BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jun 2016 | Midica s.r.l.Midica s.r.l. was fined by the Garante for making promotional calls without the consent of the individuals concerned. The company also failed to respond to information requests from the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Jul 2018 | Primo s.r.l.Primo s.r.l., a dental center, was fined by the Italian Garante in the amount of 10,000 EUR. The authority found inadequate security measures in the processing of patients’ personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Mar 2025 | Tensa Art Design S.A.The Romanian data protection authority investigated Tensa Art Design S.A., operator of lensa.ro, in March 2025. It found GDPR violations involving direct marketing without valid consent and improper handling of data subject access and erasure requests. Two fines totaling 15,000 EUR were imposed. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 26 Apr 2018 | Falotico Luca CarmeloFalotico Luca Carmelo, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Jul 2018 | BUSITALIA VENETO S.p.A.BUSITALIA VENETO S.p.A. was fined by the Garante for unlawful processing of personal data through the installation of a geolocation system on its public transport vehicles. The measure infringed employee privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Oct 2014 | San Petronio s.r.l.San Petronio s.r.l. was fined by the Garante for failing to appoint data processing officers and for providing inadequate information about video surveillance. The authority found that these practices breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jul 2020 | COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD for publishing a resident’s personal data on a community notice board. The conduct breached data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 26 Mar 2026 | Messina Social CityMessina Social City was fined by the Garante 10,000 EUR for breaching GDPR principles. The case concerned the improper dissemination of personal data, including images of minors, on Facebook without proper legal grounds and contracts. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 Dec 2024 | SOCIETE DE TRANSPORT AMBULANCIER (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE DE TRANSPORT AMBULANCIER. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 29 Jan 2026 | ASSOCIATION RELIGIEUSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on ASSOCIATION RELIGIEUSE (procédure simplifiée) and issued an injunction. The case concerned a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €10,000 | ↗ |
| 23 Nov 2023 | SC Sweat Concept One SASC Sweat Concept One SA was fined 10,000 RON for failing to respond to a data subject’s request to exercise the right to erasure. The authority found a breach of the ePrivacy provisions. | RO | ANSPDCP | ePrivacy | €2,012 | ↗ |
| 10 Feb 2022 | Costampress S.p.A.Costampress S.p.A. was fined EUR 10,000 by the Garante for failing to take required steps after employment ended. The company did not delete the former employee’s email account or transfer the phone number, which breached GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Mar 2026 | Artemide S.r.l.s.Artemide S.r.l.s., the owner of MeridioNews.it, was fined 10,000 EUR by the Garante. The authority found that the company failed to properly handle a request to delete and de-index articles concerning judicial matters, thereby infringing data protection rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 May 2024 | SOCIETE GERANT UNE PLATEFORME D'APPELS POUR LE SECRETARIAT DE PROFESSIONNELS (procédure simplifiée)CNIL imposed an administrative fine of EUR 10,000 on SOCIETE GERANT UNE PLATEFORME D'APPELS POUR LE SECRETARIAT DE PROFESSIONNELS. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 22 Aug 2022 | Enel Energie Muntenia S.A.The company was fined by ANSPDCP for failing to implement sufficient security measures. The breach concerned inadequate safeguards required to protect data. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 26 Mar 2020 | Cavauto s.r.l.Cavauto s.r.l. was fined by the Garante EUR 10,000 for violating GDPR principles on data processing. The case involved improper handling of employee data and failures to ensure proper access and deletion rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE DE FRET AEROPORTUAIRE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE DE FRET AEROPORTUAIRE. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 26 Jan 2017 | Comune di Roma CapitaleComune di Roma Capitale was fined EUR 10,000 by the Garante for unlawfully publishing personal data of disabled individuals on its website. The case concerned a breach of data protection rules and required removal of the disclosed information. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Aug 2023 | AUTOFER, S.L.AUTOFER, S.L. was fined EUR 10,000 by the AEPD for sending multiple unsolicited advertising SMS messages. The messages were sent despite the recipient’s prior request not to receive further communications, breaching Article 21 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 18 Apr 2018 | Comune di San GeminiComune di San Gemini was fined EUR 10,000 by the Garante for unlawfully transmitting personal data of residents born in 1994–1996 to a school. The conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |