Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Sept 2022CITY OF SOUND 2010, S.L.CITY OF SOUND 2010, S.L. was fined EUR 800 by the AEPD for sending at least one commercial SMS to the complainant after the complainant had requested removal from the database. The authority found this to be a breach of Article 21 of the LSSI on unsolicited marketing communications.ESAEPDePrivacy€800
01 Jan 2023CIUDAD RESIDENCIAL H.H.H.CIUDAD RESIDENCIAL H.H.H. was fined by the AEPD EUR 2,000 for breaching the data minimization principle. The case concerned capturing and storing photographs of residents collecting packages without informing them about this processing.ESAEPDGDPR€2,000
12 May 2022CIUDAUTO, S.L.CIUDAUTO, S.L. was fined by the AEPD EUR 1,000 for continuing to send advertising emails despite a request to unsubscribe. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,000
22 Oct 2013CIVESA 2005 SERVICIOS S LCIVESA 2005 SERVICIOS S L was fined EUR 600 by the AEPD for sending commercial emails to a user who had previously opted out. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€600
12 May 2022CivilstyrelsenThe Danish DPA reported Civilstyrelsen to the police and recommended a fine for failing to implement appropriate security measures and for not reporting a data breach. The case ended with a fine notice of 100,000 DKK.DKDatatilsynetGDPR€13,439
06 Apr 2017CLARIMARKET S.L.CLARIMARKET S.L. was fined EUR 600 by the AEPD. The sanction concerned sending unsolicited commercial emails in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
30 Oct 2015CLASE EJECUTIVA, S.L.CLASE EJECUTIVA, S.L. was fined by the AEPD EUR 400 for sending commercial emails without prior consent from recipients. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€400
13 Feb 2025Claudio BattagliaDr. Claudio Battaglia, an oncologist, was fined for using patient data for electoral propaganda without consent. The case indicates a breach of GDPR principles on lawfulness and purpose limitation.ITGaranteGDPR€10,000
24 Oct 2013Claudio ContiClaudio Conti was fined EUR 26,000 by the Garante for activating 100 phone cards in the name of an unaware third party. Required information was not provided and consent was not obtained, constituting a data protection breach.ITGaranteGDPR€26,000
15 Apr 2021Clear Channel Italia S.p.A.Clear Channel Italia S.p.A. was fined by the Garante EUR 75,000 for conducting intrusive checks on employees’ devices without a proper legal basis. The authority found breaches of data minimization and proportionality principles.ITGaranteGDPR€75,000
03 Sept 2024Clearview AI Inc.Clearview AI Inc. was fined by the Dutch data protection authority AP for processing personal data without a legal basis, including biometric data. The authority also cited inadequate notice to data subjects, failure to respond to access requests, and failure to appoint an EU representative.NLAPGDPR€30,500,000
12 Jul 2024CLIDEA DESARROLLO, S.A.CLIDEA DESARROLLO, S.A. was fined by the AEPD 3,000 EUR for sending an email to 349 recipients without using the BCC field. This exposed the personal email addresses of all recipients.ESAEPDGDPR€3,000
15 Mar 2022CLÍNICA DENTAL SAN FRANCISCO, S.L.The entity continued sending advertising messages to a former patient despite multiple requests to unsubscribe. AEPD found this to be a breach of data protection rules and imposed a EUR 7,000 fine.ESAEPDePrivacy€7,000
15 Oct 2010Clinica Luccioni S.p.a.Clinica Luccioni S.p.a. was fined by the Garante for failing to timely notify the authority of personal data processing activities required under the Italian Data Protection Code. The case concerned a breach of the notification obligation to the supervisory authority.ITGaranteGDPR€10,000
30 Oct 2023CLÍNICA PARÍS, S.L.CLÍNICA PARÍS, S.L. was fined 1,000 EUR by the AEPD for failing to properly handle a data subject access request. The authority found a breach of GDPR obligations.ESAEPDGDPR€1,000
10 Jul 2014Clinica Siligato s.r.l.Clinica Siligato s.r.l. was fined for failing to notify the Garante of certain processing activities involving health data. The case concerned data used to detect infectious diseases and HIV status, which had to be reported under the Italian Data Protection Code.ITGaranteGDPR€8,000
05 Dec 2024CLINIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on CLINIQUE (procédure simplifiée). The case concerns a regulatory breach that resulted in an administrative sanction.FRCNILGDPR€15,000
25 May 2022CLINT IS GOOD DIGITAL CREATIVE TEAM, S.L.CLINT IS GOOD DIGITAL CREATIVE TEAM, S.L. was fined 500 EUR by the AEPD. The case concerned sending unsolicited commercial communications by email without consent, in breach of Article 21 of the LSSI.ESAEPDePrivacy€500
21 Jul 2022Clio s.r.l.Clio s.r.l. was fined by the Italian Garante in the amount of 10,000 EUR for violations related to personal data processing. The case involved inadequate protection of whistleblower identities, in breach of the GDPR and national privacy code provisions.ITGaranteGDPR€10,000
26 Jul 2017Cloud Europa s.r.l.Cloud Europa s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unsolicited promotional phone calls, in breach of data protection rules.ITGaranteGDPR€40,000