BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 May 2018 | Luigi PagnanelliLuigi Pagnanelli, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Feb 2015 | Comune di BellizziComune di Bellizzi was fined for unlawfully publishing sensitive personal data revealing health information on its institutional website. The conduct breached privacy rules governing the processing and disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Comune di Motta Sant'AnastasiaThe Garante imposed a EUR 10,000 fine on Comune di Motta Sant'Anastasia for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 03 Nov 2020 | LOSADA ADVOCATS S.L.LOSADA ADVOCATS S.L. was fined by the AEPD EUR 10,000 for sending an email without using BCC. This exposed recipients’ email addresses and breached data protection principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Apr 2009 | Casa di cura Sant'Antonio s.p.a.Casa di cura Sant'Antonio s.p.a. was fined by the Italian data protection authority, Garante. The case concerned processing personal data without the required notification under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Mar 2015 | HYUNDAY MOTOR ESPAÑA, S.L.U.HYUNDAY MOTOR ESPAÑA, S.L.U. was fined 10,000 EUR by the AEPD. The sanction concerned sending unsolicited commercial emails without recipient consent, in breach of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 13 Feb 2025 | Claudio BattagliaDr. Claudio Battaglia, an oncologist, was fined for using patient data for electoral propaganda without consent. The case indicates a breach of GDPR principles on lawfulness and purpose limitation. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | La Gazzetta di Parma S.r.l.La Gazzetta di Parma S.r.l. was fined by the Garante EUR 10,000 for publishing an image of a presumed murderer in breach of privacy rules. The person was shown in a state of physical restraint without proper anonymization. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Aug 2023 | BODY LINE SRLIn July 2023, the Romanian authority ANSPDCP completed an investigation at BODY LINE SRL and found violations of GDPR provisions. The operator was fined 49,322 lei, equivalent to EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 30 Jul 2015 | Comune di MontallegroComune di Montallegro was fined for publishing documents on its website that contained sensitive personal data revealing individuals' health conditions. This constituted a breach of data protection law. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 Aug 2023 | Provvedimento del 31 agosto 2023 [9938463]The decision concerned a breach of rules on the processing of health data by a medical center. Garante imposed a fine of EUR 10,000. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 May 2023 | Dane anonimowe (Burmistrza Miasta i Gminy W.)UODO imposed an administrative fine of PLN 10,000 on the Mayor of the City and Commune of W. for failing to implement organisational measures appropriate to the risk of data processing. The deficiency resulted in an employee unlawfully copying personal data from a work computer to a portable storage device. | PL | UODO | GDPR | €2,187 | ↗ |
| 10 Dec 2024 | un operatorANSPDCP imposed a fine of 10,000 RON on un operator for non-compliance with the law. A warning was also issued. | RO | ANSPDCP | GDPR | €2,012 | ↗ |
| 22 Jan 2015 | Comune di RealmonteComune di Realmonte was fined by the Garante for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Mar 2023 | Alianța pentru Unirea RomânilorThe fine was imposed for collecting personal data through a website without informing the data subjects and without meeting the conditions for lawful processing. The breach affected a significant number of individuals and indicates non-compliance with basic transparency and legality requirements. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 29 Apr 2025 | Energia Pulita S.r.l.Energia Pulita S.r.l. was fined by the Garante for improper handling of personal data in telemarketing activities. The authority also noted failure to cooperate with the supervisory authority and incorrect identification of roles in data processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Jul 2021 | Regione CalabriaThe Garante imposed a 10,000 EUR fine on Regione Calabria for publishing personal data on its website. The conduct breached GDPR rules on lawful processing and protection of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Feb 2025 | ESTUDIO ALCAZAR DEL GENIL 2022, S.L.ESTUDIO ALCAZAR DEL GENIL 2022, S.L. was fined EUR 10,000 by the AEPD for collecting and storing personal data taken from mailboxes without consent or notice to the data subjects. The authority found breaches of the lawful basis and transparency requirements under GDPR Articles 6(1) and 14. | ES | AEPD | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale di PiacenzaAzienda sanitaria locale di Piacenza was fined for failing to notify the Garante about processing data relating to health and sexual life. The authority treated this as a breach of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Dec 2024 | Comune di BresciaThe Garante fined the Municipality of Brescia EUR 10,000 for violations related to the processing of personal data at a cemetery. The case concerned the unauthorized disclosure of individuals’ identities. | IT | Garante | GDPR | €10,000 | ↗ |