BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Nov 2017 | Sarida s.r.l.Sarida s.r.l. was fined by the Italian Garante 10,000 EUR for inadequate security measures in the processing of personal data. The authority specifically noted insufficient password requirements for access to the company’s systems. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Sept 2013 | Estav Nordovest ToscanaEstav Nordovest Toscana was fined 10,000 EUR by the Garante. The violation concerned the unlawful publication of candidates' judicial data on its website during a recruitment process. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Jan 2023 | NANDIVALE, S.L.NANDIVALE, S.L. was fined by the AEPD EUR 10,000 for publishing images of minors on Instagram without parental consent. The authority found this conduct to be in breach of GDPR Article 6(1). | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Mar 2017 | Ente Nazionale per L’Aviazione Civile (ENAC)ENAC was fined by the Garante in the amount of 10,000 EUR. The authority found that adequate security measures were not implemented, in breach of Articles 33 and 34 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Apr 2023 | SOCIETE D'AIDE A DOMICILE POUR LES PERSONNES AGEES ET HANDICAPEESCNIL imposed a EUR 10,000 penalty on SOCIETE D'AIDE A DOMICILE POUR LES PERSONNES AGEES ET HANDICAPEES in connection with the liquidation of a penalty payment. The case concerns compliance with a prior obligation and the sanction for non-compliance. | FR | CNIL | GDPR | €10,000 | ↗ |
| 12 Dec 2024 | Start To Fly S.r.l.Start To Fly S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited emails and SMS messages to a complainant. The complainant was unable to unsubscribe from the mailing list despite multiple attempts. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Apr 2026 | Azienda USL ModenaAzienda USL Modena was fined by the Garante in the amount of 10,000 EUR for a data breach caused by a ransomware attack. The authority found a breach of GDPR data security obligations. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Jan 2023 | KENAI MEDIA, S.L.KENAI MEDIA, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case concerned the publication of a video featuring the complainant without proper consent. | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Jun 2025 | Ordine delle Professioni Infermieristiche di ViterboThe Garante imposed a fine of EUR 10,000 on the Ordine delle Professioni Infermieristiche di Viterbo for breaches of data protection rules. The case concerned non-compliance with requirements governing the processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 03 May 2018 | Pace MarinaPace Marina, a general practitioner, was fined by the Garante for failing to implement minimum security measures to protect patients’ personal and sensitive data. This failure allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Nov 2025 | SOCIETE EXERCANT DES ACTIVITES DE SOCIETES DE HOLDING ET DEVELOPPANT DES SOLUTIONS EN RESSOURCES HUMAINES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 under a simplified procedure. The case concerns a breach of rules covered by the authority's decision. | FR | CNIL | GDPR | €10,000 | ↗ |
| 17 Jul 2025 | Associazione Il Cavallo Rosa/ChangeTheGame ODVThe Garante fined Associazione Il Cavallo Rosa/ChangeTheGame ODV 10,000 EUR for publishing a minor’s personal data on its Facebook page without anonymization. The authority found a breach of the data subject’s rights under the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 May 2018 | Ierardi TeresaIerardi Teresa, a general practitioner, was fined by the Garante for failing to adopt minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Sept 2007 | Comune di MoncalieriComune di Moncalieri was fined by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the notification obligation under Article 37 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Jul 2023 | Cat s.r.l.The Garante imposed a EUR 10,000 fine on Cat s.r.l. for operating a video surveillance system near waste bins in breach of the principles of lawfulness, fairness, and transparency. The case concerned the data of residents and non-residents of the Comune di Modica. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Nov 2019 | BANCO BILBAO VIZCAYA ARGENTARIA SLBBVA was fined by the AEPD for sending unsolicited advertising to an individual who was not a customer of the bank. The authority found this to be a breach of data protection rules. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 14 Jan 2021 | Comune di Falconara MarittimaComune di Falconara Marittima was fined EUR 10,000 by the Garante for violating data protection principles. The authority found improper processing of personal data in a disciplinary context, including breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Nov 2014 | Associazione sportiva dilettantistica Sport Fashion (A.S.D. Sport Fashion)The sports association was fined by the Garante 10,000 EUR for processing clients' biometric data without the required information and consent. The authority found this to be a breach of privacy rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Dec 2020 | Comune di LuinoComune di Luino was fined EUR 10,000 by the Garante for unlawfully disclosing personal data online. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Centro diagnostico Helios s.n.c.Centro diagnostico Helios s.n.c. was fined for failing to notify the processing of sensitive health data, including HIV status and other medical conditions. The authority treated this as a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |