BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Apr 2019 | Bill Size s.r.l.Bill Size s.r.l. was fined by the Garante in the amount of EUR 16,000 for registering phone cards to individuals without their consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 31 Jan 2019 | Azienda Sanitaria Locale di AlessandriaAzienda Sanitaria Locale di Alessandria was fined by the Garante 16,000 EUR for processing personal data through the health dossier without full compliance with data protection rules. The case concerned improper handling of sensitive data in a medical system. | IT | Garante | GDPR | €16,000 | ↗ |
| 20 Jun 2013 | Terme di Agnano s.p.a.Terme di Agnano s.p.a. was fined EUR 16,000 by the Garante for processing personal and sensitive data of individuals undergoing thermal treatments without the required notice and consent. The authority also found that personal data of job applicants were processed without providing the mandatory information notice. | IT | Garante | GDPR | €16,000 | ↗ |
| 14 Feb 2019 | Ordinanza ingiunzione - 14 febbraio 2019 [9106367]A doctor used the email addresses of former patients to send electoral propaganda without first informing them or obtaining consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 04 May 2017 | Starweb s.r.l.Starweb s.r.l. was fined €16,000 by the Garante for making unsolicited promotional calls. The authority found that the company failed to provide the required information notice and did not obtain consent from the contacted individuals. | IT | Garante | GDPR | €16,000 | ↗ |
| 06 Jun 2022 | Dane anonimowe (C.)UODO imposed an administrative fine of PLN 15,994 on Anonymous Data (C.). The case concerned the failure to report a personal data breach involving the loss of an employee’s employment certificate. | PL | UODO | GDPR | €3,491 | ↗ |
| 26 Jan 2023 | Политическа партия ******The political party unlawfully processed personal data by including individuals in a list supporting its election registration without their consent. The authority found breaches of GDPR Articles 5, 6, and 24. | BG | CPDP | GDPR | €7,823 | ↗ |
| 11 Sept 2025 | ISV Group SrlsISV Group Srls was fined €15,000 by the Garante for sending unsolicited promotional emails without consent. The authority also found that the company failed to properly control its partner Ismax, which carried out unlawful data processing activities. | IT | Garante | GDPR | €15,000 | ↗ |
| 19 May 2021 | CP&A B.V.CP&A B.V. was fined by the AP in the amount of EUR 15,000 for processing employees' health data without a legal basis. The authority also found that adequate security measures were not implemented for this processing. | NL | AP | GDPR | €15,000 | ↗ |
| 13 Apr 2023 | Citynews S.p.A.Citynews S.p.A. was fined EUR 15,000 by the Italian data protection authority, Garante. The case concerned the publication of detailed health information about an individual without consent, in breach of GDPR Article 9 on special categories of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 25 Apr 2024 | SOCIETE EXPLOITANT DES MAGASINS DE CHAUSSURES ET D'HABILLEMENT DE SPORT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE EXPLOITANT DES MAGASINS DE CHAUSSURES ET D'HABILLEMENT DE SPORT. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €15,000 | ↗ |
| 20 Dec 2019 | GESTHOTEL ACTIVOS BALAGARES S.L.GESTHOTEL ACTIVOS BALAGARES S.L. was fined by the AEPD 15,000 EUR for disclosing special categories of personal data, including medical information. The authority found a breach of the integrity and confidentiality principle under GDPR Article 5(1)(f). | ES | AEPD | GDPR | €15,000 | ↗ |
| 24 Jan 2024 | CAIXA RURAL LA VALL SAN ISIDRO, S.C.C.CAIXA RURAL LA VALL SAN ISIDRO was fined by the AEPD 15,000 EUR for a personal data breach. The incident allowed unauthorized third-party access and affected the confidentiality and integrity of the data. | ES | AEPD | GDPR | €15,000 | ↗ |
| 26 Sept 2024 | SOCIETE PROPOSANT DES SERVICES DE CONSEIL EN SYSTÈMES ET LOGICIELS INFORMATIQUES, L'EDITION ET LA REALISATION DE LOGICIELS (procédure simplifiée)CNIL imposed an administrative fine of 15,000 EUR and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €15,000 | ↗ |
| 20 Jan 2025 | Vodafone Romania S.A.Vodafone Romania S.A. was fined EUR 15,000 by ANSPDCP for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 23 Mar 2023 | Dedalus Italia S.p.a.Dedalus Italia S.p.a. was fined EUR 15,000 by the Garante for failing to implement adequate measures to protect personal data. The authority found a breach of Article 32 GDPR on security of processing. | IT | Garante | GDPR | €15,000 | ↗ |
| 10 Oct 2024 | Dane anonimowe (X w K.)The UODO imposed an administrative fine of PLN 15,000 on the entity identified as Anonymous data (X in K.). The authority found breaches of data protection principles, including integrity and confidentiality, accountability, data protection by design, processor obligations, and security measures. | PL | UODO | GDPR | €3,485 | ↗ |
| 05 Nov 2015 | VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD for sending unsolicited commercial emails despite the recipient’s repeated attempts to unsubscribe. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 12 Sept 2024 | Medic4All Italia S.r.l.Medic4All Italia S.r.l. was fined by the Garante 15,000 EUR for failing to respond to a data subject access request. The conduct breached Article 15 GDPR, which requires controllers to provide access to personal data upon request. | IT | Garante | GDPR | €15,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL GRANADA, S.C.C.CAJA RURAL GRANADA was fined by the AEPD EUR 15,000 for breaching data protection principles. The authority found that unauthorized access to personal data occurred due to a security incident, affecting confidentiality and integrity. | ES | AEPD | GDPR | €15,000 | ↗ |