BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Apr 2025 | Immobiliare Valdalpone S.r.l.Immobiliare Valdalpone S.r.l. was fined by the Garante 15,000 EUR for making unsolicited marketing calls without proper consent. The authority also found inadequate data protection measures. | IT | Garante | GDPR | €15,000 | ↗ |
| 15 Sept 2022 | Immobiliare Riscostruzione Meloria s.r.l.The company was fined by the Garante in the amount of 2,000 EUR for installing a video surveillance system without the required informational signage. This breached GDPR rules on transparency and the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €2,000 | ↗ |
| 17 Oct 2024 | Immobiliare Pianezza S.r.l.s.Immobiliare Pianezza S.r.l.s. was fined €5,000 by the Garante for making unsolicited marketing calls without consent. The authority also noted a failure to respond to requests for deletion of personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 08 Jun 2021 | IMAGINA FRAN SPORT, S.L.IMAGINA FRAN SPORT, S.L. was fined 2,000 EUR by the AEPD for not having an updated privacy policy on its website. The authority found a breach of the information obligations under GDPR Article 13. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Sept 2025 | ILVA A/SVestre Landsret upheld a DKK 1.5 million GDPR fine against ILVA A/S. The case concerned retention of data on about 385,000 customers without a deletion policy, and the fine was based on the group’s total turnover. | DK | Datatilsynet | GDPR | €200,000 | ↗ |
| 01 Mar 2023 | ILUROBOX, S.L.ILUROBOX, S.L. was fined by the AEPD EUR 3,000 for including individuals in a WhatsApp group without their consent. The authority found that this breached Article 6(1) GDPR because there was no lawful basis for the processing. | ES | AEPD | GDPR | €3,000 | ↗ |
| 19 Dec 2012 | Il Tetto srlIl Tetto srl was fined EUR 6,400 by the Garante for sending unsolicited promotional faxes. The authority found that prior, specific, and informed consent from recipients had not been obtained, in breach of data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 14 Jul 2011 | Il Tarì società consortile per azioniIl Tarì società consortile per azioni was fined €30,000 by the Garante for failing to provide adequate information and notification about the processing of personal data using biometric systems. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 28 Apr 2022 | Il Sole 24 Ore S.p.a.Il Sole 24 Ore S.p.a. was fined by the Garante EUR 40,000 for publishing a court order containing the personal data of an adopted minor. The authority also found an incomplete and delayed response to a data access request. | IT | Garante | GDPR | €40,000 | ↗ |
| 04 Oct 2011 | Il Marmo s.r.l.Il Marmo s.r.l. was fined by the Garante in the amount of 10,000 EUR for failing to provide the required privacy notice on its website, specifically in the contact form. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Nov 2024 | Illumia S.p.A.Illumia S.p.A. was fined by the Italian data protection authority, Garante, for violations related to the processing of personal data for telemarketing purposes. The authority cited inadequate contractual arrangements with sub-processors and insufficient oversight of commercial partners. | IT | Garante | GDPR | €678,000 | ↗ |
| 17 Jul 2024 | Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 50,000 by the Garante for sending promotional emails without obtaining proper customer consent. The authority found this conduct to be a breach of GDPR rules on electronic marketing. | IT | Garante | GDPR | €50,000 | ↗ |
| 09 Jul 2020 | Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 800,000 by the Garante for irregularities in the processing of customer data. The violations concerned SIM card activation, promotional use of data, inadequate security measures, and improper data retention. | IT | Garante | GDPR | €800,000 | ↗ |
| 03 Feb 2011 | Il Filo s.r.l.Il Filo s.r.l. was fined by the Garante in the amount of €6,000 for processing personal data without providing the required information notice to data subjects. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 02 Mar 2023 | Il Fatto Quotidiano S.p.A.The Garante fined Il Fatto Quotidiano S.p.A. EUR 20,000 for the unlawful dissemination of personal data linked to a judicial case involving the complainants' father. The authority found that the publication breached personal data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 10 Mar 2016 | Il Desiderio s.a.s.Il Desiderio s.a.s. was fined EUR 2,400 by the Garante for failing to provide adequate simplified information about video surveillance. The breach concerned Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 02 Dec 2022 | IK "Rigas Komunal Service"A fine of 500 EUR was imposed by the DVI. The decision was appealed. | LV | DVI | GDPR | €500 | ↗ |
| 01 Nov 2021 | IKEA ROMÂNIA SAIKEA ROMÂNIA SA was fined EUR 1,000 by ANSPDCP for compromising data confidentiality. The case concerned processing practices that were not compliant with GDPR and could affect data subjects’ rights. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 01 Jan 2019 | IKEA IBERICA, S.A.U.The AEPD fined IKEA IBERICA, S.A.U. 10,000 EUR for installing cookies on users’ devices without obtaining prior informed consent. The authority found this breached Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 07 Apr 2021 | Ignatiadis Nikolaos and SIA E.E.The company was fined for unlawfully using a surveillance camera to monitor employees. The authority found a breach of data protection principles and an absence of a valid legal basis for processing. | GR | HDPA | GDPR | €2,000 | ↗ |