Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 May 2018Luigi PagnanelliLuigi Pagnanelli, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
05 Feb 2015Comune di BellizziComune di Bellizzi was fined for unlawfully publishing sensitive personal data revealing health information on its institutional website. The conduct breached privacy rules governing the processing and disclosure of sensitive data.ITGaranteGDPR€10,000
27 Nov 2024Comune di Motta Sant'AnastasiaThe Garante imposed a EUR 10,000 fine on Comune di Motta Sant'Anastasia for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper processing of personal data.ITGaranteGDPR€10,000
03 Nov 2020LOSADA ADVOCATS S.L.LOSADA ADVOCATS S.L. was fined by the AEPD EUR 10,000 for sending an email without using BCC. This exposed recipients’ email addresses and breached data protection principles.ESAEPDGDPR€10,000
01 Apr 2009Casa di cura Sant'Antonio s.p.a.Casa di cura Sant'Antonio s.p.a. was fined by the Italian data protection authority, Garante. The case concerned processing personal data without the required notification under the Italian Data Protection Code.ITGaranteGDPR€10,000
13 Mar 2015HYUNDAY MOTOR ESPAÑA, S.L.U.HYUNDAY MOTOR ESPAÑA, S.L.U. was fined 10,000 EUR by the AEPD. The sanction concerned sending unsolicited commercial emails without recipient consent, in breach of the LSSI.ESAEPDePrivacy€10,000
13 Feb 2025Claudio BattagliaDr. Claudio Battaglia, an oncologist, was fined for using patient data for electoral propaganda without consent. The case indicates a breach of GDPR principles on lawfulness and purpose limitation.ITGaranteGDPR€10,000
17 May 2023La Gazzetta di Parma S.r.l.La Gazzetta di Parma S.r.l. was fined by the Garante EUR 10,000 for publishing an image of a presumed murderer in breach of privacy rules. The person was shown in a state of physical restraint without proper anonymization.ITGaranteGDPR€10,000
23 Aug 2023BODY LINE SRLIn July 2023, the Romanian authority ANSPDCP completed an investigation at BODY LINE SRL and found violations of GDPR provisions. The operator was fined 49,322 lei, equivalent to EUR 10,000.ROANSPDCPGDPR€10,000
30 Jul 2015Comune di MontallegroComune di Montallegro was fined for publishing documents on its website that contained sensitive personal data revealing individuals' health conditions. This constituted a breach of data protection law.ITGaranteGDPR€10,000
31 Aug 2023Provvedimento del 31 agosto 2023 [9938463]The decision concerned a breach of rules on the processing of health data by a medical center. Garante imposed a fine of EUR 10,000.ITGaranteGDPR€10,000
09 May 2023Dane anonimowe (Burmistrza Miasta i Gminy W.)UODO imposed an administrative fine of PLN 10,000 on the Mayor of the City and Commune of W. for failing to implement organisational measures appropriate to the risk of data processing. The deficiency resulted in an employee unlawfully copying personal data from a work computer to a portable storage device.PLUODOGDPR€2,187
10 Dec 2024un operatorANSPDCP imposed a fine of 10,000 RON on un operator for non-compliance with the law. A warning was also issued.ROANSPDCPGDPR€2,012
22 Jan 2015Comune di RealmonteComune di Realmonte was fined by the Garante for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy and data protection rules.ITGaranteGDPR€10,000
15 Mar 2023Alianța pentru Unirea RomânilorThe fine was imposed for collecting personal data through a website without informing the data subjects and without meeting the conditions for lawful processing. The breach affected a significant number of individuals and indicates non-compliance with basic transparency and legality requirements.ROANSPDCPGDPR€10,000
29 Apr 2025Energia Pulita S.r.l.Energia Pulita S.r.l. was fined by the Garante for improper handling of personal data in telemarketing activities. The authority also noted failure to cooperate with the supervisory authority and incorrect identification of roles in data processing.ITGaranteGDPR€10,000
22 Jul 2021Regione CalabriaThe Garante imposed a 10,000 EUR fine on Regione Calabria for publishing personal data on its website. The conduct breached GDPR rules on lawful processing and protection of personal data.ITGaranteGDPR€10,000
07 Feb 2025ESTUDIO ALCAZAR DEL GENIL 2022, S.L.ESTUDIO ALCAZAR DEL GENIL 2022, S.L. was fined EUR 10,000 by the AEPD for collecting and storing personal data taken from mailboxes without consent or notice to the data subjects. The authority found breaches of the lawful basis and transparency requirements under GDPR Articles 6(1) and 14.ESAEPDGDPR€10,000
14 Sept 2006Azienda sanitaria locale di PiacenzaAzienda sanitaria locale di Piacenza was fined for failing to notify the Garante about processing data relating to health and sexual life. The authority treated this as a breach of the Italian Privacy Code.ITGaranteGDPR€10,000
19 Dec 2024Comune di BresciaThe Garante fined the Municipality of Brescia EUR 10,000 for violations related to the processing of personal data at a cemetery. The case concerned the unauthorized disclosure of individuals’ identities.ITGaranteGDPR€10,000