BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 May 2011 | Jnternet srlJnternet srl was fined by the Italian data protection authority, Garante, in the amount of EUR 10,000. The case concerned the failure to respond to requests for information about compliance with data protection obligations in connection with promotional emails sent without proper consent. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Jul 2018 | Comune di VollaComune di Volla was fined by the Garante EUR 10,000 for allowing all employees access to sensitive and judicial personal data through its electronic protocol system. The authority found that this setup failed to meet required data protection safeguards. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Dental Leader S.p.A.Dental Leader S.p.A. was fined EUR 10,000 by the Garante. The authority found that the company required consent to process personal data for promotional purposes in order to complete an online order, even though this was not necessary for contract performance. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2014 | Tenacta Group s.p.a.Tenacta Group s.p.a. was fined €10,000 by the Garante for making an unsolicited promotional phone call. The conduct breached the complainant’s right to object, as recorded in the public opt-out list. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2015 | Comune di Castelvetrano SelinunteComune di Castelvetrano Selinunte was fined by the Garante for unlawfully publishing personal data revealing health conditions on its website. The case involved a breach of data protection rules and the confidentiality of sensitive information. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Jul 2021 | Dane anonimowe (Prezesa Sądu Rejonowego w M. za naruszenie art. 5 ust. 1 lit. f), art. 25 ust. 1, art. 32 ust. 1 lit. b) i d) oraz art. 32 ust. 2 rozporządzenia 2016/679)UODO imposed a fine of PLN 10,000 on the President of the District Court for failing to implement appropriate technical and organizational measures. The authority found that the security level did not match the risk associated with processing data using portable external storage devices. | PL | UODO | GDPR | €2,189 | ↗ |
| 21 Mar 2022 | RESTAURANTCNIL imposed a fine of EUR 10,000 on RESTAURANT. The case concerned a regulatory breach, with no further details provided. | FR | CNIL | GDPR | €10,000 | ↗ |
| 12 Mar 2015 | Comune di Alì TermeComune di Alì Terme was fined for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy rules and the protection of sensitive personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Jul 2023 | EDICIONES PERIÓDICAS DEL NOROESTE, S.L.The entity published a private video on Twitter without the data subject’s consent. The authority found a breach of data minimization because excessive data were processed beyond what was necessary for the intended purpose. | ES | AEPD | GDPR | €10,000 | ↗ |
| 12 Dec 2024 | BREOGAN AUTOLUX, S.L.BREOGAN AUTOLUX, S.L. was fined EUR 10,000 by the AEPD for sending unsolicited SMS advertisements without prior consent from recipients. The authority also found that the messages did not provide an opt-out mechanism, in breach of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 23 Jan 2024 | CAIXA RURAL BENICARLÓ, S.C.C.VCAIXA RURAL BENICARLÓ was fined by the AEPD 10,000 EUR for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident. | ES | AEPD | GDPR | €10,000 | ↗ |
| 19 Apr 2022 | INGENIERÍA Y TELECOM JAÉN, S.L.INGENIERÍA Y TELECOM JAÉN, S.L. was fined 10,000 EUR by the AEPD. The authority found that the company renewed a customer's service promotion without consent, in breach of Article 6 GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 21 Apr 2011 | Azienda Trasporti per l'Area Metropolitana S.p.A.Azienda Trasporti per l'Area Metropolitana S.p.A. was fined by the Garante €10,000 for failing to provide adequate data protection information on its website. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Mar 2019 | А.Р. ЕООДThe CPDP imposed a 10,000 BGN fine on А.Р. ЕООД for processing personal data without consent. The case also involved registering an employment contract for an imprisoned individual, which breached Article 6 GDPR. | BG | CPDP | GDPR | €5,113 | ↗ |
| 10 Jun 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited advertising SMS messages to a complainant. The messages were sent despite the recipient’s request not to receive such communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 12 Mar 2015 | Comune di BasicòComune di Basicò was fined for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of data protection rules and the confidentiality of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Feb 2016 | Decatel s.r.l.Decatel s.r.l. was fined €10,000 by the Italian Garante. The case concerned the processing and retention of telephone traffic data without the required safeguards, including biometric recognition and strong authentication. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Jan 2015 | Comune di SidernoComune di Siderno was fined by the Garante for unlawfully publishing personal data revealing health conditions on its website. The conduct breached privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Jan 2020 | дружество за комунални услугиThe utility company processed the complainant’s personal data without a lawful basis by sharing it with a private bailiff for enforcement proceedings. CPDP imposed a fine of 10,000 BGN for breaching Article 6 GDPR. | BG | CPDP | GDPR | €5,113 | ↗ |
| 17 Jul 2025 | Federazione Italiana Sport EquestriThe Italian Data Protection Authority imposed a EUR 10,000 fine on Federazione Italiana Sport Equestri for publishing a disciplinary decision involving a minor on its website without anonymizing personal data. The breach concerned data protection rules and the disclosure of information that could identify the minor. | IT | Garante | GDPR | €10,000 | ↗ |