Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Jan 2023Εκδόσεις Αρκτίνος ΛτδThe decision concerns the unlawful publication of names and photos of police investigators by the newspaper “Politis”. The authority found a breach of the data minimization principle under the GDPR.CYCyDPCGDPR€10,000
03 Jul 2025BANCO INVERSIS, S.A.Banco Inversis, S.A. was fined by the AEPD in the amount of 10,000 EUR for a personal data breach. The case involved unauthorized access to personal data, which breached Article 5(1)(f) of the GDPR.ESAEPDGDPR€10,000
15 Sept 2022Bper Banca S.p.A.Bper Banca S.p.A. was fined by the Garante for a delayed and inadequate response to requests for deletion of personal data. The authority found breaches of GDPR Articles 12 and 17.ITGaranteGDPR€10,000
24 Mar 2022Brav s.r.l.Brav s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate technical and organizational security measures. The issue concerned data processing linked to the management of contraventions by the local police of the Municipality of Genoa.ITGaranteGDPR€10,000
13 Nov 2024Thermogen S.r.l.Thermogen S.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The conduct breached the GDPR and national privacy laws.ITGaranteGDPR€10,000
08 Jun 2023Liguria News S.r.l.Liguria News S.r.l. was fined by Garante EUR 10,000 for publishing an article that breached privacy rules. The article disclosed personal and sensitive information about individuals involved in the reported incident, including a minor.ITGaranteGDPR€10,000
22 May 2018De Nittis MicheleDe Nittis Michele, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This deficiency allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
24 Jul 2024FREE TECHNOLOGIES EXCOM, S.L.FREE TECHNOLOGIES EXCOM, S.L. was fined by the AEPD 10,000 EUR for sending unencrypted emails containing user credentials without prior notice. The authority also noted the absence of two-factor authentication, which constituted a breach of Article 32 GDPR.ESAEPDGDPR€10,000
08 Feb 2007Asl Vibo ValentiaThe health authority Asl Vibo Valentia was fined by Garante for improperly handling sensitive personal data, including genetic and biometric data, without proper authorization. The case concerns a breach of data protection rules and the legal basis required for processing such data.ITGaranteGDPR€10,000
17 Jan 2008Aesculapius s.r.l.Aesculapius s.r.l. was fined by the Garante for missing the deadline to notify personal data processing activities. The breach concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
05 Oct 2017Italprest di Luca Bosimini & C. s.a.s.Italprest di Luca Bosimini & C. s.a.s. was fined €10,000 by the Garante. The authority found that the company failed to implement minimum security measures, including the use of passwords shorter than eight characters, in breach of Article 33 of the Italian Data Protection Code.ITGaranteGDPR€10,000
21 Dec 2023MediafondMediafond was fined EUR 10,000 by the Garante for continuing to use a former employee’s email account after the employment ended. The company also forwarded emails without proper notice, which breached GDPR requirements.ITGaranteGDPR€10,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined 10,000 EUR by the HDPA. The authority found that the bank did not adequately satisfy the data subject’s right of access.GRHDPAGDPR€10,000
13 Feb 2007Asl n. 5 CrotoneAsl n. 5 Crotone was fined by the Garante for failing to notify the processing of sensitive personal data, including genetic and health data. The notification requirement was set out in the Italian Data Protection Code.ITGaranteGDPR€10,000
07 Apr 2022Findomestic Banca spaFindomestic Banca spa was fined by the Garante 10,000 EUR for improperly contacting a third party, namely the debtor’s spouse, about a financial obligation. The authority found that this conduct constituted a GDPR violation.ITGaranteGDPR€10,000
10 Jun 2025Accounting Audit SRLAccounting Audit SRL was fined by ANSPDCP for a data security breach caused by a cyber attack. The incident led to unauthorized disclosure of personal data, including identification data and financial documents, affecting a large number of data subjects, mainly employees of the company’s clients.ROANSPDCPGDPR€10,000
01 Oct 2015dr. Ruben Omar UnzurrunzagaDr. Ruben Omar Unzurrunzaga was fined by the Garante for processing clients’ personal data for medical purposes without obtaining documented consent. The authority found a breach of Article 23 of the Italian Data Protection Code.ITGaranteGDPR€10,000
10 Jul 2025Cooperativa Sociale CoopseliosCooperativa Sociale Coopselios was fined by the Garante €10,000 for failing to properly handle data subject requests. The нарушения concerned the GDPR rights of access, rectification, and data portability.ITGaranteGDPR€10,000
21 Jul 2022Clio s.r.l.Clio s.r.l. was fined by the Italian Garante in the amount of 10,000 EUR for violations related to personal data processing. The case involved inadequate protection of whistleblower identities, in breach of the GDPR and national privacy code provisions.ITGaranteGDPR€10,000
14 Sept 2023Comune di San SeveroThe Municipality of San Severo was fined EUR 10,000 by the Garante for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€10,000