BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Mar 2025 | BEKO ROMÂNIA SAIn February 2025, ANSPDCP completed an investigation at BEKO ROMÂNIA SA and found violations of GDPR provisions. As a result, the controller was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 28 Mar 2023 | SOCIETE DE MARKETING (procédure simplifiée)CNIL imposed a fine of EUR 10,000 on SOCIETE DE MARKETING and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 11 Jul 2019 | Thomas N****The individual secretly recorded video footage of two women in a changing room without their consent. The DSB found this to be a breach of GDPR rules on lawful processing and consent. | AT | DSB | GDPR | €10,000 | ↗ |
| 29 May 2019 | Regione PugliaRegione Puglia was fined by the Garante 10,000 EUR for unlawfully publishing personal data of participants in a selection process on its official website. The disclosure included tax codes and income data, breaching privacy rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Apr 2025 | BitdefenderBitdefender received a GDPR fine of EUR 10,000 from the Romanian data protection authority. The sanction followed an investigation completed in April 2025 after a data breach notification, with the authority citing inadequate technical and organizational security measures. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | — | €10,000 | ↗ |
| 19 Feb 2015 | Comune di CampotostoComune di Campotosto was fined by the Garante for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy and personal data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Mar 2015 | Istituto Professionale di Stato per i Servizi Commerciali Turistici Alberghieri "Cesare Musatti"The Istituto Professionale di Stato per i Servizi Commerciali Turistici Alberghieri “Cesare Musatti” was fined by the Italian data protection authority, Garante, in the amount of €10,000. The violation involved unlawfully publishing personal data on its website that revealed students’ health status. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Pettirossi AngeloDr Pettirossi Angelo was fined by the Garante for failing to implement minimum security measures for personal data protection. The breach allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Dec 2009 | Polisportiva Eschilo 1 società sportiva dilettantistica a r.l.Polisportiva Eschilo 1 was fined EUR 10,000 by the Italian Garante. The case concerned processing biometric data without prior notification to the supervisory authority, which breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Jan 2023 | CORREDURÍA DE SEGUROS DE MADRID, S.L.CORREDURÍA DE SEGUROS DE MADRID, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company linked the complainant’s bank account to insurance policies they had not taken out, resulting in unauthorized charges. | ES | AEPD | GDPR | €10,000 | ↗ |
| 27 Mar 2014 | Casa di cura Scarnati srlCasa di cura Scarnati srl was fined €10,000 by the Garante. The authority found that the company failed to properly designate, in writing, the employees authorized to process personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl Basso MoliseAsl Basso Molise was fined by the Garante for failing to notify its data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Jan 2024 | B.B.B.The entity was fined for publishing personal images and phone numbers on Telegram channels without the data subjects’ consent. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2019 | D. B.B.B.The respondent was fined for publishing intimate photos and conversations of the complainant on WhatsApp without consent. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 10 Oct 2022 | EKO ABEEThe fine was imposed for a violation of Article 15 GDPR because the controller failed to provide the data subject with access to their personal data. The case concerns non-compliance with the obligation to ensure the right of access within the required scope. | GR | HDPA | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Engineering Ingegneria Informatica S.p.A.The Garante imposed a fine of EUR 10,000 on Engineering Ingegneria Informatica S.p.A. for a data breach involving the Molise regional health portal. A system vulnerability allowed unauthorized access to personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 Jan 2024 | SOCIETE AYANT POUR ACTIVITE LE SOUTIEN AUX ENTREPRISES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE LE SOUTIEN AUX ENTREPRISES. The decision concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €10,000 | ↗ |
| 12 Sept 2013 | Comune di MantovaThe Municipality of Mantua was fined by the Garante for unlawfully disseminating personal data through its online services without a proper legal basis. The authority found a breach of Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 May 2022 | DKN.5131.51.2021StatusuchylonaTytuUODO imposed an administrative fine of PLN 10,000 for a breach involving the recording and storage of sound in a monitoring system. The case concerned improper use of CCTV monitoring with audio capture. | PL | UODO | GDPR | €2,183 | ↗ |
| 04 Apr 2007 | Azienda sanitaria locale di PescaraAzienda sanitaria locale di Pescara was fined €10,000 by the Garante for breaching data protection rules. The case involved improper handling of sensitive personal data, including genetic and health information, without the required notification to the authority. | IT | Garante | GDPR | €10,000 | ↗ |