BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Feb 2017 | Geoanalysis S.A.Geoanalysis S.A. was fined EUR 10,000 by the HDPA for improper installation and operation of a video surveillance system. The authority found data protection breaches, including failure to notify the authority and inadequate employee information. | GR | HDPA | GDPR | €10,000 | ↗ |
| 21 Apr 2016 | Comune di PozzuoliComune di Pozzuoli was fined EUR 10,000 by the Garante for publishing a minor’s personal data, including health information, on its institutional website. The conduct breached privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Nov 2016 | Minerv@ s.r.l.Minerv@ s.r.l. was fined by the Garante 10,000 EUR for sending promotional emails to a complainant after they objected and requested deletion of their data. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Sept 2007 | Asl Salerno 2Asl Salerno 2 was fined EUR 10,000 by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Apr 2018 | Azienda Ospedaliera Sant’Andrea di RomaAzienda Ospedaliera Sant’Andrea di Roma was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate individuals responsible for data processing, in breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jun 2018 | Acentro s.r.l.Acentro s.r.l. was fined EUR 10,000 by the Garante for failing to appoint data processors and provide them with the necessary instructions. The case concerns non-compliance with data protection obligations. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Oct 2022 | Limit Call S.r.l.s.Limit Call S.r.l.s. was fined by the Garante in the amount of 10,000 EUR for making numerous unsolicited phone calls. The authority found that this conduct breached Article 5 of the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Oct 2022 | Codess Sociale, Soc. Coop. socialeCodess Sociale, Soc. Coop. sociale was fined EUR 10,000 by the Garante. The authority found that the company failed to respond to a data subject's request to exercise GDPR rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 May 2017 | Brennercom s.p.a.Brennercom s.p.a. was fined 10,000 EUR by the Garante for inadequate password security measures. The authority found that the company's practices breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Aug 2025 | APARELLS ORTOPEDICS CURTO, S.L.APARELLS ORTOPEDICS CURTO, S.L. did not provide complete personal data and medical records in response to an access request. The AEPD found this to be a breach of data protection rules and imposed a fine of 10,000 EUR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 07 Apr 2021 | Anonymizováno (ÚOOÚ UOOU-03058/20-30)The entity did not respond to a data subject's request to delete personal data from a publicly accessible auction notice. The authority found this to be a breach of GDPR rights and imposed a monetary penalty. | CZ | UOOU | GDPR | €386 | ↗ |
| 03 Apr 2025 | SOCIETE DE COURTAGE EN TRAVAUX, CONSULTING EN BATIMENT ET TRAVAUX PUBLICS, ACHAT ET REVENTE DE MATERIEL, TRANSACTION IMMOBILIERE ET MAITRISE D'ŒUVRE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 20 Oct 2022 | Promofarma Sviluppo s.r.l.Promofarma Sviluppo s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate data security measures and for lacking transparency in the authentication process on vaccine booking portals. These shortcomings made the system vulnerable to fraudulent access and misuse. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Mar 2015 | Comune di SortinoComune di Sortino was fined for unlawfully publishing personal data revealing health information on its institutional website. The case concerned a breach of data protection rules and the improper disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2016 | Agenzia di promozione economica della ToscanaAgenzia di promozione economica della Toscana was fined 10,000 EUR by the Garante for publishing lists of disabled candidates admitted to competitive exams on its institutional websites. The authority found that this disclosure breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Mar 2025 | Οργανισμός Χρηματοδοτήσεως ΣτέγηςThe Housing Finance Corporation was fined by the CyDPC in the amount of €10,000 for retaining personal data beyond the legal retention period. The authority found this breached GDPR storage limitation and data accuracy requirements. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 31 Jan 2024 | Sectorul 1 al Municipiului BucureștiThe National Supervisory Authority for Personal Data Processing fined Sectorul 1 of Bucharest Municipality for GDPR violations. The entity failed to demonstrate compliance with a remediation measure, which formed the basis for the sanction. | RO | ANSPDCP | GDPR | €2,010 | ↗ |
| 18 May 2017 | Terrecablate reti e servizi s.r.l.Terrecablate reti e servizi s.r.l. was fined by the Garante €10,000 for inadequate security measures. The violation concerned weak password authentication on servers storing telephone traffic data. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 May 2015 | Pelamatti GiacomoPelamatti Giacomo was fined by the Garante EUR 10,000 for activating phone cards in the names of individuals without their knowledge. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 May 2024 | Azzurro Club Hotels S.r.l.Azzurro Club Hotels S.r.l. was fined by the Garante 10,000 EUR for sending promotional emails without consent. The company also failed to respond to a data subject’s request for information under Article 15 GDPR. | IT | Garante | GDPR | €10,000 | ↗ |