Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jun 2016Midica s.r.l.Midica s.r.l. was fined by the Garante for making promotional calls without the consent of the individuals concerned. The company also failed to respond to information requests from the supervisory authority.ITGaranteGDPR€10,000
26 Jul 2018Primo s.r.l.Primo s.r.l., a dental center, was fined by the Italian Garante in the amount of 10,000 EUR. The authority found inadequate security measures in the processing of patients’ personal data.ITGaranteGDPR€10,000
01 Mar 2025Tensa Art Design S.A.The Romanian data protection authority investigated Tensa Art Design S.A., operator of lensa.ro, in March 2025. It found GDPR violations involving direct marketing without valid consent and improper handling of data subject access and erasure requests. Two fines totaling 15,000 EUR were imposed.ROANSPDCPGDPR€10,000
26 Apr 2018Falotico Luca CarmeloFalotico Luca Carmelo, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
11 Jul 2018BUSITALIA VENETO S.p.A.BUSITALIA VENETO S.p.A. was fined by the Garante for unlawful processing of personal data through the installation of a geolocation system on its public transport vehicles. The measure infringed employee privacy and data protection rules.ITGaranteGDPR€10,000
02 Oct 2014San Petronio s.r.l.San Petronio s.r.l. was fined by the Garante for failing to appoint data processing officers and for providing inadequate information about video surveillance. The authority found that these practices breached data protection rules.ITGaranteGDPR€10,000
01 Jul 2020COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD for publishing a resident’s personal data on a community notice board. The conduct breached data protection rules.ESAEPDGDPR€10,000
26 Mar 2026Messina Social CityMessina Social City was fined by the Garante 10,000 EUR for breaching GDPR principles. The case concerned the improper dissemination of personal data, including images of minors, on Facebook without proper legal grounds and contracts.ITGaranteGDPR€10,000
31 Dec 2024SOCIETE DE TRANSPORT AMBULANCIER (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE DE TRANSPORT AMBULANCIER. The case was handled under a simplified procedure.FRCNILGDPR€10,000
29 Jan 2026ASSOCIATION RELIGIEUSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on ASSOCIATION RELIGIEUSE (procédure simplifiée) and issued an injunction. The case concerned a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€10,000
23 Nov 2023SC Sweat Concept One SASC Sweat Concept One SA was fined 10,000 RON for failing to respond to a data subject’s request to exercise the right to erasure. The authority found a breach of the ePrivacy provisions.ROANSPDCPePrivacy€2,012
10 Feb 2022Costampress S.p.A.Costampress S.p.A. was fined EUR 10,000 by the Garante for failing to take required steps after employment ended. The company did not delete the former employee’s email account or transfer the phone number, which breached GDPR requirements.ITGaranteGDPR€10,000
12 Mar 2026Artemide S.r.l.s.Artemide S.r.l.s., the owner of MeridioNews.it, was fined 10,000 EUR by the Garante. The authority found that the company failed to properly handle a request to delete and de-index articles concerning judicial matters, thereby infringing data protection rights.ITGaranteGDPR€10,000
23 May 2024SOCIETE GERANT UNE PLATEFORME D'APPELS POUR LE SECRETARIAT DE PROFESSIONNELS (procédure simplifiée)CNIL imposed an administrative fine of EUR 10,000 on SOCIETE GERANT UNE PLATEFORME D'APPELS POUR LE SECRETARIAT DE PROFESSIONNELS. The case was handled under a simplified procedure.FRCNILGDPR€10,000
22 Aug 2022Enel Energie Muntenia S.A.The company was fined by ANSPDCP for failing to implement sufficient security measures. The breach concerned inadequate safeguards required to protect data.ROANSPDCPGDPR€10,000
26 Mar 2020Cavauto s.r.l.Cavauto s.r.l. was fined by the Garante EUR 10,000 for violating GDPR principles on data processing. The case involved improper handling of employee data and failures to ensure proper access and deletion rights.ITGaranteGDPR€10,000
30 Dec 2025SOCIETE EXERCANT UNE ACTIVITE DE FRET AEROPORTUAIRE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE DE FRET AEROPORTUAIRE. The case was handled under a simplified procedure.FRCNILGDPR€10,000
26 Jan 2017Comune di Roma CapitaleComune di Roma Capitale was fined EUR 10,000 by the Garante for unlawfully publishing personal data of disabled individuals on its website. The case concerned a breach of data protection rules and required removal of the disclosed information.ITGaranteGDPR€10,000
09 Aug 2023AUTOFER, S.L.AUTOFER, S.L. was fined EUR 10,000 by the AEPD for sending multiple unsolicited advertising SMS messages. The messages were sent despite the recipient’s prior request not to receive further communications, breaching Article 21 of the LSSI.ESAEPDePrivacy€10,000
18 Apr 2018Comune di San GeminiComune di San Gemini was fined EUR 10,000 by the Garante for unlawfully transmitting personal data of residents born in 1994–1996 to a school. The conduct breached data protection rules.ITGaranteGDPR€10,000