BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Jul 2025 | Istituto Comprensivo 2 C.D.The Garante fined Istituto Comprensivo 2 C.D. EUR 4,000 for breaches of data protection rules. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency in the processing of personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Jul 2017 | Istituto Auxologico ItalianoIstituto Auxologico Italiano was fined EUR 10,000 by the Garante for failing to implement adequate technical and organizational measures to protect sensitive personal data. The breach concerned the control and security of personal data contained in medical records, in violation of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Jun 2020 | Istituto autonomo per le case popolari della provincia di IserniaIstituto autonomo per le case popolari della provincia di Isernia was fined EUR 2,000 by the Garante. The authority found that personal data, including health information, had been published on the institutional website without a proper legal basis. | IT | Garante | GDPR | €2,000 | ↗ |
| 17 Apr 2026 | Istituto “Ancelle della Compagnia della Regina dei Gigli”The Garante fined the school EUR 4,000 for processing students’ personal data without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Mar 2025 | Istituto Alberghiero Mediterraneo di Pulsano (TA)Istituto Alberghiero Mediterraneo di Pulsano was fined EUR 2,000 by the Garante. The authority found breaches of the principles of lawfulness, fairness, and transparency in personal data processing. | IT | Garante | GDPR | €2,000 | ↗ |
| 17 Jul 2024 | IstitutoThe Garante fined Istituto EUR 10,000 for violations related to the processing of personal data in the context of medical and scientific research. The authority found that retention periods were not defined and transparency toward data subjects was insufficient. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Feb 2021 | Istituti ospedalieri bergamaschiThe Garante fined Istituti ospedalieri bergamaschi EUR 45,000 for a data protection breach. Online medical reports were accessible to other patients, exposing sensitive personal data. | IT | Garante | GDPR | €45,000 | ↗ |
| 27 Feb 2025 | Istarski vodovod d.o.o.Istarski vodovod d.o.o. was fined by AZOP EUR 25,000 for failing to implement adequate technical security measures. The deficiencies included the absence of two-factor authentication and monitoring systems, which led to unauthorized access and a data breach. | HR | AZOP | GDPR | €25,000 | ↗ |
| 07 Sept 2023 | ISRA Center Marketing Research SRLIn August 2023, the Romanian supervisory authority ANSPDCP completed an investigation into ISRA Center Marketing Research SRL. It found a GDPR violation and imposed a fine of EUR 2,000. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 20 Oct 2022 | I.S.P.R.O.The Italian Data Protection Authority fined I.S.P.R.O. EUR 7,000 for violations related to the processing of health data. The case concerned improper handling of sensitive data, creating a material compliance risk. | IT | Garante | GDPR | €7,000 | ↗ |
| 11 Apr 2013 | I.S.P. Italia srlI.S.P. Italia srl was fined by the Garante for sending unsolicited promotional faxes without the required information notice and without obtaining recipients’ consent. The authority found that the conduct breached rules on prior consent and information duties. | IT | Garante | GDPR | €32,000 | ↗ |
| 06 Feb 2023 | I&S Limited Kft.I&S Limited Kft. was fined by NAIH for continuous recording of work activities and monitoring guests, as well as for misleading information about data processing. The authority also found unauthorized processing of health data for marketing purposes. | HU | NAIH | GDPR | €76,800 | ↗ |
| 21 Apr 2021 | Isinc S.r.l.s.Isinc S.r.l.s. was fined 20,000 EUR by the Garante for sending promotional emails using personal data taken from public databases without proper consent. The authority found this conduct to be in breach of GDPR Article 5. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jan 2023 | ISA MADRID SERVICIOS, S.L.ISA MADRID SERVICIOS, S.L. was fined EUR 900 by the AEPD for improperly positioning a surveillance camera that captured public areas. The authority also found that adequate signage informing individuals about the surveillance was not provided, in breach of data protection rules. | ES | AEPD | GDPR | €900 | ↗ |
| 21 Jan 2010 | I.S.A. - Istituto Scolastico Ambrosiano s.n.c.I.S.A. - Istituto Scolastico Ambrosiano s.n.c. was fined EUR 6,000 by the Garante. The case concerned the collection of personal data through its website without providing users with adequate information required under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 23 Mar 2021 | Irish Credit Bureau DACThe Irish Data Protection Commission (DPC) fined Irish Credit Bureau DAC EUR 90,000 in inquiry IN-19-7-2. The fine has been collected. | IE | DPC | GDPR | €90,000 | ↗ |
| 09 May 2024 | IRIDEX GROUP SALUBRIZARE SRLIRIDEX GROUP SALUBRIZARE SRL was fined by ANSPDCP 2,000 EUR for sending a collective email to clients with recipients' email addresses visible. The incident resulted in unauthorized disclosure of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 13 May 2021 | Iren Mercato S.p.A.Iren Mercato S.p.A. was fined by the Garante for processing personal data for marketing purposes without proper consent. The company also contacted individuals listed in the public opposition register. | IT | Garante | GDPR | €2,856,000 | ↗ |
| 01 Feb 2018 | Iqbal QuasimIqbal Quasim was fined EUR 30,000 by the Garante. The case concerned registering phone SIM cards to third parties without their consent, which breached data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 31 May 2018 | Iqbal QasimIqbal Qasim was fined by the Garante in the amount of EUR 70,000 for registering phone SIM cards to third parties without their consent. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €70,000 | ↗ |