BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Dec 2022 | Comune di Reggio EmiliaThe Municipality of Reggio Emilia was fined 8,000 EUR by the Garante for unlawfully publishing personal data, including health information, of a former employee on its website. The case concerned an unauthorized disclosure of sensitive information in breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 05 May 2011 | Mondolibri s.p.a.Mondolibri s.p.a. was fined EUR 8,000 by the Garante for collecting personal email addresses through its website without providing adequate information to the data subjects. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 31 Jan 2013 | Smart s.n.c.Smart s.n.c. was fined by the Garante in the amount of 8,000 EUR. The case concerned the sending of unsolicited promotional faxes without obtaining explicit consent, which breached data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 11 Sept 2025 | Ente Parco Regionale Migliarino San Rossore MassaciuccoliEnte Parco Regionale Migliarino San Rossore Massaciuccoli was fined EUR 8,000 by the Garante for failing to implement adequate technical and organizational measures. The authority found that more personal data was processed than necessary, in breach of the GDPR and national data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 19 Jan 2023 | A startup football clubThe Belgian data protection authority, GBA, imposed an EUR 8,000 fine on a startup football club. The case involved failure to respond to a data subject access request, as well as additional GDPR breaches concerning transparency and processor-contract requirements. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €8,000 | ↗ |
| 10 Mar 2011 | Gruppo Guide Italia s.r.l.Gruppo Guide Italia s.r.l. was fined 8,000 EUR by the Garante for publishing personal data without authorization in a guide. The case concerned a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 28 Jun 2018 | Autotrasporti Viviani s.r.l.Autotrasporti Viviani s.r.l. was fined by the Garante 8,000 EUR for failing to comply with notification obligations related to the geolocation system installed on its transport vehicles. The case concerned missing required notices regarding the processing of data. | IT | Garante | GDPR | €8,000 | ↗ |
| 23 Jan 2025 | SOCIETE DE TRANSPORT ROUTIER DE MARCHANDISES (procédure simplifiée)CNIL imposed an administrative fine of 8,000 EUR on SOCIETE DE TRANSPORT ROUTIER DE MARCHANDISES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €8,000 | ↗ |
| 14 Mar 2013 | Unitelma SapienzaUnitelma Sapienza was fined EUR 8,000 by the Garante for failing to provide information to data subjects and for not obtaining consent to process sensitive data. The violations occurred during online registration for university courses. | IT | Garante | GDPR | €8,000 | ↗ |
| 05 Mar 2020 | Azienda Sanitaria Locale di Ciriè, Chivasso e Ivrea (ASL TO4)ASL TO4 was fined by the Garante EUR 8,000 for unlawful data processing through video surveillance. The authority found that the required agreements with unions were not in place. | IT | Garante | GDPR | €8,000 | ↗ |
| 11 Sept 2025 | Provvedimento dell'11 settembre 2025 [10184654]The decision imposes a fine on a healthcare company for cybersecurity-related breaches following a security incident involving patient data. The authority found non-compliance with Articles 25 and 32 GDPR. | IT | Garante | GDPR | €8,000 | ↗ |
| 27 Nov 2025 | CANDIDAT AUX ELECTIONS AU PARLEMENT EUROPEEN DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of €8,000 on CANDIDAT AUX ELECTIONS AU PARLEMENT EUROPEEN DE 2024 and issued an injunction. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €8,000 | ↗ |
| 24 Oct 2013 | ASL n.1 – Avezzano/Sulmona/L'AquilaASL n.1 – Avezzano/Sulmona/L'Aquila was fined EUR 8,000 by the Garante. The authority found a breach consisting of failure to make the notification required under the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 24 May 2017 | LAM Centro Biomedico s.r.l.LAM Centro Biomedico s.r.l. was fined by the Garante for failing to notify the corporate name change following a merger. The case involved processing sensitive personal data, which required informing the supervisory authority. | IT | Garante | GDPR | €8,000 | ↗ |
| 01 Jan 2014 | BONANZA DIGITAL SERVICES S.L.BONANZA DIGITAL SERVICES S.L. was fined by the AEPD 8,000 EUR for sending unsolicited SMS messages promoting “Tarot del Alba”. The company did not provide an opt-out mechanism, which breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 27 Apr 2023 | Comune di AdelfiaThe Garante fined Comune di Adelfia EUR 8,000 for violations related to the publication of personal data on its institutional website. The data were later removed. | IT | Garante | GDPR | €8,000 | ↗ |
| 19 Sept 2024 | GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.GACM Seguros was fined 8,000 EUR by the AEPD for improperly sharing personal data related to an insurance claim with another insured party. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €8,000 | ↗ |
| 06 Jun 2018 | SECCHI Elettroservice S.r.l.SECCHI Elettroservice S.r.l. was fined by the Garante 8,000 EUR for failing to properly notify employees about the use of a geolocation system on company vehicles. The authority found a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 01 Jan 2016 | BANCO SANTANDER, S.A.Banco Santander, S.A. was fined by the AEPD €8,000 for sending unsolicited commercial emails. The authority found that the messages did not provide a valid email address for recipients to opt out, breaching Article 21 of the LSSI. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 26 Feb 2020 | Comune di AstiComune di Asti was fined EUR 8,000 by the Garante for unlawfully publishing personal data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €8,000 | ↗ |