BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2014 | COMERCIAL POLINDUS 21, SLUCOMERCIAL POLINDUS 21, SLU was fined by the AEPD EUR 1,200 for sending an SMS to a number listed on the Robinson List. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 01 Jan 2019 | COMERCIAL VIGOBRANDY, S.L.COMERCIAL VIGOBRANDY, S.L. was fined by the AEPD 1,500 EUR for installing a video surveillance camera without the required informational sign inside the premises. The case concerned a breach of data protection rules and the duty to properly inform individuals being recorded. | ES | AEPD | GDPR | €1,500 | ↗ |
| 27 Dec 2023 | COMITE SOCIAL ECONOMIQUE D'ENTREPRISES (procédure simplifiée)The CNIL imposed an administrative fine of 10,000 EUR on COMITE SOCIAL ECONOMIQUE D'ENTREPRISES under a simplified procedure. The case concerns a confirmed regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €10,000 | ↗ |
| 04 Apr 2024 | COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATIONCNIL imposed an administrative fine of EUR 525,000 on COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATION. The case concerns identified breaches of rules supervised by CNIL. | FR | CNIL | GDPR | €525,000 | ↗ |
| 28 Sept 2023 | COMMERCE INTERENTREPRISES DE PRODUITS SURGELES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on COMMERCE INTERENTREPRISES DE PRODUITS SURGELES under a simplified procedure. The case concerns a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €20,000 | ↗ |
| 11 Jan 2023 | Commify Italia S.r.l.Commify Italia S.r.l. was fined by the Garante 80,000 EUR for violations related to the processing of personal data through its Skebby platform. The case involved inadequate data protection measures and unauthorized access that led to phishing attacks. | IT | Garante | GDPR | €80,000 | ↗ |
| 12 Dec 2023 | COMMUNECNIL imposed a EUR 5,000 fine on COMMUNE and issued an injunction. The case concerns a regulatory breach requiring corrective action. | FR | CNIL | GDPR | €5,000 | ↗ |
| 22 Jul 2024 | COMMUNECNIL imposed EUR 6,900 on COMMUNE as an astreinte liquidation. The case concerns enforcement of a prior obligation subject to supervisory authority action. | FR | CNIL | GDPR | €6,900 | ↗ |
| 15 Nov 2023 | COMMUNE (procédure simplifiée)CNIL imposed a EUR 6,000 fine on COMMUNE under a simplified procedure. The case concerns an administrative sanction decision. | FR | CNIL | GDPR | €6,000 | ↗ |
| 08 Feb 2023 | COMMUNE (procédure simplifiée)CNIL imposed a EUR 5,000 fine on COMMUNE under a simplified procedure and issued an injunction. The case concerned a confirmed breach requiring corrective action. | FR | CNIL | GDPR | €5,000 | ↗ |
| 13 Sept 2024 | COMMUNE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on COMMUNE (procédure simplifiée) and issued an injunction. The decision concerns a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €20,000 | ↗ |
| 11 Sept 2025 | COMMUNE (procédure simplifiée)CNIL imposed an administrative fine of EUR 10,000 on COMMUNE under a simplified procedure and issued a warning. The case concerns a breach of rules requiring supervisory intervention. | FR | CNIL | GDPR | €10,000 | ↗ |
| 30 Oct 2013 | Compagnia Assicuratrice Linear s.p.a.Compagnia Assicuratrice Linear s.p.a. was fined by the Garante 80,000 EUR for collecting personal data without specific consent for purposes beyond registration services. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €80,000 | ↗ |
| 23 Apr 2015 | Compagnia dei Telefoni s.r.l.Compagnia dei Telefoni s.r.l. was fined by the Garante 80,000 EUR for conducting telemarketing through automated calls without prior informed consent. The company also made promotional calls while concealing the caller's identity. | IT | Garante | GDPR | €80,000 | ↗ |
| 05 Jul 2017 | Compagnia Generale Trattori S.p.A.Compagnia Generale Trattori S.p.A. was fined by the Garante EUR 20,000 for using a GPS/GPRS system to monitor employee activities without proper notification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 08 Dec 2025 | Compania de Apă Oltenia S.A.The company was fined EUR 1,000 by ANSPDCP after an employee disclosed personal data on a social network. The case was initiated following a complaint from the data subject. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 12 Jun 2026 | Compania Națională Poșta RomânăCompania Națională Poșta Română was fined by ANSPDCP in the amount of EUR 5,000 for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 07 Nov 2022 | Compania Națională Poșta Română SAIn October 2022, ANSPDCP completed an investigation into Compania Națională Poșta Română SA and found a breach of GDPR provisions. The company was fined EUR 2,000 following a data security incident reported by a data operator. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 16 May 2023 | Compania Națională Poșta Română S.A.Compania Națională Poșta Română S.A. was fined EUR 5,000 by ANSPDCP for GDPR violations related to the completion of Form 230. The case arose from complaints, and the authority instructed the company to ensure personal data processing complies with processing principles. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 18 Jul 2023 | Compara Facile S.r.l.Compara Facile S.r.l. was fined EUR 40,000 by the Garante for making unsolicited marketing calls to a number listed in the Public Register of Oppositions without prior informed consent. The authority also found that the company failed to respond to data subject rights requests, indicating non-compliance with data protection obligations. | IT | Garante | GDPR | €40,000 | ↗ |