Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Dec 2008Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c.Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c. was fined for failing to notify the Garante of personal data processing activities within the required timeframe. The case concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
24 Mar 2023NATURGESTYGAS, S.L.NATURGESTYGAS, S.L. was fined EUR 10,000 by the AEPD for processing personal data without a legal basis. The company charged a customer despite having no contract or consent, which breached the legality requirement for processing.ESAEPDGDPR€10,000
14 Jan 2016Comune di Santa FlaviaThe Garante fined Comune di Santa Flavia €10,000 for unlawfully publishing documents on its website that disclosed individuals' health data. The case involved the disclosure of sensitive personal data without a lawful basis.ITGaranteGDPR€10,000
30 Jul 2015Comune di GallipoliThe Municipality of Gallipoli was fined by the Garante for unlawfully publishing personal data revealing health status on its institutional website. The conduct breached data protection rules.ITGaranteGDPR€10,000
04 Apr 2022Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 10,000 EUR for breaching the principle of data confidentiality. The bank sent debit card transaction notifications to incorrect email addresses, failed to notify the authority of the breach, and did not take timely corrective action.GRHDPAGDPR€10,000
06 Jul 2023AcegasApsAmga S.p.A.AcegasApsAmga S.p.A. was fined €10,000 by the Italian supervisory authority, Garante. The sanction concerned the company’s failure to respond to a data subject’s request for access to personal data, in breach of GDPR Article 15.ITGaranteGDPR€10,000
22 Jul 2021Università degli Studi di Milano-BicoccaUniversità degli Studi di Milano-Bicocca was fined EUR 10,000 by the Garante for data protection violations linked to the publication of personal data on its institutional website. The case concerned the disclosure of information on the university’s website, which breached data processing rules.ITGaranteGDPR€10,000
02 Feb 2022Anonymisé (CNPD decision-01-fr-2022)The entity breached GDPR requirements on data minimization, retention limitation, and the duty to inform data subjects, including employees and third parties, about processing activities. CNPD imposed a fine of EUR 10,000.LUCNPDGDPR€10,000
27 Jan 2021Azienda Ospedaliero Universitaria SeneseAzienda Ospedaliero Universitaria Senese was fined by the Garante in the amount of 10,000 EUR for breaches of data protection rules in the healthcare sector. The case concerned the processing of sensitive personal data in a medical setting.ITGaranteGDPR€10,000
23 Nov 2023Alpha BankAlpha Bank was fined for failing to satisfy the complainant’s request for access to personal data. The authority found breaches of GDPR Articles 15 and 5.GRHDPAGDPR€10,000
24 Jun 2020Azienda Sanitaria Universitaria Giuliano IsontinaAzienda Sanitaria Universitaria Giuliano Isontina was fined by the Garante for unlawfully communicating health data without an adequate legal basis. The conduct breached Article 20 of the Italian Privacy Code.ITGaranteGDPR€10,000
10 Nov 2010Fitness Solution società sportiva dilettantistica s.r.l.Fitness Solution was fined EUR 10,000 by the Garante. The authority found that biometric personal data were processed without proper consent and retained longer than necessary.ITGaranteGDPR€10,000
01 Sept 2025La Fântâna S.R.L.In July 2025, ANSPDCP completed an investigation into La Fântâna S.R.L. and found a breach of GDPR provisions. As a result, the operator was fined 10,000 EUR.ROANSPDCPGDPR€10,000
23 Jan 2008Deas Desideri e associati s.r.l.Deas Desideri e associati s.r.l. was fined €10,000 by the Garante for failing to notify the processing of sensitive personal data within the required timeframe. The authority found a breach of Article 163 of the Italian Data Protection Code.ITGaranteGDPR€10,000
01 Jan 2016BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 10,000 EUR for failing to provide the required cookie information and for not obtaining consent on its website. The case concerns breaches of notice and consent obligations for website cookies.ESAEPDePrivacy€10,000
01 Jan 2020PERSONAL MARK, S.L.PERSONAL MARK, S.L. was fined by the AEPD 10,000 EUR for failing to diligently delete personal data from its databases despite the complainant’s requests. The case indicates inadequate handling of data erasure obligations.ESAEPDGDPR€10,000
11 Jan 2024Build Lenders S.r.l.Build Lenders S.r.l. was fined EUR 10,000 by the Garante for unlawfully publishing personal data and failing to respond to a data deletion request. The authority found that the company breached GDPR rules on data protection and data subject rights.ITGaranteGDPR€10,000
17 Jul 2024IstitutoThe Garante fined Istituto EUR 10,000 for violations related to the processing of personal data in the context of medical and scientific research. The authority found that retention periods were not defined and transparency toward data subjects was insufficient.ITGaranteGDPR€10,000
01 Apr 2022SOPHIE ET VOILA, S.L.SOPHIE ET VOILA, S.L. was fined EUR 10,000 by the AEPD for publishing a photo on Instagram without the data subject’s consent. The authority found a breach of Article 6 GDPR on lawful processing.ESAEPDGDPR€10,000
01 Jan 2024FRESHLY COSMETICS, S.L.FRESHLY COSMETICS, S.L. was fined by the AEPD EUR 10,000 for using advertising cookies on its website without user consent. The authority found this breached Article 22.2 of the LSSI.ESAEPDePrivacy€10,000