BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Nov 2021 | B.B.B.The entity was fined by the AEPD 10,000 EUR for publishing the complainant's phone number on a website without consent. This led to unwanted calls, and despite requests for removal, the number reappeared, breaching GDPR Article 6. | ES | AEPD | GDPR | €10,000 | ↗ |
| 17 Jan 2008 | Assioma selezione e sviluppo s.r.l.Assioma selezione e sviluppo s.r.l. was fined by the Garante in the amount of 10,000 EUR for failing to comply with data protection notification requirements. The breach concerned Article 163 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Mar 2017 | Azienda Sanitaria ULSS 6 di VicenzaAzienda Sanitaria ULSS 6 di Vicenza was fined by the Garante 10,000 EUR for unlawfully communicating an individual's health data to the Comune di Arcugnano without proper authorization. The case involved a breach of lawful processing rules and safeguards for special-category data. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Sept 2022 | HERON CITY VALENCIA MANAGEMENT S.L.HERON CITY VALENCIA MANAGEMENT S.L. was fined by the AEPD in the amount of 10,000 EUR for refusing to provide access to surveillance footage. This conduct breached the data subject’s rights, in particular the right of access under Article 15 of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 25 Aug 2021 | Amendă în aplicarea Legii nr. 190/2018The operator was fined for failing to respond to the authority's requests during an investigation. The case concerns non-cooperation with ANSPDCP in the course of supervisory proceedings. | RO | ANSPDCP | GDPR | €2,029 | ↗ |
| 20 Jun 2013 | Terme di Montecatini s.p.a.Terme di Montecatini s.p.a. was fined by the Garante in the amount of 10,000 EUR. The company processed personal and sensitive data of national health service patients undergoing spa treatments without obtaining consent, in breach of Article 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Oct 2024 | political partyThe Hellenic Data Protection Authority imposed a 10,000 EUR fine on a political party for unlawful processing of the personal data of overseas voters. The case concerns data protection breaches in the handling of electoral information. | GR | Hellenic Data Protection Authority | GDPR | €10,000 | ↗ |
| 04 Apr 2022 | B.B.B.The entity was fined by the AEPD in the amount of EUR 10,000 for publishing personal data, including images and videos, without the consent of the data subjects. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 04 Oct 2011 | Il Marmo s.r.l.Il Marmo s.r.l. was fined by the Garante in the amount of 10,000 EUR for failing to provide the required privacy notice on its website, specifically in the contact form. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Sept 2011 | Enterprise Service s.r.l.Enterprise Service s.r.l. was fined by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The company also failed to provide the required information notice under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Ordinanza ingiunzione - 22 maggio 2018 [9037459]A general practitioner failed to implement minimum security measures to protect patients' personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Jun 2023 | Anonymisiert (DSB 2023-0.420.407)The responsible party unlawfully processed special categories of personal data by publishing health data in response to an online review. This breached GDPR principles of lawfulness, purpose limitation, and data minimization. | AT | DSB | GDPR | €10,000 | ↗ |
| 04 Jun 2015 | Direzione Casa Circondariale di BariDirezione Casa Circondariale di Bari was fined €10,000 by the Garante for unlawfully processing sensitive data. The authority found that it collected, stored, and communicated the names of participants in a union demonstration without initiating any disciplinary proceedings, in breach of data protection law. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Dec 2022 | SUDREZIDENȚIAL Broker S.R.L.The company was fined for failing to inform data subjects about a personal data breach. The authority found a violation of Article 34 of the GDPR. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 19 Feb 2015 | Comune di MesoracaComune di Mesoraca was fined by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its institutional website. The case involved unauthorized disclosure of medical information made publicly accessible. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 Feb 2023 | SOCIETE EXERCANT UNE ACTIVITE DE DETAIL D'HABILLEMENT EN MAGASIN SPECIALISE (procédure simplifiée)CNIL imposed a fine of 10,000 EUR on SOCIETE EXERCANT UNE ACTIVITE DE DETAIL D'HABILLEMENT EN MAGASIN SPECIALISE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 16 Dec 2021 | Centro di Medicina preventiva s.r.l.Centro di Medicina preventiva s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate measures to prevent unauthorized access to personal data. The deficiency resulted in a data breach. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jul 2022 | Stay Over s.r.l.Stay Over s.r.l. was fined by the Garante EUR 10,000 for a delayed and inadequate response to a data access request. The authority also found unlawful processing of a former employee's email account after employment ended. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Oct 2017 | Antea Service soc. coop.Antea Service soc. coop. was fined by the Garante 10,000 EUR for unlawfully processing biometric data of employees. The data were used to monitor workplace attendance. The case concerns a breach of personal data protection rules in an employment context. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Oct 2012 | Umbra Acque S.p.a.Umbra Acque S.p.a. was fined by the Garante 10,000 EUR for breaches of data protection rules. The authority found that the company failed to designate data processing officers and did not adopt minimum security measures for its video surveillance system. | IT | Garante | GDPR | €10,000 | ↗ |