Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Mar 2015Comune di AcateComune di Acate was fined by the Garante for unlawfully publishing personal data revealing health information on its institutional website. The case concerned a breach of data protection rules and the confidentiality of sensitive data.ITGaranteGDPR€10,000
27 May 2021Società e Salute S.p.a.Società e Salute S.p.a. was fined by the Garante EUR 10,000 for a data breach involving the mishandling of personal data, including health information. The authority found violations of GDPR Articles 5 and 9.ITGaranteGDPR€10,000
12 Feb 2018Политическа партия „Движение презареди България“The political party Movement Reload Bulgaria was fined 10,000 BGN by the CPDP for processing personal data without consent. The breach occurred during the registration of individuals as election commission members and violated the Bulgarian Personal Data Protection Act.BGCPDPGDPR€5,113
21 Jan 2016Alfonso EspositoAlfonso Esposito, a gynecologist, was fined by the Garante for processing clients’ personal data for medical purposes without obtaining their consent. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
05 Jul 2017Istituto Auxologico ItalianoIstituto Auxologico Italiano was fined EUR 10,000 by the Garante for failing to implement adequate technical and organizational measures to protect sensitive personal data. The breach concerned the control and security of personal data contained in medical records, in violation of the Italian Data Protection Code.ITGaranteGDPR€10,000
28 Sept 2023REVUE LITTERAIRE FRANCAISE (procédure simplifiée)The CNIL imposed a 10,000 EUR fine on REVUE LITTERAIRE FRANCAISE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
13 Sept 2007Asl San Severo (Foggia 1)Asl San Severo (Foggia 1) was fined by the Garante for processing personal data, including genetic and biometric data, without proper compliance with data protection rules. The case indicates insufficient legal basis and safeguards for the handling of sensitive data.ITGaranteGDPR€10,000
14 Sept 2006Asl 21 di Casale MonferratoThe Garante fined Asl 21 di Casale Monferrato 10,000 EUR for processing genetic and health data without the required notification. The authority found a breach of the Italian Privacy Code.ITGaranteGDPR€10,000
30 Dec 2025Roumasport S.R.LRoumasport S.R.L was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data.ROANSPDCPGDPR€10,000
09 Aug 2021ACONCAGUA JUEGOS S.A.ACONCAGUA JUEGOS S.A. was fined by the AEPD 10,000 EUR for failing to appoint a Data Protection Officer. The authority also found that the company did not address a data subject’s erasure request within the legal deadline.ESAEPDGDPR€10,000
29 Feb 2024SOCIETE AYANT POUR ACTIVITE LA RECHERCHE ET LE DEVELOPPEMENT SCIENTIFIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE LA RECHERCHE ET LE DEVELOPPEMENT SCIENTIFIQUE under a simplified procedure. The case concerns a violation identified by the French supervisory authority.FRCNILGDPR€10,000
01 Dec 2022Regione CampaniaRegione Campania was fined by the Garante in the amount of EUR 10,000 for unauthorized access to personal data. The case concerned breaches of GDPR requirements on data protection and security measures.ITGaranteGDPR€10,000
12 Feb 2015Comune di CalatabianoComune di Calatabiano was fined 10,000 EUR by the Garante for unlawfully publishing personal data revealing health conditions on its institutional website. The conduct breached privacy rules governing the processing and disclosure of sensitive data.ITGaranteGDPR€10,000
14 Jan 2021Azienda Ospedaliera San Pio di BeneventoAzienda Ospedaliera San Pio di Benevento was fined by the Garante 10,000 EUR for publishing employees’ personal data on its intranet without a proper legal basis. The case concerned unauthorized disclosure of personal data within the organization’s internal environment.ITGaranteGDPR€10,000
03 May 2018Marconi RobertoMarconi Roberto, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum security measures to protect patients' personal and sensitive data were not adopted, allowing unauthorized access to the healthcare system.ITGaranteGDPR€10,000
13 May 2015Provincia di NapoliProvincia di Napoli was fined for unlawfully publishing personal data, including health information, on its institutional website. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
22 May 2018Alessandro SabatiniAlessandro Sabatini, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum personal data security measures were not implemented, which allowed unauthorized access to a health information system.ITGaranteGDPR€10,000
18 Nov 2015Collegio professionale dei periti industriali di Roma e provinciaCollegio professionale dei periti industriali di Roma e provincia was fined 10,000 EUR by the Garante for unlawfully publishing judicial data on its website. The publication occurred during an election campaign.ITGaranteGDPR€10,000
28 Oct 2021dott.ssa GiglioA doctor was fined for improperly handling personal data, including medical prescriptions. The authority found breaches of GDPR Articles 5, 9, and 32 on processing principles, special-category data, and security measures.ITGaranteGDPR€10,000
06 Jul 2016La Fourchette (Italy) s.r.l.La Fourchette (Italy) s.r.l. was fined EUR 10,000 by the Garante. The authority found that the company collected personal data for promotional purposes without obtaining specific consent from users.ITGaranteGDPR€10,000