Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Jul 2011F.B. Aurum di Ferrero Wilma e Barathier Sergio s.n.c.F.B. Aurum di Ferrero Wilma e Barathier Sergio s.n.c. was fined by the Garante 10,000 EUR for operating a video surveillance system without providing the required notice to data subjects. This constituted a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€10,000
15 Oct 2010Clinica Luccioni S.p.a.Clinica Luccioni S.p.a. was fined by the Garante for failing to timely notify the authority of personal data processing activities required under the Italian Data Protection Code. The case concerned a breach of the notification obligation to the supervisory authority.ITGaranteGDPR€10,000
17 May 2023Grizzaffi Management S.r.l.Grizzaffi Management S.r.l. was fined by the Garante in the amount of 10,000 EUR for sending unsolicited promotional emails without recipient consent. The conduct breached GDPR rules on electronic marketing and consent for commercial communications.ITGaranteGDPR€10,000
23 Jan 2008Laboratorio di analisi cliniche Pasini MarioLaboratorio di analisi cliniche Pasini Mario was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code.ITGaranteGDPR€10,000
19 Aug 2020Anonymizováno (ÚOOÚ UOOU-05284/19-36)The entity was fined for publishing a partially anonymized criminal order on Facebook that still contained personal data. The authority found a breach of GDPR principles governing lawful processing and personal data protection.CZUOOUGDPR€383
11 Jul 2013Patronato ENCALPatronato ENCAL was fined by the Garante 10,000 EUR for failing to implement minimum security measures in the assignment and use of authentication credentials for access to INPS databases. The breach concerned inadequate access control over systems containing sensitive data.ITGaranteGDPR€10,000
05 May 2022РТК ЕООДThe company processed personal data without a lawful basis by including an individual's data in a public register without a valid contract or consent. The authority found this to be a breach of data protection principles and imposed a fine.BGCPDPGDPR€5,113
01 Jan 2023B.B.B.The entity used a video from a training session containing the complainant’s personal statements without consent. The material was used for marketing purposes to attract new clients, which constituted a breach of data protection rules.ESAEPDGDPR€10,000
01 Jan 2023VACACIONES EDREAMS, S.L.VACACIONES EDREAMS, S.L. was fined by the AEPD in the amount of 10,000 EUR for failing to provide access to personal data upon a customer request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€10,000
09 Apr 2024ADNAYA GREEN SOLUTIONS, S.L.ADNAYA GREEN SOLUTIONS, S.L. was fined by the AEPD EUR 10,000 for unlawfully sharing personal data with a third party without consent. The authority found this conduct breached Article 6(1) of the GDPR.ESAEPDGDPR€10,000
05 Mar 2015Comune di CapaccioComune di Capaccio was fined for unlawfully publishing sensitive personal data revealing health conditions on its institutional website. The authority found this to be a breach of privacy and data protection rules.ITGaranteGDPR€10,000
09 Jun 2022Cribis Credit Management s.r.l.Cribis Credit Management s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company unjustifiably communicated debtor information to third parties, in breach of GDPR Article 5.ITGaranteGDPR€10,000
16 Jun 2023BORSA MEDIC, S.L.BORSA MEDIC, S.L. was fined 10,000 EUR by the AEPD for failing to comply with a data deletion request and for sending unsolicited advertising emails after the recipient objected. The case concerns breaches of data protection and electronic commerce rules.ESAEPDePrivacy€10,000
08 Jan 2015CHRYSOS ODIGOS ENTYPH & HLEKTRONIKI PLHROFORISI A.E.The company was fined by the HDPA EUR 10,000 for processing personal data without consent. The authority also found that it failed to respond to data subjects' requests for access and objection.GRHDPAGDPR€10,000
11 Feb 2021Azienda Unità Sanitaria Locale di ParmaAzienda Unità Sanitaria Locale di Parma was fined by the Garante €10,000 for improper handling of sensitive personal data. The violation was linked to an occasional malfunction of its IT system, which led to improper data processing.ITGaranteGDPR€10,000
26 Nov 2024AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited advertising emails. The messages were sent despite the recipient's unsubscribe request and inclusion on the Robinson list, breaching the LSSI.ESAEPDePrivacy€10,000
06 Oct 2022Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante in the amount of 10,000 EUR for failing to respond to a data access request. The authority found a breach of Article 15 of the GDPR.ITGaranteGDPR€10,000
19 Mar 2015Provincia di PisaProvincia di Pisa was fined €10,000 by the Garante. The authority found that employees at the employment center were not designated as data processing officers, resulting in insufficient security measures for handling personal data.ITGaranteGDPR€10,000
01 Jan 2024ESCOLA LES CAROLINES COOP. V.The school was fined by the AEPD 10,000 EUR for processing a minor’s image without a lawful basis. The child’s photograph was displayed on posters inside the school premises, which was found to breach GDPR Article 6(1).ESAEPDGDPR€10,000
01 Jan 2020CENTRO DE DIAGNÓSTICO ***LOCALIDAD.1, S.A.The entity was fined for breaching data confidentiality by improperly sharing medical information between different entities without consent. The case involved sensitive data processing and a lack of a valid legal basis for the disclosure.ESAEPDGDPR€10,000