Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
25 Oct 2012Dario Flaccovio Editore s.r.l.Dario Flaccovio Editore s.r.l. was fined by the Garante 8,000 EUR for sending unsolicited promotional faxes without prior explicit consent. The conduct breached data protection rules and the requirement for lawful processing.ITGaranteGDPR€8,000
11 Jan 2024Società David S.r.l.The Garante imposed an €8,000 fine on Società David S.r.l. for posting on Instagram a video of a patient undergoing a cosmetic procedure without a lawful basis. The authority found breaches of the GDPR principles of lawfulness, fairness, transparency, and purpose limitation.ITGaranteGDPR€8,000
06 Jun 2018Maganetti Spedizioni S.p.A.Maganetti Spedizioni S.p.A. was fined by the Italian Garante in the amount of €8,000. The case concerned the use of GPS devices on vehicles without adequate personal data protection measures.ITGaranteGDPR€8,000
13 Apr 2023Azienda Ospedaliera Universitaria di CagliariAzienda Ospedaliera Universitaria di Cagliari was fined EUR 8,000 by the Garante for unlawfully publishing personal data related to a disciplinary procedure online. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€8,000
18 Dec 2013Comune di MonticianoThe Municipality of Monticiano was fined 8,000 EUR by the Garante. The authority found a privacy violation after the municipality failed to provide requested information about the publication of personal data on its institutional website.ITGaranteGDPR€8,000
03 May 2018Omis s.p.a.Omis s.p.a. was fined by the Garante 8,000 EUR for failing to notify the processing of geolocation data from vehicles. This notification was required under privacy regulations.ITGaranteGDPR€8,000
10 Jul 2025Università degli Studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined €8,000 by the Garante for failing to comply with data protection rules. The case concerned improper handling of personal data requests and deficiencies in administrative procedures.ITGaranteGDPR€8,000
15 Dec 2022Comune di VicchioComune di Vicchio was fined by the Garante 8,000 EUR for using fingerprints to monitor employee attendance without appropriate legal basis and safeguards. The authority found that the biometric processing breached GDPR requirements.ITGaranteGDPR€8,000
04 Jun 2025Comune di RoccaforzataComune di Roccaforzata was fined EUR 8,000 by the Garante for publishing sensitive health data, including an employee’s disability percentage, in a council resolution. The authority found a breach of the GDPR and national privacy code provisions.ITGaranteGDPR€8,000
11 Oct 2017SANTANDER CONSUMER EFC, S.A.SANTANDER CONSUMER EFC, S.A. was fined by the AEPD for sending promotional SMS messages without the recipient’s consent. The authority also noted that the messages were sent despite the recipient’s objection to receiving advertising.ESAEPDePrivacy€8,000
05 Mar 2026Altex România S.R.L.The National Supervisory Authority for Personal Data Processing imposed fines totaling EUR 8,000 on Altex România S.R.L. for GDPR violations. The case followed complaints from data subjects.ROANSPDCPGDPR€8,000
14 May 2026Comune di VentassoComune di Ventasso was fined EUR 8,000 by the Garante. The authority found breaches of the principles of lawful, fair and transparent processing of personal data, as well as data minimization.ITGaranteGDPR€8,000
12 Feb 2021HIGHCLIFFE ESTATES MARBELLA, S.L.The company was fined by the AEPD for not providing a legal notice, privacy policy, or consent checkbox on its website. The authority also found that it used an individual's image without consent, breaching GDPR Articles 13 and 6(1).ESAEPDGDPR€8,000
17 Oct 2024ComuneThe Garante fined Comune EUR 8,000 for breaches of GDPR Articles 5, 6 and 9, and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data in the context of public employment and administrative transparency.ITGaranteGDPR€8,000
19 Jul 2013ALL THE WORLD - COSMOS ONLINEThe company was fined for sending unsolicited marketing emails without obtaining prior consent from recipients. This conduct breached ePrivacy rules governing electronic communications.GRHDPAePrivacy€8,000
10 Mar 2022Agenzia Regionale per la Tutela dell'Ambiente dell'AbruzzoThe Regional Agency for Environmental Protection of Abruzzo was fined by the Garante €8,000 for breaches of data protection principles. The violations concerned lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€8,000
07 Dec 2023Azienda OspedalieraAzienda Ospedaliera was fined EUR 8,000 by the Garante for breaches of data protection rules. The case concerned data processing principles and insufficient security measures.ITGaranteGDPR€8,000
28 Mar 2019Comune di GenovaComune di Genova was fined for unlawfully communicating personal data to third-party companies without a proper legal basis. The authority found a breach of data protection rules.ITGaranteGDPR€8,000
14 Jun 2018Osimo Servizi s.p.a.Osimo Servizi s.p.a. was fined EUR 8,000 by the Garante. The breach concerned the failure to notify the processing of biometric data used in an employee attendance system.ITGaranteGDPR€8,000
20 Aug 2024HEBERGEUR DE SITE WEB (procédure simplifiée)The CNIL imposed an administrative fine of 8,000 EUR on HEBERGEUR DE SITE WEB under a simplified procedure. The decision concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€8,000