Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Nov 2015Croce Rosa Italiana s.r.l.Croce Rosa Italiana s.r.l. was fined for processing employee personal data using electronic tools for geolocation without adopting minimum security measures. The authority found a breach of Article 33 of the Italian Data Protection Code.ITGaranteGDPR€10,000
20 Jun 2024Provvedimento del 20 giugno 2024 [10105123]The Municipality of XX was fined for unlawfully disclosing personal and health data by publishing it on its Facebook page. The authority found that the public disclosure of this information breached data protection rules.ITGaranteGDPR€10,000
22 May 2018Calvanese RaffaelloCalvanese Raffaello, a general practitioner, was fined for failing to adopt minimum security measures to protect patients’ personal and sensitive data. The deficiencies allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
13 Nov 2023RECICLAJES LOGROÑO, S.L.RECICLAJES LOGROÑO, S.L. was fined by the AEPD 10,000 EUR for photocopying a customer's ID without consent and for failing to provide privacy policy information. The authority found breaches of GDPR data minimization and transparency principles.ESAEPDGDPR€10,000
25 Aug 2025ASSOCIATION DE DEFENSE DE DROITS FONDAMENTAUX (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on ASSOCIATION DE DEFENSE DE DROITS FONDAMENTAUX and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
23 Apr 2023GRIMEY WEAR, S.L.GRIMEY WEAR, S.L. did not delete the complainant’s personal data after a request and continued sending promotional emails. The AEPD found this to be a breach of Article 17 GDPR and imposed a fine of 10,000 EUR.ESAEPDGDPR€10,000
17 Oct 2013Comune di AcirealeComune di Acireale was fined for failing to adopt minimum security measures and for not appointing data processing officers, as required by the Italian Data Protection Code. The case concerned basic organizational and security compliance failures.ITGaranteGDPR€10,000
09 Mar 2023Banca Cambiano 1884 S.p.A.Banca Cambiano 1884 S.p.A. was fined by the Garante 10,000 EUR for failing to respond within the required timeframe to a data subject's request for access to personal data. The authority found a breach of GDPR Articles 15 and 12.ITGaranteGDPR€10,000
16 May 2018Greco LuigiGreco Luigi, a general practitioner, was fined for failing to implement minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
17 May 2023Azienda ULSS 6 EuganeaThe Garante fined Azienda ULSS 6 Euganea 10,000 EUR for the incorrect handling of health-related documents. The authority found breaches of GDPR Articles 5, 6, and 32.ITGaranteGDPR€10,000
14 Sept 2006Asl VercelliAsl Vercelli was fined by the Garante for processing special-category personal data, including genetic and health data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
11 Feb 2021Arma dei carabinieriArma dei carabinieri was fined by the Garante for improperly handling sensitive and judicial data without adequate safeguards against unauthorized access. The authority found breaches of the GDPR and the Italian Privacy Code.ITGaranteGDPR€10,000
16 Apr 2015Web performance s.r.l.Web performance s.r.l. was fined by the Garante for collecting personal data through website forms without proper consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€10,000
19 Mar 2025XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited SMS advertisements to a number registered on the Robinson List. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€10,000
13 Nov 2024Spinacqua S.r.l.Spinacqua S.r.l. was fined by the Garante €10,000 for making unsolicited promotional calls to a number listed in the Public Opposition Register. The company did not obtain consent and failed to verify the number’s registration status before contacting it.ITGaranteGDPR€10,000
10 Jul 2025Asilo nido “La Combricola Dei Birichini Di Betty”The Garante imposed a 10,000 EUR fine on the nursery for failing to provide parents with the required information about the processing of children's images. It also found that no data protection impact assessment had been carried out for the surveillance system.ITGaranteGDPR€10,000
26 Feb 2021PINTODIS, S.L.PINTODIS, S.L. was fined by the AEPD for installing surveillance cameras that recorded employees in private areas without sufficient justification. The authority found this to be a breach of data protection principles.ESAEPDGDPR€10,000
26 Jun 2020ESLORA PROYECTOS, S.L.ESLORA PROYECTOS, S.L. was fined by the AEPD 10,000 EUR for failing to provide cookie information and for not obtaining user consent before using cookies. The authority cited a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€10,000
23 Apr 2015Comune di AostaComune di Aosta was fined for publishing personal data that revealed health information on its website. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€10,000
26 Sept 2024Comune di VeronaThe Garante fined Comune di Verona €10,000 for violations of GDPR Articles 5, 6 and 9, as well as Article 2-ter of the Italian Privacy Code. The case concerned the processing of personal data in a manner not compliant with legal requirements.ITGaranteGDPR€10,000