Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Mar 2015Comune di Acquarica del CapoThe Municipality of Acquarica del Capo was fined 10,000 EUR by the Garante for unlawfully publishing personal data revealing health information on its website. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€10,000
07 May 2015Provincia di FrosinoneProvincia di Frosinone was fined for failing to update the Security Policy Document (DPS) for several years. The authority found this to be a breach of security measures required under the Italian Data Protection Code.ITGaranteGDPR€10,000
26 Apr 2018Comune di DerutaThe Municipality of Deruta was fined 10,000 EUR for unlawfully providing lists of personal data of residents born in 1994–1996 to a private educational institution. The recipient was not entitled to receive the data under public utility exceptions.ITGaranteGDPR€10,000
30 Jun 2011Porto di Tropea s.p.a.Porto di Tropea s.p.a. was fined by the Garante 10,000 EUR for failing to provide adequate information about video surveillance. The authority also found that data processors were not formally appointed for customer data collected through mooring contracts.ITGaranteGDPR€10,000
22 May 2018Parnofiello AntonellaParnofiello Antonella, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to a healthcare system.ITGaranteGDPR€10,000
13 Feb 2007Asl Alto MoliseAsl Alto Molise was fined 10,000 EUR by the Garante for failing to notify data processing activities related to health diagnosis, treatment, and prevention within the required timeframe. The breach violated the Italian Data Protection Code.ITGaranteGDPR€10,000
08 Aug 2014Compass ExpoCompass Expo was fined EUR 10,000 by the HDPA for sending unsolicited electronic communications without recipients' consent. The authority found a breach of Article 11 of Law 3471/2006.GRHDPAePrivacy€10,000
15 Jun 2017Azienda Policlinico Umberto IAzienda Policlinico Umberto I was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate data processing officers and provide them with the necessary instructions, breaching minimum security measures under the Italian Data Protection Code.ITGaranteGDPR€10,000
17 Sept 2021Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR.CYCyDPCGDPR€10,000
04 Sept 2023ASSOCIACIO OASIS CULTURALASSOCIACIO OASIS CULTURAL was fined by the AEPD EUR 10,000 for unlawful processing of personal data. The case concerned the publication on TikTok of a video showing minors performing dances with sexual connotations without a legal basis under Article 6(1) GDPR.ESAEPDGDPR€10,000
26 Nov 2024ASSOCIATION AYANT POUR ACTIVITE L'ACTION SOCIALE SANS HEBERGEMENT ET LA GESTION D'ETABLISSEMENTS MEDICO-SOCIAUX ET SANITAIRES (procédure simplifiée)CNIL imposed an administrative fine of 10,000 EUR on ASSOCIATION AYANT POUR ACTIVITE L'ACTION SOCIALE SANS HEBERGEMENT ET LA GESTION D'ETABLISSEMENTS MEDICO-SOCIAUX ET SANITAIRES. The case was handled under a simplified procedure.FRCNILGDPR€10,000
19 Jan 2023ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal and banking data without consent. The conduct occurred in connection with a contract renewal offer presented as if it came from the complainant's electricity supplier.ESAEPDGDPR€10,000
17 Sept 2019Geanonimiseerd (APD 06/2019)The case concerned a complaint about the use of electronic identity cards to create customer cards. The Litigation Chamber found breaches of data minimization, lawful basis for processing, and information duties under the GDPR, and imposed a fine of EUR 10,000.BEAPDGDPR€10,000
19 Jan 2017Bertolotto Michele e Azienda Universitaria Ospedaliera Ospedali Riuniti di TriesteThe Garante imposed a 10,000 EUR fine on Bertolotto Michele and Azienda Universitaria Ospedaliera Ospedali Riuniti di Trieste. The case concerned unauthorized access by two doctors to personal health data, including Bertolotto’s data.ITGaranteGDPR€10,000
07 Jun 2023ELECTRAWORKS - CEUTA, S.A.ELECTRAWORKS - CEUTA, S.A. did not comply with a data deletion request and retained personal data for 10 years without proper justification. The AEPD found this to be a breach of Article 13 GDPR and imposed a 10,000 EUR fine.ESAEPDGDPR€10,000
22 Jun 2022B.B.B.An individual's personal data was used without consent to publish an online advertisement for sexual services, resulting in harassment. The responsible entity was fined for violating Article 6(1) of the GDPR.ESAEPDGDPR€10,000
10 Apr 2025Azienda Ospedaliera Universitaria Integrata VeronaAzienda Ospedaliera Universitaria Integrata Verona was fined by the Garante for failing to adequately protect personal data. After a ransomware attack, 612 GB of data was published on the dark web, indicating serious security shortcomings.ITGaranteGDPR€10,000
13 Feb 2007Asl Centro MoliseAsl Centro Molise was fined by the Garante for processing personal data, including genetic and biometric data, without the required notification. The breach concerned obligations under the Italian data protection code.ITGaranteGDPR€10,000
16 Jan 2025CENTRE DE FORMATION A DISTANCE D'APPRENTIS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on CENTRE DE FORMATION A DISTANCE D'APPRENTIS and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
30 May 2018Alpha BankAlpha Bank was fined by the HDPA for failing to respond to a data subject access request within the prescribed timeframe. The case concerned Article 12 of Law 2472/1997 and the bank’s obligations to facilitate data subject rights.GRHDPAGDPR€10,000