BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Nov 2014 | Ruggiero FerdinandoRuggiero Ferdinando was fined EUR 10,000 by the Garante. The sanction concerned failing to provide a complete response to a request for information during a privacy investigation. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2023 | EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.EL ESPAÑOL was fined 10,000 EUR by the AEPD for publishing a private video without the consent of the data subject. The case concerns a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 24 Nov 2016 | Unione Comunale del Chianti fiorentinoUnione Comunale del Chianti fiorentino was fined by the Garante 10,000 EUR for publishing on its website the personal data of individuals who were not admitted to a financial benefit. The conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Asl FerraraAsl Ferrara was fined by the Garante for processing genetic, health, and sexual life data without the required notification. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Feb 2026 | Radio Immagine Uno S.r.l.The Garante imposed a €10,000 fine on Radio Immagine Uno S.r.l. for failing to respond to a data subject's request to remove an online article containing personal data. The company did not comply with the right to be forgotten, resulting in a data protection breach. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Jul 2014 | Comune di OrbetelloThe Municipality of Orbetello was fined EUR 10,000 by the Italian data protection authority, Garante. The sanction concerned the publication of individuals’ personal health data on the municipality’s official website, in breach of privacy rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Feb 2022 | Regione ToscanaRegione Toscana was fined by the Garante EUR 10,000 for failing to implement adequate security measures, which resulted in a data breach. The breach was mitigated by the region’s prompt response to reduce the negative effects on affected individuals. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2021 | B.B.B.B.B.B. was fined by the AEPD 10,000 EUR for publishing personal data, including DNI/NIF, on a website. The authority found a breach of data minimization principles and GDPR requirements. | ES | AEPD | GDPR | €10,000 | ↗ |
| 07 Mar 2024 | BdM Banca S.p.a.BdM Banca S.p.a. was fined 10,000 EUR by the Garante for failing to provide an adequate response to a data access request submitted by an heir. The authority found that the response did not meet the requirements of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Oct 2019 | JOKER PREMIUM INVEX, S.L.JOKER PREMIUM INVEX, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited commercial communications. The company used personal data taken from public sources without the individuals’ consent. | ES | AEPD | GDPR | €10,000 | ↗ |
| 11 Jan 2024 | DESPACHO TORRENTE, S.L.P.DESPACHO TORRENTE, S.L.P. was fined by the AEPD 10,000 EUR for improperly disclosing personal data, including sensitive information, in a letter concerning damage at public facilities. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 04 Jul 2024 | Nomodidattica S.r.l.Nomodidattica S.r.l. was fined EUR 10,000 by the Garante for publishing a court ruling online without anonymizing minors' data. The authority found this breached GDPR data protection principles. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Dec 2009 | BonassisaLab s.r.l.BonassisaLab s.r.l. was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jan 2010 | Servizi sanitari s.r.l. – Istituto cardiovascolare CamogliServizi sanitari s.r.l. was fined by the Garante 10,000 EUR for violations related to the processing of personal data without the required notification. The case concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2015 | ORANGE ESPAGNE, S.A.U.JAZZ TELECOM S.A.U. was fined for sending unsolicited SMS advertising to a non-customer. The authority found that the conduct breached the LSSI rules on marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 19 Mar 2024 | LOCAL VERTICALS, S.L.LOCAL VERTICALS, S.L. was fined by the AEPD 10,000 EUR for storing cookies without user consent and for failing to provide a legal notice on its website. The case concerns breaches of data protection rules and website transparency obligations. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 15 Jul 2010 | Comune di VentimigliaComune di Ventimiglia was fined by the Garante for processing employees’ biometric data without the required notification. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Azienda Ospedaliero Universitaria di ParmaAzienda Ospedaliero Universitaria di Parma was fined by the Garante for violations related to the handling of health data. The violations resulted in a data breach, which led to the 10,000 EUR penalty. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Mar 2021 | Anonymizováno (ÚOOÚ UOOU-00681/20-18)The entity was fined for sending unsolicited commercial communications by email without the recipients' consent. This breached Czech electronic communications rules. | CZ | UOOU | ePrivacy | €382 | ↗ |
| 10 Jan 2017 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited commercial SMS messages. The messages were sent despite the complainant being registered on the Robinson List, breaching Articles 21.1 and 21.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |