Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 May 2018Bolignari PietroBolignari Pietro, a general practitioner, was fined for failing to implement minimum security measures for personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
22 Mar 2024NH HOTEL GROUP S.A.NH HOTEL GROUP S.A. was fined by the AEPD EUR 10,000 for using cookies on its website without obtaining user consent. The authority found this to be a breach of the LSSI rules on cookie consent.ESAEPDePrivacy€10,000
30 May 2022ASOCIACIÓN CONTRA LA CORRUPCION Y EN DEFENSA DE LA ACCIÓN PÚBLICAACODAP was fined EUR 10,000 by the AEPD for publishing complainants’ personal data on its website without anonymization. The authority found this conduct to be contrary to GDPR Article 5(1)(b).ESAEPDGDPR€10,000
26 Oct 2020***EMPRESA.1.The company was fined by the AEPD 10,000 EUR for sending an email containing personal data of a former employee to a third party without authorization. The case involved a breach of data protection principles and unauthorized disclosure of information.ESAEPDGDPR€10,000
31 Oct 2022B OEThe company was fined for violations related to the operation of a video surveillance system. The authority found non-compliance with data processing principles and insufficient data minimization.GRHDPAGDPR€10,000
16 Nov 2017Terre Etrusche e di Maremma Credito CooperativoThe Garante fined Terre Etrusche e di Maremma Credito Cooperativo EUR 10,000 for inadequate password security measures. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€10,000
04 Feb 2026GENPACT ROMANIA SRLThe National Supervisory Authority for Personal Data Processing completed an investigation into GENPACT ROMANIA SRL and found a GDPR violation. The company was fined EUR 10,000 due to the severity of the circumstances.ROANSPDCPGDPR€10,000
27 May 2024Urban Home Development S.R.L.Urban Home Development S.R.L. was fined 10,000 RON by ANSPDCP. The sanction was imposed for violating the provisions of Law no. 506/2004.ROANSPDCPePrivacy€2,010
13 Sept 2007Asl Benevento 1The Garante fined Asl Benevento 1 10,000 EUR for failing to notify data processing activities within the required timeframe. The breach concerned Article 163 of the Italian Data Protection Code.ITGaranteGDPR€10,000
30 Mar 2023Vodafone-PanafonVodafone-Panafon was fined by the HDPA for processing personal data for direct marketing without proper consent and transparency. The authority found breaches of lawfulness, fairness, and purpose limitation.GRHDPAGDPR€10,000
14 Sept 2006Azienda sanitaria locale della provincia di MantovaThe local health authority in Mantua was fined for failing to notify the processing of personal data revealing health status and sexual life. The case concerned obligations under the privacy code.ITGaranteGDPR€10,000
07 Jul 2025Partidul Alianța pentru Unirea Românilor (AUR)Partidul Alianța pentru Unirea Românilor (AUR) was fined €10,000 for violations related to data security breaches reported by the party. The case concerned shortcomings in the protection and safeguarding of personal data.ROANSPDCPGDPR€10,000
24 Apr 2024C.I.EL. S.p.A.C.I.EL. S.p.A. was fined 10,000 EUR by the Garante following a complaint from a former employee. The case concerned violations related to the right of access to training certificates.ITGaranteGDPR€10,000
19 Feb 2018AVIS ALQUILE UN COCHE S.A.AVIS ALQUILE UN COCHE S.A. was fined by the AEPD 10,000 EUR for improper handling of personal data. This led to the wrongful publication of an individual's details in the Official State Gazette as the responsible party for a traffic violation they did not commit.ESAEPDGDPR€10,000
09 Mar 2020OLIVEROS USTRELL, S.L.OLIVEROS USTRELL, S.L. was fined 10,000 EUR by the AEPD for unauthorized processing of a customer's personal and banking data. The case involved a fraudulent mobile contract and number portability carried out without a valid legal basis.ESAEPDGDPR€10,000
12 Mar 2015Comune di TorittoComune di Toritto was fined by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its website. The conduct breached privacy rules and triggered enforcement action by the supervisory authority.ITGaranteGDPR€10,000
01 Jan 2024B.B.B.B.B.B. was fined by the AEPD in the amount of 10,000 EUR for publishing a patient's medical photos on social media without consent. The conduct breached GDPR Articles 6(1) and 9, which govern lawful processing and special categories of personal data.ESAEPDGDPR€10,000
04 Feb 2016Fondazione IRCCS Cà Granda, Ospedale Maggiore PoliclinicoFondazione IRCCS Cà Granda, Ospedale Maggiore Policlinico was fined by the Garante €10,000 for unlawful processing of personal data. The breach involved the incorrect delivery of documents containing health information of third parties.ITGaranteGDPR€10,000
12 Feb 2026Conversion Media S.r.l.Conversion Media S.r.l. was fined EUR 10,000 by the Garante for failing to meet data protection obligations. The case concerned telemarketing activities in which required transparency and information duties toward data subjects were not fulfilled.ITGaranteGDPR€10,000
07 Apr 2022Tecnomed Trento s.r.l.Tecnomed Trento s.r.l. was fined by the Garante 10,000 EUR for operating a video surveillance system that did not comply with GDPR and the Italian Privacy Code. The authority found breaches of information duties and general data processing principles.ITGaranteGDPR€10,000