BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Sept 2022 | CITY OF SOUND 2010, S.L.CITY OF SOUND 2010, S.L. was fined EUR 800 by the AEPD for sending at least one commercial SMS to the complainant after the complainant had requested removal from the database. The authority found this to be a breach of Article 21 of the LSSI on unsolicited marketing communications. | ES | AEPD | ePrivacy | €800 | ↗ |
| 01 Jan 2023 | CIUDAD RESIDENCIAL H.H.H.CIUDAD RESIDENCIAL H.H.H. was fined by the AEPD EUR 2,000 for breaching the data minimization principle. The case concerned capturing and storing photographs of residents collecting packages without informing them about this processing. | ES | AEPD | GDPR | €2,000 | ↗ |
| 12 May 2022 | CIUDAUTO, S.L.CIUDAUTO, S.L. was fined by the AEPD EUR 1,000 for continuing to send advertising emails despite a request to unsubscribe. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 22 Oct 2013 | CIVESA 2005 SERVICIOS S LCIVESA 2005 SERVICIOS S L was fined EUR 600 by the AEPD for sending commercial emails to a user who had previously opted out. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 12 May 2022 | CivilstyrelsenThe Danish DPA reported Civilstyrelsen to the police and recommended a fine for failing to implement appropriate security measures and for not reporting a data breach. The case ended with a fine notice of 100,000 DKK. | DK | Datatilsynet | GDPR | €13,439 | ↗ |
| 06 Apr 2017 | CLARIMARKET S.L.CLARIMARKET S.L. was fined EUR 600 by the AEPD. The sanction concerned sending unsolicited commercial emails in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 30 Oct 2015 | CLASE EJECUTIVA, S.L.CLASE EJECUTIVA, S.L. was fined by the AEPD EUR 400 for sending commercial emails without prior consent from recipients. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €400 | ↗ |
| 13 Feb 2025 | Claudio BattagliaDr. Claudio Battaglia, an oncologist, was fined for using patient data for electoral propaganda without consent. The case indicates a breach of GDPR principles on lawfulness and purpose limitation. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Oct 2013 | Claudio ContiClaudio Conti was fined EUR 26,000 by the Garante for activating 100 phone cards in the name of an unaware third party. Required information was not provided and consent was not obtained, constituting a data protection breach. | IT | Garante | GDPR | €26,000 | ↗ |
| 15 Apr 2021 | Clear Channel Italia S.p.A.Clear Channel Italia S.p.A. was fined by the Garante EUR 75,000 for conducting intrusive checks on employees’ devices without a proper legal basis. The authority found breaches of data minimization and proportionality principles. | IT | Garante | GDPR | €75,000 | ↗ |
| 03 Sept 2024 | Clearview AI Inc.Clearview AI Inc. was fined by the Dutch data protection authority AP for processing personal data without a legal basis, including biometric data. The authority also cited inadequate notice to data subjects, failure to respond to access requests, and failure to appoint an EU representative. | NL | AP | GDPR | €30,500,000 | ↗ |
| 12 Jul 2024 | CLIDEA DESARROLLO, S.A.CLIDEA DESARROLLO, S.A. was fined by the AEPD 3,000 EUR for sending an email to 349 recipients without using the BCC field. This exposed the personal email addresses of all recipients. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Mar 2022 | CLÍNICA DENTAL SAN FRANCISCO, S.L.The entity continued sending advertising messages to a former patient despite multiple requests to unsubscribe. AEPD found this to be a breach of data protection rules and imposed a EUR 7,000 fine. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 15 Oct 2010 | Clinica Luccioni S.p.a.Clinica Luccioni S.p.a. was fined by the Garante for failing to timely notify the authority of personal data processing activities required under the Italian Data Protection Code. The case concerned a breach of the notification obligation to the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Oct 2023 | CLÍNICA PARÍS, S.L.CLÍNICA PARÍS, S.L. was fined 1,000 EUR by the AEPD for failing to properly handle a data subject access request. The authority found a breach of GDPR obligations. | ES | AEPD | GDPR | €1,000 | ↗ |
| 10 Jul 2014 | Clinica Siligato s.r.l.Clinica Siligato s.r.l. was fined for failing to notify the Garante of certain processing activities involving health data. The case concerned data used to detect infectious diseases and HIV status, which had to be reported under the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 05 Dec 2024 | CLINIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on CLINIQUE (procédure simplifiée). The case concerns a regulatory breach that resulted in an administrative sanction. | FR | CNIL | GDPR | €15,000 | ↗ |
| 25 May 2022 | CLINT IS GOOD DIGITAL CREATIVE TEAM, S.L.CLINT IS GOOD DIGITAL CREATIVE TEAM, S.L. was fined 500 EUR by the AEPD. The case concerned sending unsolicited commercial communications by email without consent, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €500 | ↗ |
| 21 Jul 2022 | Clio s.r.l.Clio s.r.l. was fined by the Italian Garante in the amount of 10,000 EUR for violations related to personal data processing. The case involved inadequate protection of whistleblower identities, in breach of the GDPR and national privacy code provisions. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Jul 2017 | Cloud Europa s.r.l.Cloud Europa s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unsolicited promotional phone calls, in breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |