BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Dec 2008 | Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c.Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c. was fined for failing to notify the Garante of personal data processing activities within the required timeframe. The case concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Mar 2023 | NATURGESTYGAS, S.L.NATURGESTYGAS, S.L. was fined EUR 10,000 by the AEPD for processing personal data without a legal basis. The company charged a customer despite having no contract or consent, which breached the legality requirement for processing. | ES | AEPD | GDPR | €10,000 | ↗ |
| 14 Jan 2016 | Comune di Santa FlaviaThe Garante fined Comune di Santa Flavia €10,000 for unlawfully publishing documents on its website that disclosed individuals' health data. The case involved the disclosure of sensitive personal data without a lawful basis. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Jul 2015 | Comune di GallipoliThe Municipality of Gallipoli was fined by the Garante for unlawfully publishing personal data revealing health status on its institutional website. The conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Apr 2022 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 10,000 EUR for breaching the principle of data confidentiality. The bank sent debit card transaction notifications to incorrect email addresses, failed to notify the authority of the breach, and did not take timely corrective action. | GR | HDPA | GDPR | €10,000 | ↗ |
| 06 Jul 2023 | AcegasApsAmga S.p.A.AcegasApsAmga S.p.A. was fined €10,000 by the Italian supervisory authority, Garante. The sanction concerned the company’s failure to respond to a data subject’s request for access to personal data, in breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Jul 2021 | Università degli Studi di Milano-BicoccaUniversità degli Studi di Milano-Bicocca was fined EUR 10,000 by the Garante for data protection violations linked to the publication of personal data on its institutional website. The case concerned the disclosure of information on the university’s website, which breached data processing rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Feb 2022 | Anonymisé (CNPD decision-01-fr-2022)The entity breached GDPR requirements on data minimization, retention limitation, and the duty to inform data subjects, including employees and third parties, about processing activities. CNPD imposed a fine of EUR 10,000. | LU | CNPD | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Azienda Ospedaliero Universitaria SeneseAzienda Ospedaliero Universitaria Senese was fined by the Garante in the amount of 10,000 EUR for breaches of data protection rules in the healthcare sector. The case concerned the processing of sensitive personal data in a medical setting. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Nov 2023 | Alpha BankAlpha Bank was fined for failing to satisfy the complainant’s request for access to personal data. The authority found breaches of GDPR Articles 15 and 5. | GR | HDPA | GDPR | €10,000 | ↗ |
| 24 Jun 2020 | Azienda Sanitaria Universitaria Giuliano IsontinaAzienda Sanitaria Universitaria Giuliano Isontina was fined by the Garante for unlawfully communicating health data without an adequate legal basis. The conduct breached Article 20 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Nov 2010 | Fitness Solution società sportiva dilettantistica s.r.l.Fitness Solution was fined EUR 10,000 by the Garante. The authority found that biometric personal data were processed without proper consent and retained longer than necessary. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Sept 2025 | La Fântâna S.R.L.In July 2025, ANSPDCP completed an investigation into La Fântâna S.R.L. and found a breach of GDPR provisions. As a result, the operator was fined 10,000 EUR. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 23 Jan 2008 | Deas Desideri e associati s.r.l.Deas Desideri e associati s.r.l. was fined €10,000 by the Garante for failing to notify the processing of sensitive personal data within the required timeframe. The authority found a breach of Article 163 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2016 | BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 10,000 EUR for failing to provide the required cookie information and for not obtaining consent on its website. The case concerns breaches of notice and consent obligations for website cookies. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 01 Jan 2020 | PERSONAL MARK, S.L.PERSONAL MARK, S.L. was fined by the AEPD 10,000 EUR for failing to diligently delete personal data from its databases despite the complainant’s requests. The case indicates inadequate handling of data erasure obligations. | ES | AEPD | GDPR | €10,000 | ↗ |
| 11 Jan 2024 | Build Lenders S.r.l.Build Lenders S.r.l. was fined EUR 10,000 by the Garante for unlawfully publishing personal data and failing to respond to a data deletion request. The authority found that the company breached GDPR rules on data protection and data subject rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Jul 2024 | IstitutoThe Garante fined Istituto EUR 10,000 for violations related to the processing of personal data in the context of medical and scientific research. The authority found that retention periods were not defined and transparency toward data subjects was insufficient. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Apr 2022 | SOPHIE ET VOILA, S.L.SOPHIE ET VOILA, S.L. was fined EUR 10,000 by the AEPD for publishing a photo on Instagram without the data subject’s consent. The authority found a breach of Article 6 GDPR on lawful processing. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | FRESHLY COSMETICS, S.L.FRESHLY COSMETICS, S.L. was fined by the AEPD EUR 10,000 for using advertising cookies on its website without user consent. The authority found this breached Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |