Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Nov 2017Sarida s.r.l.Sarida s.r.l. was fined by the Italian Garante 10,000 EUR for inadequate security measures in the processing of personal data. The authority specifically noted insufficient password requirements for access to the company’s systems.ITGaranteGDPR€10,000
19 Sept 2013Estav Nordovest ToscanaEstav Nordovest Toscana was fined 10,000 EUR by the Garante. The violation concerned the unlawful publication of candidates' judicial data on its website during a recruitment process.ITGaranteGDPR€10,000
09 Jan 2023NANDIVALE, S.L.NANDIVALE, S.L. was fined by the AEPD EUR 10,000 for publishing images of minors on Instagram without parental consent. The authority found this conduct to be in breach of GDPR Article 6(1).ESAEPDGDPR€10,000
23 Mar 2017Ente Nazionale per L’Aviazione Civile (ENAC)ENAC was fined by the Garante in the amount of 10,000 EUR. The authority found that adequate security measures were not implemented, in breach of Articles 33 and 34 of the Italian Data Protection Code.ITGaranteGDPR€10,000
17 Apr 2023SOCIETE D'AIDE A DOMICILE POUR LES PERSONNES AGEES ET HANDICAPEESCNIL imposed a EUR 10,000 penalty on SOCIETE D'AIDE A DOMICILE POUR LES PERSONNES AGEES ET HANDICAPEES in connection with the liquidation of a penalty payment. The case concerns compliance with a prior obligation and the sanction for non-compliance.FRCNILGDPR€10,000
12 Dec 2024Start To Fly S.r.l.Start To Fly S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited emails and SMS messages to a complainant. The complainant was unable to unsubscribe from the mailing list despite multiple attempts.ITGaranteGDPR€10,000
17 Apr 2026Azienda USL ModenaAzienda USL Modena was fined by the Garante in the amount of 10,000 EUR for a data breach caused by a ransomware attack. The authority found a breach of GDPR data security obligations.ITGaranteGDPR€10,000
11 Jan 2023KENAI MEDIA, S.L.KENAI MEDIA, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case concerned the publication of a video featuring the complainant without proper consent.ESAEPDGDPR€10,000
23 Jun 2025Ordine delle Professioni Infermieristiche di ViterboThe Garante imposed a fine of EUR 10,000 on the Ordine delle Professioni Infermieristiche di Viterbo for breaches of data protection rules. The case concerned non-compliance with requirements governing the processing of personal data.ITGaranteGDPR€10,000
03 May 2018Pace MarinaPace Marina, a general practitioner, was fined by the Garante for failing to implement minimum security measures to protect patients’ personal and sensitive data. This failure allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
20 Nov 2025SOCIETE EXERCANT DES ACTIVITES DE SOCIETES DE HOLDING ET DEVELOPPANT DES SOLUTIONS EN RESSOURCES HUMAINES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 under a simplified procedure. The case concerns a breach of rules covered by the authority's decision.FRCNILGDPR€10,000
17 Jul 2025Associazione Il Cavallo Rosa/ChangeTheGame ODVThe Garante fined Associazione Il Cavallo Rosa/ChangeTheGame ODV 10,000 EUR for publishing a minor’s personal data on its Facebook page without anonymization. The authority found a breach of the data subject’s rights under the GDPR.ITGaranteGDPR€10,000
16 May 2018Ierardi TeresaIerardi Teresa, a general practitioner, was fined by the Garante for failing to adopt minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
13 Sept 2007Comune di MoncalieriComune di Moncalieri was fined by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the notification obligation under Article 37 of the Italian Data Protection Code.ITGaranteGDPR€10,000
18 Jul 2023Cat s.r.l.The Garante imposed a EUR 10,000 fine on Cat s.r.l. for operating a video surveillance system near waste bins in breach of the principles of lawfulness, fairness, and transparency. The case concerned the data of residents and non-residents of the Comune di Modica.ITGaranteGDPR€10,000
29 Nov 2019BANCO BILBAO VIZCAYA ARGENTARIA SLBBVA was fined by the AEPD for sending unsolicited advertising to an individual who was not a customer of the bank. The authority found this to be a breach of data protection rules.ESAEPDePrivacy€10,000
14 Jan 2021Comune di Falconara MarittimaComune di Falconara Marittima was fined EUR 10,000 by the Garante for violating data protection principles. The authority found improper processing of personal data in a disciplinary context, including breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€10,000
12 Nov 2014Associazione sportiva dilettantistica Sport Fashion (A.S.D. Sport Fashion)The sports association was fined by the Garante 10,000 EUR for processing clients' biometric data without the required information and consent. The authority found this to be a breach of privacy rules.ITGaranteGDPR€10,000
17 Dec 2020Comune di LuinoComune di Luino was fined EUR 10,000 by the Garante for unlawfully disclosing personal data online. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€10,000
14 Sept 2006Centro diagnostico Helios s.n.c.Centro diagnostico Helios s.n.c. was fined for failing to notify the processing of sensitive health data, including HIV status and other medical conditions. The authority treated this as a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000