Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Feb 2026Ciemme S.r.l.sThe Italian Data Protection Authority fined Ciemme S.r.l.s EUR 1,000 for failing to respond to a data subject request to exercise rights of access, erasure, and objection. The case arose after unsolicited marketing calls.ITGaranteGDPR€1,000
16 Mar 2017Cigno d’Argento s.r.l.Cigno d’Argento s.r.l. was fined by the Garante 36,000 EUR for data protection violations. The case concerned the improper use of video surveillance systems without the required authorization.ITGaranteGDPR€36,000
11 Mar 2022CINCON S.C.CINCON S.C. was fined EUR 500 by the AEPD for failing to provide adequate information about the retention period of personal data collected through a website form. The authority found a breach of Article 13 GDPR because data subjects were not given the required notice.ESAEPDGDPR€500
27 Jan 2022Circolo culturale “Ruian”Circolo culturale “Ruian” was fined EUR 2,000 by the Garante for operating a video surveillance system in breach of data protection rules. The cameras were not properly signposted, which failed to meet the required information obligations toward monitored individuals.ITGaranteGDPR€2,000
29 May 2008Circolo privato 'Astoria'The private club “Astoria” was fined 3,000 EUR by the Garante for failing to provide the required data protection notice to individuals identified through its video surveillance system. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
09 Dec 2010Circolo Privato PirliCircolo Privato Pirli was fined EUR 6,000 by the Garante for failing to provide the required privacy notice to individuals entering the premises. The breach concerned the Italian Data Protection Code and the Garante's video surveillance guidelines.ITGaranteGDPR€6,000
11 Feb 2016Circolo ricreativo D.D. PeckerCircolo ricreativo D.D. Pecker was fined by the Garante for providing inadequate information to data subjects about the processing of their personal data. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
01 Oct 2013CIRCULO GACELA S.L.U.CIRCULO GACELA S.L.U. was fined by the AEPD EUR 1,800 for sending unsolicited commercial emails without prior consent. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,800
09 Oct 2014CISPEL Lombardia Services s.r.l.CISPEL Lombardia Services s.r.l. was fined by the Garante for failing to provide the required data protection information to job applicants. The authority also found that personal data was shared with third parties without the data subjects' consent.ITGaranteGDPR€16,000
04 May 2015CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank. The case concerned the bank’s failure to satisfy the complainant’s right of access to personal data.GRHDPAGDPR€8,000
04 May 2015CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank for unlawful processing of the complainant’s creditworthiness data. The case concerned a breach of the rules governing lawful processing of personal data.GRHDPAGDPR€8,000
31 May 2012CITIBANK ESPAÑA, S.A.CITIBANK ESPAÑA, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails despite a prior request to be removed from its mailing list. The conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,001
22 Apr 2022CÍTRICOS TANTA, S.L.CÍTRICOS TANTA, S.L. was fined by the AEPD for processing personal data without consent. The case involved registering an individual in the Social Security system without their knowledge or agreement.ESAEPDGDPR€5,000
19 Feb 2020CITRICOS Y FRUTALES DEL SURESTE, S.L.CITRICOS Y FRUTALES DEL SURESTE, S.L. was fined by the AEPD 3,000 EUR for installing video surveillance in common areas without approval from the property owners' association and without obtaining explicit consent from affected individuals. The authority found breaches of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€3,000
29 Oct 2020Città Metropolitana di NapoliCittà Metropolitana di Napoli was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found that a disciplinary document was not marked as confidential, which allowed unauthorized access within the administration.ITGaranteGDPR€8,000
26 Sept 2024Città metropolitana di TorinoCittà metropolitana di Torino was fined by the Garante 50,000 EUR for publishing personal data on its institutional website about individuals fined by voluntary ecological guards. The disclosure included names and contact details, breaching data protection rules.ITGaranteGDPR€50,000
07 Apr 2016CityFan s.r.l.CityFan s.r.l. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned the failure to formally designate employees and collaborators as data processors under Article 33 of the Italian Data Protection Code.ITGaranteGDPR€4,000
13 Apr 2023Citynews S.p.A.Citynews S.p.A. was fined EUR 15,000 by the Italian data protection authority, Garante. The case concerned the publication of detailed health information about an individual without consent, in breach of GDPR Article 9 on special categories of personal data.ITGaranteGDPR€15,000
23 Jun 2025City of Dublin Education and Training Board (CDETB)The Irish supervisory authority concluded an inquiry into City of Dublin Education and Training Board (CDETB) and found GDPR infringements linked to a personal data breach. It imposed administrative fines totaling EUR 125,000 and issued a reprimand on 23 June 2025.IEData Protection Commission (Ireland)GDPR€125,000
23 Jun 2025City of Dublin Education and Training Board (CDETB)The Irish DPC imposed a fine of EUR 125,000 on City of Dublin Education and Training Board (CDETB) in inquiry IN-19-7-3. The fine status is collected.IEDPCGDPR€125,000