BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Nov 2015 | Croce Rosa Italiana s.r.l.Croce Rosa Italiana s.r.l. was fined for processing employee personal data using electronic tools for geolocation without adopting minimum security measures. The authority found a breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Jun 2024 | Provvedimento del 20 giugno 2024 [10105123]The Municipality of XX was fined for unlawfully disclosing personal and health data by publishing it on its Facebook page. The authority found that the public disclosure of this information breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Calvanese RaffaelloCalvanese Raffaello, a general practitioner, was fined for failing to adopt minimum security measures to protect patients’ personal and sensitive data. The deficiencies allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Nov 2023 | RECICLAJES LOGROÑO, S.L.RECICLAJES LOGROÑO, S.L. was fined by the AEPD 10,000 EUR for photocopying a customer's ID without consent and for failing to provide privacy policy information. The authority found breaches of GDPR data minimization and transparency principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 25 Aug 2025 | ASSOCIATION DE DEFENSE DE DROITS FONDAMENTAUX (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on ASSOCIATION DE DEFENSE DE DROITS FONDAMENTAUX and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 23 Apr 2023 | GRIMEY WEAR, S.L.GRIMEY WEAR, S.L. did not delete the complainant’s personal data after a request and continued sending promotional emails. The AEPD found this to be a breach of Article 17 GDPR and imposed a fine of 10,000 EUR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 17 Oct 2013 | Comune di AcirealeComune di Acireale was fined for failing to adopt minimum security measures and for not appointing data processing officers, as required by the Italian Data Protection Code. The case concerned basic organizational and security compliance failures. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Mar 2023 | Banca Cambiano 1884 S.p.A.Banca Cambiano 1884 S.p.A. was fined by the Garante 10,000 EUR for failing to respond within the required timeframe to a data subject's request for access to personal data. The authority found a breach of GDPR Articles 15 and 12. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 May 2018 | Greco LuigiGreco Luigi, a general practitioner, was fined for failing to implement minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | Azienda ULSS 6 EuganeaThe Garante fined Azienda ULSS 6 Euganea 10,000 EUR for the incorrect handling of health-related documents. The authority found breaches of GDPR Articles 5, 6, and 32. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Asl VercelliAsl Vercelli was fined by the Garante for processing special-category personal data, including genetic and health data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Feb 2021 | Arma dei carabinieriArma dei carabinieri was fined by the Garante for improperly handling sensitive and judicial data without adequate safeguards against unauthorized access. The authority found breaches of the GDPR and the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Apr 2015 | Web performance s.r.l.Web performance s.r.l. was fined by the Garante for collecting personal data through website forms without proper consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Mar 2025 | XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited SMS advertisements to a number registered on the Robinson List. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 13 Nov 2024 | Spinacqua S.r.l.Spinacqua S.r.l. was fined by the Garante €10,000 for making unsolicited promotional calls to a number listed in the Public Opposition Register. The company did not obtain consent and failed to verify the number’s registration status before contacting it. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Jul 2025 | Asilo nido “La Combricola Dei Birichini Di Betty”The Garante imposed a 10,000 EUR fine on the nursery for failing to provide parents with the required information about the processing of children's images. It also found that no data protection impact assessment had been carried out for the surveillance system. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Feb 2021 | PINTODIS, S.L.PINTODIS, S.L. was fined by the AEPD for installing surveillance cameras that recorded employees in private areas without sufficient justification. The authority found this to be a breach of data protection principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 26 Jun 2020 | ESLORA PROYECTOS, S.L.ESLORA PROYECTOS, S.L. was fined by the AEPD 10,000 EUR for failing to provide cookie information and for not obtaining user consent before using cookies. The authority cited a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 23 Apr 2015 | Comune di AostaComune di Aosta was fined for publishing personal data that revealed health information on its website. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Sept 2024 | Comune di VeronaThe Garante fined Comune di Verona €10,000 for violations of GDPR Articles 5, 6 and 9, as well as Article 2-ter of the Italian Privacy Code. The case concerned the processing of personal data in a manner not compliant with legal requirements. | IT | Garante | GDPR | €10,000 | ↗ |