BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Apr 2021 | INPSThe Italian Data Protection Authority fined INPS €12,000 for failing to provide a data subject with access to their personal data and for unlawfully communicating personal data to third parties. The authority found breaches of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €12,000 | ↗ |
| 24 Apr 2024 | I.N.P.A.S.The Garante imposed a fine on I.N.P.A.S. for violations related to the processing of employees' personal data, including sensitive data. The authority found that the processing did not ensure lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €3,000 | ↗ |
| 15 Feb 2018 | Innovastem s.r.l.Innovastem s.r.l. was fined by the Garante for processing personal data without providing the required information notice and for handling health-related data without proper consent. The case indicates breaches of transparency obligations and the rules governing the lawful processing of sensitive data. | IT | Garante | GDPR | €22,400 | ↗ |
| 04 Jan 2021 | Innovasjon NorgeThe Norwegian DPA notified Innovasjon Norge of a planned NOK 1,000,000 fine for conducting four credit assessments of an individual and his sole proprietorship without a legal basis. The case indicates a breach of the lawfulness principle for personal data processing. | NO | Datatilsynet | GDPR | €95,750 | ↗ |
| 11 Apr 2024 | Innova Camera – Azienda speciale della Camera di commercio, industria, artigianato e agricoltura di RomaInnova Camera was fined by the Garante EUR 25,000 for inadequate data security measures. The breach resulted in personal data being accessed and published online following an SQL Injection attack. | IT | Garante | GDPR | €25,000 | ↗ |
| 08 Jun 2022 | INMUR JOYEROS, S.L.INMUR JOYEROS, S.L. was fined by the AEPD 300 EUR for failing to properly inform individuals about the video surveillance system in its premises. The authority found a breach of Article 13 GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 09 Jun 2021 | INMOPISO ZARAGOZA, S.L.INMOPISO ZARAGOZA, S.L. was fined EUR 2,000 by the AEPD for failing to provide data protection information to a customer who made a deposit for a property purchase. The case concerns a breach of the transparency and information duty owed to the data subject. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2022 | INMOBILIARIA MESLLOC, S.L.INMOBILIARIA MESLLOC, S.L. was fined by the AEPD for unlawfully sharing tenants’ personal data with third-party companies without authorization. The authority found this conduct violated Article 6(1) of the GDPR. | ES | AEPD | GDPR | €40,000 | ↗ |
| 01 Jan 2021 | INMARÁN ASESORES, S.L.INMARÁN ASESORES, S.L. was fined 2,000 EUR by the AEPD for recording telephone conversations without informing the data subject or obtaining consent. The authority found this to be a breach of the GDPR information obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 30 Nov 2022 | INMARAN ASESORES S.L.INMARAN ASESORES S.L. was fined by the AEPD 1,000 EUR for failing to comply with data protection authority resolutions. The breach concerned the obligation to inform data subjects under Article 13 of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 Jan 2023 | INMARAN ASESORES S.L.INMARAN ASESORES S.L. was fined by the AEPD in the amount of 2,000 EUR for failing to comply with a data protection authority resolution. The company did not implement the required measures to inform data subjects under Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 27 Apr 2011 | Iniziative immobiliari s.p.a.Iniziative immobiliari s.p.a. was fined 20,000 EUR by the Garante. The authority found that the company collected personal data through a website form without providing adequate information and failed to appoint data processing personnel or implement minimum security measures. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Sept 2013 | Iniziative Commerciali S.r.l.Iniziative Commerciali S.r.l. was fined by the Garante for collecting personal data through a website contact form without providing the required privacy notice. This breached the Italian Data Protection Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 16 Nov 2010 | INGORA SERAI S.L.INGORA SERAI S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits unsolicited marketing communications. | ES | AEPD | ePrivacy | €600 | ↗ |
| 19 Apr 2022 | INGENIERÍA Y TELECOM JAÉN, S.L.INGENIERÍA Y TELECOM JAÉN, S.L. was fined 10,000 EUR by the AEPD. The authority found that the company renewed a customer's service promotion without consent, in breach of Article 6 GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 27 Mar 2014 | ING DIRECT NV SUCURSAL EN ESPAÑAING Direct Spain was fined by the AEPD for sending commercial emails to a user after consent had been revoked. The authority found this to be a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 05 Jun 2014 | Ing. Claudio ZiniThe individual enterprise of Ing. Claudio Zini was fined for sending unsolicited promotional emails. The authority also found that the required information notice under Article 13 of the Italian Privacy Code was not provided. | IT | Garante | GDPR | €2,400 | ↗ |
| 23 Jul 2025 | ING Bank Śląski SAThe Polish supervisory authority imposed an administrative fine on ING Bank Śląski SA for scanning the identity documents of customers and prospective customers without properly assessing whether this was necessary under AML rules. The decision became final on 23 July 2025 and concerns breaches of Articles 5(1)(a), (b) and (c) and 6(1) of the GDPR. | PL | President of the Personal Data Protection Office | GDPR | €4,375,000 | ↗ |
| 23 Mar 2026 | ING Bank NV Amsterdam – Sucursala București S.A.The fine was imposed for failing to implement adequate technical and organizational measures to ensure the confidentiality of personal data. As a result, an unauthorized third party received a bank account statement. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 18 Jul 2023 | ING BANK NV Amsterdam Sucursala BucureștiING Bank NV Amsterdam Sucursala București received a fine from ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |