BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Jul 2011 | F.B. Aurum di Ferrero Wilma e Barathier Sergio s.n.c.F.B. Aurum di Ferrero Wilma e Barathier Sergio s.n.c. was fined by the Garante 10,000 EUR for operating a video surveillance system without providing the required notice to data subjects. This constituted a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Oct 2010 | Clinica Luccioni S.p.a.Clinica Luccioni S.p.a. was fined by the Garante for failing to timely notify the authority of personal data processing activities required under the Italian Data Protection Code. The case concerned a breach of the notification obligation to the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | Grizzaffi Management S.r.l.Grizzaffi Management S.r.l. was fined by the Garante in the amount of 10,000 EUR for sending unsolicited promotional emails without recipient consent. The conduct breached GDPR rules on electronic marketing and consent for commercial communications. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Jan 2008 | Laboratorio di analisi cliniche Pasini MarioLaboratorio di analisi cliniche Pasini Mario was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Aug 2020 | Anonymizováno (ÚOOÚ UOOU-05284/19-36)The entity was fined for publishing a partially anonymized criminal order on Facebook that still contained personal data. The authority found a breach of GDPR principles governing lawful processing and personal data protection. | CZ | UOOU | GDPR | €383 | ↗ |
| 11 Jul 2013 | Patronato ENCALPatronato ENCAL was fined by the Garante 10,000 EUR for failing to implement minimum security measures in the assignment and use of authentication credentials for access to INPS databases. The breach concerned inadequate access control over systems containing sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 May 2022 | РТК ЕООДThe company processed personal data without a lawful basis by including an individual's data in a public register without a valid contract or consent. The authority found this to be a breach of data protection principles and imposed a fine. | BG | CPDP | GDPR | €5,113 | ↗ |
| 01 Jan 2023 | B.B.B.The entity used a video from a training session containing the complainant’s personal statements without consent. The material was used for marketing purposes to attract new clients, which constituted a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2023 | VACACIONES EDREAMS, S.L.VACACIONES EDREAMS, S.L. was fined by the AEPD in the amount of 10,000 EUR for failing to provide access to personal data upon a customer request. The authority found a breach of Article 15 of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 09 Apr 2024 | ADNAYA GREEN SOLUTIONS, S.L.ADNAYA GREEN SOLUTIONS, S.L. was fined by the AEPD EUR 10,000 for unlawfully sharing personal data with a third party without consent. The authority found this conduct breached Article 6(1) of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 05 Mar 2015 | Comune di CapaccioComune di Capaccio was fined for unlawfully publishing sensitive personal data revealing health conditions on its institutional website. The authority found this to be a breach of privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Jun 2022 | Cribis Credit Management s.r.l.Cribis Credit Management s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company unjustifiably communicated debtor information to third parties, in breach of GDPR Article 5. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Jun 2023 | BORSA MEDIC, S.L.BORSA MEDIC, S.L. was fined 10,000 EUR by the AEPD for failing to comply with a data deletion request and for sending unsolicited advertising emails after the recipient objected. The case concerns breaches of data protection and electronic commerce rules. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 08 Jan 2015 | CHRYSOS ODIGOS ENTYPH & HLEKTRONIKI PLHROFORISI A.E.The company was fined by the HDPA EUR 10,000 for processing personal data without consent. The authority also found that it failed to respond to data subjects' requests for access and objection. | GR | HDPA | GDPR | €10,000 | ↗ |
| 11 Feb 2021 | Azienda Unità Sanitaria Locale di ParmaAzienda Unità Sanitaria Locale di Parma was fined by the Garante €10,000 for improper handling of sensitive personal data. The violation was linked to an occasional malfunction of its IT system, which led to improper data processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Nov 2024 | AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited advertising emails. The messages were sent despite the recipient's unsubscribe request and inclusion on the Robinson list, breaching the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 06 Oct 2022 | Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante in the amount of 10,000 EUR for failing to respond to a data access request. The authority found a breach of Article 15 of the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Mar 2015 | Provincia di PisaProvincia di Pisa was fined €10,000 by the Garante. The authority found that employees at the employment center were not designated as data processing officers, resulting in insufficient security measures for handling personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | ESCOLA LES CAROLINES COOP. V.The school was fined by the AEPD 10,000 EUR for processing a minor’s image without a lawful basis. The child’s photograph was displayed on posters inside the school premises, which was found to breach GDPR Article 6(1). | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2020 | CENTRO DE DIAGNÓSTICO ***LOCALIDAD.1, S.A.The entity was fined for breaching data confidentiality by improperly sharing medical information between different entities without consent. The case involved sensitive data processing and a lack of a valid legal basis for the disclosure. | ES | AEPD | GDPR | €10,000 | ↗ |