BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Sept 2015 | Acquapark di Milillo Rosa & C. s.a.s.Acquapark di Milillo Rosa & C. s.a.s. was fined EUR 6,400 by the Garante for collecting personal data without providing the required information notice and for publishing user photos without consent. The case concerns failures to meet transparency obligations and lawful processing requirements. | IT | Garante | GDPR | €6,400 | ↗ |
| 30 Jan 2014 | impresa individuale Otelma di Belelli Marco AmletoThe sole proprietorship Otelma di Belelli Marco Amleto was fined EUR 6,400 by the Garante for failing to implement minimum security measures when processing sensitive data via its website. The breaches included not appointing a data processor and not preparing a security program document. | IT | Garante | GDPR | €6,400 | ↗ |
| 11 Mar 2021 | dott. Gregorio GrecoDott. Gregorio Greco was fined 6,400 EUR by the Garante for failing to provide information to data subjects and for processing patients' health-related personal data without consent. The case concerns patient data and breaches of transparency and lawful basis requirements. | IT | Garante | GDPR | €6,400 | ↗ |
| 08 May 2013 | Business Services s.r.lBusiness Services s.r.l was fined EUR 6,400 by the Garante. The case concerned the sending of promotional faxes without the required information and without obtaining explicit consent from recipients. | IT | Garante | GDPR | €6,400 | ↗ |
| 27 Jun 2013 | New Company di Scattolin LorisNew Company di Scattolin Loris was fined EUR 6,400 by the Garante for making unsolicited promotional phone calls without proper consent. The conduct breached Articles 13 and 130 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,400 | ↗ |
| 01 Oct 2015 | Semplice viaggi s.r.l.Semplice viaggi s.r.l. was fined EUR 6,400 by the Garante for providing insufficient information to users on its website and for pre-setting consent to the processing of personal data for promotional purposes. The authority found these practices to be in breach of data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 19 Dec 2012 | Il Tetto srlIl Tetto srl was fined EUR 6,400 by the Garante for sending unsolicited promotional faxes. The authority found that prior, specific, and informed consent from recipients had not been obtained, in breach of data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 17 Oct 2024 | Giancarlo FranciniThe Garante imposed a EUR 6,500 fine on Giancarlo Francini for breaches related to the processing of health data. The authority found failures to meet transparency obligations and noted that data subject requests were answered only after a complaint was filed. | IT | Garante | GDPR | €6,500 | ↗ |
| 11 Feb 2021 | Azienda Sanitaria Locale n. 2 Lanciano-Vasto-ChietiAzienda Sanitaria Locale n. 2 Lanciano-Vasto-Chieti was fined by the Garante 6,500 EUR for violations related to the processing of health data. The нарушения led to a data breach incident. | IT | Garante | GDPR | €6,500 | ↗ |
| 02 Feb 2022 | Anonymisé (CNPD decision-02-fr-2022)The company was fined by the CNPD 6,600 EUR for breaches of GDPR requirements. The authority found deficiencies in data minimization, retention, security of processing, and the information provided to data subjects in connection with video surveillance and geolocation systems. | LU | CNPD | GDPR | €6,600 | ↗ |
| 04 Aug 2021 | Anonymisé (CNPD decision-30-fr-2021)The public establishment failed to communicate the DPO’s contact details to the supervisory authority and did not provide the DPO with the resources needed to perform the role effectively. CNPD found breaches of GDPR Articles 37(7), 38(2), and 39(1)(b) and imposed a fine of 6,600 EUR. | LU | CNPD | GDPR | €6,600 | ↗ |
| 10 Feb 2026 | Dane anonimowe (R.)The UODO imposed a PLN 6,700 fine on Anonymous data (R.) for failing to notify a personal data breach within 72 hours and for not informing affected individuals without undue delay. The authority also found deficiencies in the appointment of the data protection officer, including missing contact details, failure to notify the supervisory authority, and a conflict of interest because the role was assigned to a board member. | PL | UODO | GDPR | €1,589 | ↗ |
| 31 Aug 2022 | niegoThe President of UODO imposed a fine of PLN 6,854 on an individual for processing the complainant’s image through video surveillance. The breach consisted of failing to cooperate with the authority and not providing information necessary for it to perform its duties. | PL | UODO | GDPR | €1,450 | ↗ |
| 22 Jul 2024 | COMMUNECNIL imposed EUR 6,900 on COMMUNE as an astreinte liquidation. The case concerns enforcement of a prior obligation subject to supervisory authority action. | FR | CNIL | GDPR | €6,900 | ↗ |
| 20 Oct 2022 | I.S.P.R.O.The Italian Data Protection Authority fined I.S.P.R.O. EUR 7,000 for violations related to the processing of health data. The case concerned improper handling of sensitive data, creating a material compliance risk. | IT | Garante | GDPR | €7,000 | ↗ |
| 11 Sept 2025 | ASSOCIATION GERANT UN LYCEE ET UN INTERNAT POUR LES JEUNES EN SITUATION DE DECROCHAGE SCOLAIRE (procédure simplifiée)CNIL imposed an administrative fine of 7,000 EUR on ASSOCIATION GERANT UN LYCEE ET UN INTERNAT POUR LES JEUNES EN SITUATION DE DECROCHAGE SCOLAIRE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €7,000 | ↗ |
| 22 Feb 2023 | MUNDOVIAJES2010, S.L.MUNDOVIAJES2010, S.L. was fined by the AEPD in the amount of 7,000 EUR for processing personal data without consent. The authority also found a failure to provide the required information about data processing, in breach of GDPR Articles 6(1) and 14. | ES | AEPD | GDPR | €7,000 | ↗ |
| 01 Jan 2016 | CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD for sending unsolicited advertising emails. The authority also found that the company did not provide an easy opt-out mechanism, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 01 Jan 2023 | INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L.INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L. was fined by the AEPD EUR 7,000 for unlawfully disclosing personal data, including health information, in response to a Google review. The authority found a breach of confidentiality and of the security obligations under the GDPR. | ES | AEPD | GDPR | €7,000 | ↗ |
| 12 May 2022 | Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante €7,000 for violations related to the processing of health data. The authority also found insufficient data security measures. | IT | Garante | GDPR | €7,000 | ↗ |