BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 May 2023 | COLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRECOLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRE was fined by the AEPD for failing to implement appropriate technical and organizational measures to ensure data security. The deficiency resulted in a breach involving minors’ data stored in cloud services. | ES | AEPD | GDPR | €5,000 | ↗ |
| 10 Apr 2023 | COLEGIO OFICIAL DE ARQUITECTOS DE GRANADACOLEGIO OFICIAL DE ARQUITECTOS DE GRANADA was fined €14,000 by the AEPD for data protection breaches. The authority found a conflict of interest in the appointment of the Data Protection Officer, missing required information on data processing in complaint forms, and the use of third-party cookies without user consent. | ES | AEPD | ePrivacy | €14,000 | ↗ |
| 29 Jan 2022 | COLEGIO VILLAEUROPA, S.C.L.The school was fined by the AEPD in the amount of 5,000 EUR for recording a child's image without parental consent. The authority also found that the school failed to provide adequate information about personal data processing. | ES | AEPD | GDPR | €5,000 | ↗ |
| 22 Jun 2023 | COLEGIO VIRGEN DE EUROPA, S.L.The school processed and published images of a 3-year-old child on Facebook and WhatsApp without parental consent. This disregarded the parents’ explicit refusal and led to a fine imposed by the AEPD. | ES | AEPD | GDPR | €15,000 | ↗ |
| 13 Sept 2017 | Coleman s.p.a.Coleman s.p.a. was fined by the Garante 20,000 EUR for failing to implement minimum security measures for online booking requests. This allowed access to personal data without authentication. | IT | Garante | GDPR | €20,000 | ↗ |
| 04 Nov 2025 | COLLECTIVITE TERRITORIALE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on COLLECTIVITE TERRITORIALE under a simplified procedure. The decision concerns a breach of data protection rules. | FR | CNIL | GDPR | €4,000 | ↗ |
| 18 Nov 2015 | Collegio professionale dei periti industriali di Roma e provinciaCollegio professionale dei periti industriali di Roma e provincia was fined 10,000 EUR by the Garante for unlawfully publishing judicial data on its website. The publication occurred during an election campaign. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2014 | Colligo s.r.lColligo s.r.l was fined EUR 40,000 by the Garante for making promotional phone calls while disguising or hiding the caller's identity. The authority found this conduct breached the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 05 Aug 2022 | Colosseo S.r.l.Colosseo S.r.l. was fined EUR 1,000 by the Garante for sending unsolicited promotional emails without prior recipient consent. The authority found this breached GDPR rules on lawful processing and consent. | IT | Garante | GDPR | €1,000 | ↗ |
| 15 Apr 2025 | COLPER BUSINESS 2020 S.L.COLPER BUSINESS 2020 S.L. was fined by the AEPD EUR 20,000 for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 11 Feb 2021 | Comando generale del Corpo delle Capitanerie di porto-Guardia CostieraThe Garante imposed a €5,000 fine on the Comando generale del Corpo delle Capitanerie di porto-Guardia Costiera for inadequate data protection measures. The breach resulted in the unlawful disclosure of personal data on its website. | IT | Garante | GDPR | €5,000 | ↗ |
| 08 Jul 2024 | COMERCIAL GIRONA DE LLIBRES, S.L.COMERCIAL GIRONA DE LLIBRES, S.L. was fined by the AEPD 20,000 EUR for inadequate security measures. The authority cited, among other issues, the sending of credentials by email, which breached Article 32 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 14 Feb 2022 | COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company sent a customer's electricity supply contract containing personal data to an incorrect address. This breached data protection principles and led to a fine by the AEPD. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Jan 2024 | COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company was fined EUR 80,000 by the AEPD for processing a gas contract without the complainant's consent. It used personal data without authorization, which constitutes a breach of data protection law. | ES | AEPD | GDPR | €80,000 | ↗ |
| 01 Jan 2014 | COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD EUR 3,000 for sending unsolicited spam messages without providing an opt-out mechanism. The conduct breached Article 21 of the LSSI and failed to meet basic requirements for marketing communications. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 30 Apr 2014 | COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD 3,000 EUR for sending unsolicited and misleading commercial messages by electronic means. The authority found a breach of Article 21 of the LSSI on marketing communications without prior consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jan 2014 | COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD €3,000 for sending unsolicited commercial messages by electronic means. The conduct breached Article 21 of the LSSI, which prohibits such communications without prior consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jan 2013 | COMERCIAL POLINDUS 21, S.L.COMERCIAL POLINDUS 21, S.L. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited SMS messages. The case concerned Article 21 of the LSSI, which governs commercial communications sent without prior consent. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 22 May 2014 | COMERCIAL POLINDUS 21, S.L.COMERCIAL POLINDUS 21, S.L. was fined by the AEPD 9,000 EUR for sending unsolicited commercial SMS messages. The authority found that recipients were not given an opt-out option, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €9,000 | ↗ |
| 13 Feb 2015 | COMERCIAL POLINDUS, 21, S.L.COMERCIAL POLINDUS, 21, S.L. was fined by the AEPD 3,000 EUR for sending unsolicited commercial communications. The case concerned Article 21 of the LSSI, which prohibits such messages without prior recipient consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |