BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 May 2018 | Bolignari PietroBolignari Pietro, a general practitioner, was fined for failing to implement minimum security measures for personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Mar 2024 | NH HOTEL GROUP S.A.NH HOTEL GROUP S.A. was fined by the AEPD EUR 10,000 for using cookies on its website without obtaining user consent. The authority found this to be a breach of the LSSI rules on cookie consent. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 30 May 2022 | ASOCIACIÓN CONTRA LA CORRUPCION Y EN DEFENSA DE LA ACCIÓN PÚBLICAACODAP was fined EUR 10,000 by the AEPD for publishing complainants’ personal data on its website without anonymization. The authority found this conduct to be contrary to GDPR Article 5(1)(b). | ES | AEPD | GDPR | €10,000 | ↗ |
| 26 Oct 2020 | ***EMPRESA.1.The company was fined by the AEPD 10,000 EUR for sending an email containing personal data of a former employee to a third party without authorization. The case involved a breach of data protection principles and unauthorized disclosure of information. | ES | AEPD | GDPR | €10,000 | ↗ |
| 31 Oct 2022 | B OEThe company was fined for violations related to the operation of a video surveillance system. The authority found non-compliance with data processing principles and insufficient data minimization. | GR | HDPA | GDPR | €10,000 | ↗ |
| 16 Nov 2017 | Terre Etrusche e di Maremma Credito CooperativoThe Garante fined Terre Etrusche e di Maremma Credito Cooperativo EUR 10,000 for inadequate password security measures. The case concerned non-compliance with data protection requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Feb 2026 | GENPACT ROMANIA SRLThe National Supervisory Authority for Personal Data Processing completed an investigation into GENPACT ROMANIA SRL and found a GDPR violation. The company was fined EUR 10,000 due to the severity of the circumstances. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 27 May 2024 | Urban Home Development S.R.L.Urban Home Development S.R.L. was fined 10,000 RON by ANSPDCP. The sanction was imposed for violating the provisions of Law no. 506/2004. | RO | ANSPDCP | ePrivacy | €2,010 | ↗ |
| 13 Sept 2007 | Asl Benevento 1The Garante fined Asl Benevento 1 10,000 EUR for failing to notify data processing activities within the required timeframe. The breach concerned Article 163 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Mar 2023 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for processing personal data for direct marketing without proper consent and transparency. The authority found breaches of lawfulness, fairness, and purpose limitation. | GR | HDPA | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale della provincia di MantovaThe local health authority in Mantua was fined for failing to notify the processing of personal data revealing health status and sexual life. The case concerned obligations under the privacy code. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Jul 2025 | Partidul Alianța pentru Unirea Românilor (AUR)Partidul Alianța pentru Unirea Românilor (AUR) was fined €10,000 for violations related to data security breaches reported by the party. The case concerned shortcomings in the protection and safeguarding of personal data. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 24 Apr 2024 | C.I.EL. S.p.A.C.I.EL. S.p.A. was fined 10,000 EUR by the Garante following a complaint from a former employee. The case concerned violations related to the right of access to training certificates. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Feb 2018 | AVIS ALQUILE UN COCHE S.A.AVIS ALQUILE UN COCHE S.A. was fined by the AEPD 10,000 EUR for improper handling of personal data. This led to the wrongful publication of an individual's details in the Official State Gazette as the responsible party for a traffic violation they did not commit. | ES | AEPD | GDPR | €10,000 | ↗ |
| 09 Mar 2020 | OLIVEROS USTRELL, S.L.OLIVEROS USTRELL, S.L. was fined 10,000 EUR by the AEPD for unauthorized processing of a customer's personal and banking data. The case involved a fraudulent mobile contract and number portability carried out without a valid legal basis. | ES | AEPD | GDPR | €10,000 | ↗ |
| 12 Mar 2015 | Comune di TorittoComune di Toritto was fined by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its website. The conduct breached privacy rules and triggered enforcement action by the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | B.B.B.B.B.B. was fined by the AEPD in the amount of 10,000 EUR for publishing a patient's medical photos on social media without consent. The conduct breached GDPR Articles 6(1) and 9, which govern lawful processing and special categories of personal data. | ES | AEPD | GDPR | €10,000 | ↗ |
| 04 Feb 2016 | Fondazione IRCCS Cà Granda, Ospedale Maggiore PoliclinicoFondazione IRCCS Cà Granda, Ospedale Maggiore Policlinico was fined by the Garante €10,000 for unlawful processing of personal data. The breach involved the incorrect delivery of documents containing health information of third parties. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2026 | Conversion Media S.r.l.Conversion Media S.r.l. was fined EUR 10,000 by the Garante for failing to meet data protection obligations. The case concerned telemarketing activities in which required transparency and information duties toward data subjects were not fulfilled. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Apr 2022 | Tecnomed Trento s.r.l.Tecnomed Trento s.r.l. was fined by the Garante 10,000 EUR for operating a video surveillance system that did not comply with GDPR and the Italian Privacy Code. The authority found breaches of information duties and general data processing principles. | IT | Garante | GDPR | €10,000 | ↗ |