BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Oct 2022 | IPM Group NVThe case concerned the use of cookies on the L'Avenir website operated by IPM Group NV. A settlement was reached under which the company agreed to pay 10,000 EUR to the Belgian treasury. | BE | APD | ePrivacy | €10,000 | ↗ |
| 29 Jan 2015 | Iper Market Yi-Gou s.r.l.Iper Market Yi-Gou s.r.l. was fined EUR 6,000 by the Italian supervisory authority, Garante. The case concerned the failure to provide the required information to data subjects about personal data processing through a video surveillance system. | IT | Garante | GDPR | €6,000 | ↗ |
| 13 May 2015 | Iperal S.p.A.Iperal S.p.A. was fined EUR 40,000 by the Garante for activating 11 phone cards in the names of 5 individuals without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 17 Apr 2026 | Io e te s.r.l.s.Io e te s.r.l.s. was fined EUR 2,000 by the Italian Garante. The case concerned improper use of a surveillance camera that enabled remote viewing through a mobile application without proper authorization. | IT | Garante | GDPR | €2,000 | ↗ |
| 08 Jan 2024 | INVERTIA TENERIFE 2019, S.L.INVERTIA TENERIFE 2019, S.L. was fined 1,000 EUR by the AEPD for failing to meet its information obligations toward data subjects. The authority found that the required information under Article 13 GDPR was not provided. | ES | AEPD | GDPR | €1,000 | ↗ |
| 14 Aug 2022 | INVERTIA TENERIFE 2019, S.L.INVERTIA TENERIFE 2019, S.L. was fined 2,000 EUR by the AEPD for failing to inform data subjects about the processing of their personal data. The authority treated this as a breach of Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 20 Jul 2017 | InvalsiInvalsi was fined EUR 40,000 by the Italian Garante for unlawful processing of personal data. The case concerned the online publication of files containing disaggregated student personal data, including sensitive information. | IT | Garante | GDPR | €40,000 | ↗ |
| 04 Jun 2025 | INTS Italia S.r.l.INTS Italia S.r.l. was fined 15,000 EUR by the Garante for failing to provide employees with adequate information on data protection and for not responding to data access requests. The authority found that the company breached core GDPR principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 07 Jul 2022 | Intesa Sanpaolo Vita S.p.a.Intesa Sanpaolo Vita S.p.a. was fined by the Garante EUR 20,000 for unlawfully disclosing personal data related to a life insurance policy to unauthorized third parties. The breach resulted from an operational error and raised concerns about personal data protection and access controls. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 May 2022 | Intesa Sanpaolo S.p.A.Intesa Sanpaolo S.p.A. was fined EUR 100,000 by the Garante for unlawfully disclosing personal banking data to unauthorized third parties. The case concerned a breach of data protection rules and required review of the bank’s data-sharing controls. | IT | Garante | GDPR | €100,000 | ↗ |
| 28 Jul 2022 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined EUR 100,000 by Garante after an employee accessed a customer's financial data without authorization. The data was then used in judicial proceedings. The authority found that the bank had not implemented adequate data protection measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 14 Sept 2023 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined 42,000 EUR by the Garante for failing to provide timely access to personal data requested by a parent under GDPR Article 15. The authority said the delay resulted from an operational error that prevented timely handling of the request. | IT | Garante | GDPR | €42,000 | ↗ |
| 20 Oct 2022 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined by the Garante €40,000 for failing to provide a data subject with access to personal data relating to derivative transactions. The authority found a breach of the principles of lawful, fair, and transparent processing. | IT | Garante | GDPR | €40,000 | ↗ |
| 27 May 2021 | Intesa Sanpaolo s.p.a.Intesa Sanpaolo s.p.a. was fined by the Garante in the amount of 200,000 EUR for unlawfully communicating banking data to an unauthorized third party. The case concerned breaches of data protection principles, including lawfulness and restricted access to information. | IT | Garante | GDPR | €200,000 | ↗ |
| 30 Apr 2026 | Intesa SanpaoloItaly’s data protection authority, Garante, fined Intesa Sanpaolo EUR 31.8 million. The sanction concerned serious failures in security and access management for personal data. | IT | Garante per la protezione dei dati personali | GDPR | €31,800,000 | ↗ |
| 02 Nov 2024 | Intesa SanpaoloThe Italian Data Protection Authority fined Intesa Sanpaolo €31.8 million for a data breach involving unauthorized access to banking information of more than 3,500 clients. The authority also found that the bank detected the activity late and filed an incomplete and delayed breach notification. | IT | Garante per la protezione dei dati personali | GDPR | €31,800 | ↗ |
| 09 Mar 2023 | INTERURBANA DE AUTOBUSES, S.A.INTERURBANA DE AUTOBUSES, S.A. was fined by the AEPD 70,000 EUR for publishing employees’ personal data without consent. The breach involved exposing unnecessary information on notice boards accessible to others, contrary to data minimization requirements. | ES | AEPD | GDPR | €70,000 | ↗ |
| 04 Jun 2021 | INTERSUMI S.C.INTERSUMI S.C. was fined EUR 2,000 by the AEPD for not having an adequate privacy policy on its website. The authority found this to be a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 16 Dec 2022 | INTER PARTNER ASSISTANCE SERVICIOS ESPAÑA, S.A.INTER PARTNER ASSISTANCE SERVICIOS ESPAÑA, S.A. was fined by the AEPD 30,000 EUR for potentially transferring personal data internationally without proper disclosure. This was contrary to the company’s stated privacy policies. | ES | AEPD | GDPR | €30,000 | ↗ |
| 29 Aug 2014 | INTERNET OTT CHANNELS S.L.INTERNET OTT CHANNELS S.L. was fined by the AEPD in the amount of 1,400 EUR for sending unsolicited commercial emails to a user who had opted out. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,400 | ↗ |