThe National Supervisory Authority for Personal Data Processing imposed a fine on Centrul Medical dr. Furtună Dan for breaching Article 6 of the GDPR. The infringement concerned the absence of a proper legal basis for personal data processing. | RO | ANSPDCP | GDPR | €1,500 | ↗ |
| 13 Jan 2025 | Centrul Medical Unirea S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation at Centrul Medical Unirea S.R.L. and found a breach of Article 32 of the GDPR. A fine of EUR 2,000 was imposed. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 08 May 2024 | CENTRUL MEDICAL UNIREA SRLCENTRUL MEDICAL UNIREA SRL was fined EUR 5,000 by ANSPDCP for unauthorized disclosure of personal data on the internet. The case indicates a breach of data protection rules and warrants review of security controls and publication procedures. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 25 Oct 2016 | CEPSA COMERCIAL PETROLEO, SAUCEPSA COMERCIAL PETROLEO, SAU was fined by the AEPD in the amount of 5,700 EUR. The sanction concerned the sending of unauthorized commercial emails in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €5,700 | ↗ |
| 20 Sept 2016 | CEPSA COMERCIAL PETROLEO, S.A.U.CEPSA COMERCIAL PETROLEO, S.A.U. was fined EUR 4,100 by the AEPD for sending commercial emails to a customer after the customer had requested to unsubscribe. The authority found this to be a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €4,100 | ↗ |
| 19 Sept 2017 | CEPSA COMERCIAL PETRÓLEO, S.A.U.CEPSA was fined by the AEPD 3,300 EUR for sending two unsolicited commercial emails without prior consent from the recipients. The authority found this breached Article 21 of the LSSI on commercial communications. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 23 Oct 2019 | CERRAJERIA CARLOS RODRIGUEZ S.L.CERRAJERIA CARLOS RODRIGUEZ S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to the data subjects. The authority found a breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 23 Oct 2019 | CERRAJERIA VERIN S.L.CERRAJERIA VERIN S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to data subjects. The authority found a breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 05 Nov 2019 | CERRAJERO ONLINE S.L.CERRAJERO ONLINE S.L. was fined EUR 1,500 by the AEPD for collecting personal data without providing the required information to data subjects. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 27 Nov 2020 | CERTIME, S.A.CERTIME, S.A. was fined by the AEPD in the amount of 5,000 EUR for processing personal data for a purpose different from the one originally specified. The authority found this to be a breach of Article 5(1)(b) GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 21 Jun 2016 | Česká republika – Ministerstvo školství, mládeže a tělovýchovyThe Czech Republic’s Ministry of Education, Youth and Sports was fined by the UOOU for processing sensitive personal data about students’ disabilities without a legal basis. The case indicates a breach of personal data protection rules and requires review of the lawful basis and data scope. | CZ | UOOU | GDPR | €7,390 | ↗ |
| 11 May 2018 | Česká republika – Ministerstvo vnitraThe Ministry of the Interior was fined by UOOU for processing sensitive personal data, including DNA profiles, without explicit consent. The authority found this to be a breach of data protection law. | CZ | UOOU | GDPR | €25,487 | ↗ |