BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Sept 2021 | LODEJU, S.L.LODEJU, S.L. was fined EUR 3,000 by the AEPD for excessive video surveillance of public space without proper signage. The authority found a breach of GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €3,000 | ↗ |
| 10 Sept 2021 | LA OFICINA BAR XXXXThe entity installed two surveillance cameras aimed at public areas without justification. This breached data protection principles. | ES | AEPD | GDPR | €1,500 | ↗ |
| 16 Sept 2021 | Farpa s.r.l.Farpa s.r.l. was fined by the Garante 1,000 EUR for failing to provide proper information to data subjects, including workers, about the processing of personal data through a video surveillance system. The authority found that the information duty toward affected individuals was not met adequately. | IT | Garante | GDPR | €1,000 | ↗ |
| 16 Sept 2021 | Barilla G. e R. fratelli S.p.A.Barilla G. e R. fratelli S.p.A. was fined by the Garante EUR 75,000 for violations linked to the use of a video surveillance system at its operational site. The system did not comply with data protection requirements. | IT | Garante | GDPR | €75,000 | ↗ |
| 16 Sept 2021 | Azienda Ospedaliero-Universitaria di ModenaAzienda Ospedaliero-Universitaria di Modena was fined by the Garante for the incorrect handling of sensitive health data, including HIV diagnoses, during the COVID-19 emergency. The case concerned breaches of personal data protection rules and medical confidentiality. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Sept 2021 | La Prima S.r.l.La Prima S.r.l. was fined by the Garante for carrying out promotional activities without a valid legal basis. The authority found that this conduct breached GDPR requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Comune di Montalbano JonicoThe Garante fined Comune di Montalbano Jonico 5,000 EUR for breaching the data minimization principle. The municipality published excessive personal data on its website, including health-related information. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Istituto per Ciechi Ardizzone GioeniIstituto per Ciechi Ardizzone Gioeni was fined by the Garante EUR 5,000 for failing to provide adequate data protection information about the activation of a video surveillance system. The case involved vulnerable guests, including blind and visually impaired persons, who were not properly informed about the processing of their personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Consorzio di Bonifica dell’OristaneseConsorzio di Bonifica dell’Oristanese was fined EUR 5,000 by the Garante for publishing a disciplinary measure on its website that included an employee’s health information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Azienda sanitaria provinciale di CosenzaAzienda sanitaria provinciale di Cosenza was fined by the Garante for unlawfully publishing health data on its institutional website. The case involved breaches of data protection principles and required security measures for sensitive data. | IT | Garante | GDPR | €18,000 | ↗ |
| 16 Sept 2021 | Università Commerciale “Luigi Bocconi” di MilanoUniversità Commerciale “Luigi Bocconi” di Milano was fined EUR 150,000 by the Garante for data protection breaches during remote exams. The authority found an insufficient legal basis, inadequate transparency, and weak security measures for transfers of data to the USA. | IT | Garante | GDPR | €150,000 | ↗ |
| 16 Sept 2021 | Ordine Provinciale di Roma dei Medici Chirurghi e degli OdontoiatriOrdine Provinciale di Roma dei Medici Chirurghi e degli Odontoiatri was fined by the Garante €5,000 for failing to adequately respond to a data subject’s request for access to personal data. The authority found a breach of GDPR Articles 12 and 15. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Istituto Comprensivo - IC Cosenza III “V. Negroni”Istituto Comprensivo - IC Cosenza III “V. Negroni” was fined by the Garante 2,000 EUR for unlawful processing of personal data and inadequate data protection. The authority also noted that personal data were made accessible online, increasing the risk to affected individuals. | IT | Garante | GDPR | €2,000 | ↗ |
| 16 Sept 2021 | Favrskov KommuneFavrskov Kommune was fined 75,000 DKK for failing to implement appropriate security measures, including encryption, to protect sensitive personal data on a stolen laptop. The authority found a breach of GDPR Article 32. | DK | Datatilsynet | GDPR | €10,086 | ↗ |
| 16 Sept 2021 | Accademia di Belle Arti di RomaAccademia di Belle Arti di Roma was fined EUR 5,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data in a disciplinary procedure and the dissemination of sensitive information. | IT | Garante | GDPR | €5,000 | ↗ |
| 17 Sept 2021 | Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 23 Sept 2021 | TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD EUR 1,000,000 for failing to adequately prevent unauthorized SIM card duplication. The breach enabled access to confidential information and caused financial losses for customers. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 24 Sept 2021 | B.B.B.The entity was fined for operating a video surveillance system aimed at public and private spaces without sufficient justification. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €2,500 | ↗ |
| 27 Sept 2021 | Сиела Норма АДThe CPDP found that Сиела Норма АД violated the GDPR by inaccurately processing personal data. The error led to an individual being misidentified as a liquidator of companies, and a fine of 5,000 BGN was imposed. | BG | CPDP | GDPR | €2,557 | ↗ |
| 27 Sept 2021 | B.B.B.The entity was fined by the AEPD for operating a video surveillance system without proper informational signage. The system also captured footage beyond the intended purpose, including public transit areas. | ES | AEPD | GDPR | €1,500 | ↗ |