Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Apr 2023Česká republika – Ministerstvo vnitraThe Czech Ministry of Interior was fined CZK 975,000 by the UOOU for violations of personal data processing rules during COVID-19 measures. The authority found, among other issues, a failure to conduct data protection impact assessments and improper disclosure of processing purposes.CZUOOUGDPR€41,633
10 Feb 2021CEYLLE SOLUTIONS & DEVELOPMENT S.L.CEYLLE SOLUTIONS & DEVELOPMENT S.L. was fined by the AEPD in the amount of 2,000 EUR for disclosing personal data in emails sent to commercial partners. The authority found a breach of data protection rules.ESAEPDGDPR€2,000
02 Oct 2023Cez Vânzare S.A.Cez Vânzare S.A. was fined by ANSPDCP EUR 1,000 for a data protection breach. The incident resulted in unauthorized disclosure or access to personal data, including names, correspondence addresses, and customer codes of both individuals and legal entities.ROANSPDCPGDPR€1,000
01 Mar 2017CGPN, SARLCGPN, SARL was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails without prior consent. This conduct breached Spanish data protection rules.ESAEPDePrivacy€2,000
26 Nov 2020Charly Mike s.r.l.Charly Mike s.r.l. was fined by the Garante EUR 3,000 for improper use of a video surveillance system at Hotel Olimpo. The system was used for continuous monitoring and remote viewing of employees, in breach of data protection rules.ITGaranteGDPR€3,000
27 Apr 2023Checcoro di Nigro FrancescoThe company was fined EUR 2,000 by the Italian data protection authority, Garante. The sanction concerned the use of surveillance cameras without appropriate informational signage, in breach of GDPR requirements.ITGaranteGDPR€2,000
12 Sept 2013Cheng LiangxiaoCheng Liangxiao was fined by the Italian Garante for failing to provide the required privacy notice for a surveillance camera at his commercial premises. The breach concerned the absence of information on personal data processing for individuals captured by the camera.ITGaranteGDPR€2,400
15 May 2013Chen JingChen Jing was fined by the Italian Garante in the amount of EUR 2,400 for providing inadequate information about a video surveillance system at Ottimoda S.a.s. The case concerned a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
07 Jan 2020CHENMING YE (BAZAR REAL)CHENMING YE (BAZAR REAL) was fined EUR 900 by the AEPD. The authority found that the required visible notice identifying the data controller was missing, which breached data protection rules.ESAEPDGDPR€900
05 Jun 2023CHINA CENTER LLEIDACHINA CENTER LLEIDA was fined EUR 700 by the AEPD for failing to properly sign its video surveillance system and for not providing customers with required data protection information. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€700
08 Jul 2015Chirco MicheleChirco Michele was fined for processing personal data through a video surveillance system without providing the required information notice to the data subjects. This constituted a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
12 May 2023CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed a fine of EUR 4,500 on CHIRURGIEN DENTISTE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€4,500
17 Oct 2024CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on CHIRURGIEN DENTISTE under a simplified procedure. The authority also issued an injunction, indicating that remedial action is required.FRCNILGDPR€3,000
31 Jan 2024CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on CHIRURGIEN DENTISTE. The case was handled under a simplified procedure.FRCNILGDPR€5,000
29 Feb 2024CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on CHIRURGIEN DENTISTE under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision.FRCNILGDPR€4,000
08 Jan 2015CHRYSOS ODIGOS ENTYPH & HLEKTRONIKI PLHROFORISI A.E.The company was fined by the HDPA EUR 10,000 for processing personal data without consent. The authority also found that it failed to respond to data subjects' requests for access and objection.GRHDPAGDPR€10,000
01 Jan 2024CIBERSEO JAÉN, S.L.CIBERSEO JAÉN, S.L. was fined EUR 1,500 by the AEPD for publishing a photograph of an individual without consent on a job search website. The case concerned processing personal data without a lawful basis, contrary to Article 6 of the GDPR.ESAEPDGDPR€1,500
20 Mar 2008Cid-Centro informazioni didatticoCid-Centro informazioni didattico was fined 3,000 EUR by the Garante for sending advertising material by fax without providing prior and adequate information to recipients. The conduct breached data protection rules.ITGaranteGDPR€3,000
26 Sept 2024CI & DI Food s.r.l.CI & DI Food s.r.l. was fined by the Garante 4,000 EUR for failing to respond to an employee’s request to access personal data related to employment. The request included work attendance records.ITGaranteGDPR€4,000
24 Apr 2024C.I.EL. S.p.A.C.I.EL. S.p.A. was fined 10,000 EUR by the Garante following a complaint from a former employee. The case concerned violations related to the right of access to training certificates.ITGaranteGDPR€10,000