BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Feb 2023 | It's OK LimitedBetween 1 July 2019 and 1 June 2020, It's OK Limited made 1,752,149 unsolicited direct marketing calls to subscribers who had been registered with the TPS for at least 28 days. The company had no evidence that the recipients had not objected to receiving such calls, breaching regulation 21 of PECR. | GB | ICO | ePrivacy | €225,000 | ↗ |
| 18 Apr 2013 | Itel s.r.l. UnipersonaleItel s.r.l. Unipersonale was fined EUR 102,000 by the Garante for improper processing of personal data. The case involved registering phone cards to third parties without their knowledge, in breach of privacy rules. | IT | Garante | GDPR | €102,000 | ↗ |
| 05 Apr 2018 | I Tel s.r.l.I Tel s.r.l. was fined EUR 230,000 by the Italian data protection authority, Garante. The case concerned the registration of phone cards to 23 individuals without their consent, in breach of data protection rules. | IT | Garante | GDPR | €230,000 | ↗ |
| 05 May 2021 | Ítélet a NAIH-3644-9/2021. sz. ügyben (Fővárosi Törvényszék 105.K.704.512/2021/21)The supervisory authority found that the controller had not implemented adequate technical and organizational measures to protect personal data. Employees were also not properly informed about processing related to email accounts and devices, and personal email was accessed without proper justification. | HU | NAIH | GDPR | €5,560 | ↗ |
| 09 Jul 2020 | Ítélet a NAIH/2020/974 sz. ügyben (Kúria végzése Kpk.III.39.352/2022/3)The controller processed personal data without a legal basis and did not provide adequate information about the processing. The authority found violations of several GDPR provisions and imposed a fine. | HU | NAIH | GDPR | €2,820 | ↗ |
| 09 Jul 2020 | Ítélet a NAIH/2020/974 sz. ügyben (Kúria Kfv. II.37.001/2021/6)The controller processed personal data without a legal basis for a political campaign. It also failed to provide adequate information about the processing, resulting in breaches of several GDPR provisions. | HU | NAIH | GDPR | €2,820 | ↗ |
| 09 Jul 2020 | Ítélet a NAIH/2020/974 sz. ügyben (Alkotmánybíróság 3110/2022. (III. 23.) AB határozata)The controller processed personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The authority imposed a fine of HUF 1,000,000 for breaches of GDPR principles. | HU | NAIH | GDPR | €2,820 | ↗ |
| 10 Dec 2020 | Ítélet a NAIH/2020/54/H. sz. ügyben (Fővárosi Törvényszék 105.K.707.432/2020/17.)The entity was fined for processing scholarship applicants' personal data without a legal basis, including sensitive data. The authority also found that the data subjects were not adequately informed about the processing. | HU | NAIH | GDPR | €22,480 | ↗ |
| 09 Dec 2020 | Ítélet a NAIH/2019/3633/10 sz. ügyben (Fővárosi Törvényszék 106.K.700.561/2019/16) - 2020. december 9.The case concerned a HUF 800,000 fine imposed by the NAIH for unlawful camera surveillance. The authority found that the processing breached GDPR principles of lawfulness, fairness, transparency, purpose limitation, and data minimization. | HU | NAIH | GDPR | €2,240 | ↗ |
| 23 May 2019 | Ítélet a NAIH/2019/1189/11 sz. ügyben (Fővárosi Törvényszék 105.K.700.364/2019/11)The controller did not provide the requested personal data or information beyond a 2012 lease agreement. This breached the data subject’s access rights under the GDPR. | HU | NAIH | GDPR | €918 | ↗ |
| 06 Oct 2023 | Ítélet a NAIH-19-18-2024 sz. ügyben (Kúria Kfv.IV.37.804/2025/2)The entity was fined for improper processing of personal data in a nationwide energy efficiency program. The authority found inadequate transparency and consent procedures, as well as insufficient data security measures. | HU | NAIH | GDPR | €194,000 | ↗ |
| 12 Mar 2026 | ITAS MutuaITAS Mutua was fined EUR 50,000 by the Garante for failing to adequately respond to a former employee’s request for access to personal data. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €50,000 | ↗ |
| 05 Oct 2017 | Italprest di Luca Bosimini & C. s.a.s.Italprest di Luca Bosimini & C. s.a.s. was fined €10,000 by the Garante. The authority found that the company failed to implement minimum security measures, including the use of passwords shorter than eight characters, in breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Jan 2008 | Italmarmo di Rossin EzioItalmarmo di Rossin Ezio was fined EUR 4,000 by the Garante for failing to provide timely access to personal data upon request. The case concerned non-compliance with data protection obligations. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Nov 2012 | Italiasalute s.r.l.Italiasalute s.r.l. was fined by the Garante EUR 10,400 for processing personal data on its website without providing data subjects with adequate information. The authority also found that consent was obtained in a non-compliant manner, particularly for profiling and marketing purposes. | IT | Garante | GDPR | €10,400 | ↗ |
| 22 Feb 2024 | Italiaonline S.p.A.Italiaonline S.p.A. was fined by the Garante 100,000 EUR for conducting direct email marketing campaigns without proper consent. The authority also found inadequate information about data processing activities shared with Google LLC. | IT | Garante | GDPR | €100,000 | ↗ |
| 13 Jul 2016 | Italian Lab s.r.l.Italian Lab s.r.l. was fined EUR 4,000 by the Garante. The case concerned the processing of personal data for a mailing list and newsletter without obtaining user consent. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Jan 2018 | Italia Consulenza e Formazione s.r.l.Italia Consulenza e Formazione s.r.l. was fined EUR 32,000 by the Garante for sending promotional emails without proper consent. The case concerns a breach of data protection rules governing direct marketing. | IT | Garante | GDPR | €32,000 | ↗ |
| 04 Dec 2014 | Itala s.p.aItala s.p.a was fined EUR 4,000 by the Garante for processing personal data related to job applications without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 Apr 2022 | ISWEB S.p.A.ISWEB S.p.A. was fined EUR 40,000 by the Italian supervisory authority, Garante. The authority found that the company failed to properly regulate its relationship with the hosting service provider in relation to data processing for Azienda ospedaliera di Perugia, in breach of Article 28 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |