BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Oct 2015 | Comune di Loiri Porto San PaoloThe Municipality of Comune di Loiri Porto San Paolo was fined by the Garante 10,000 EUR for publishing personal data on its website that revealed health status. The case involved unlawful disclosure of sensitive data in breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Jan 2026 | Istituto tecnico industriale statale “Stanislao Cannizzaro” di CataniaIstituto tecnico industriale statale “Stanislao Cannizzaro” di Catania was fined by the Garante €10,000 for breaches of data protection principles. The authority found that personal data were processed in a manner that was not lawful, fair, or transparent. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 May 2021 | TNT EXPRESS WORLDWIDE SPAIN, S.L.TNT Express Worldwide Spain, S.L. was fined by the AEPD €10,000 for incorrectly linking a personal delivery service to a corporate account. This resulted in the unauthorized sharing of personal data with the complainant’s employer. | ES | AEPD | GDPR | €10,000 | ↗ |
| 11 Sept 2025 | ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD for disclosing personal data, including a handwritten signature, in a news broadcast without necessity. The authority found that the disclosure breached data protection principles because it was not proportionate to the purpose of the publication. | ES | AEPD | GDPR | €10,000 | ↗ |
| 26 Mar 2010 | Lenzi automobili s.p.a.Lenzi automobili s.p.a. was fined by the Garante for using a biometric system to verify employee attendance without the required authorization. This constituted a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2025 | ASESORAMOS TU FORMACIÓN CON CALIDAD S.L.ASESORAMOS TU FORMACIÓN CON CALIDAD S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case also involved the improper inclusion of individuals in credit information systems. | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE BAENA NTRA. SRA. DE GUADALUPE, S.C.C.A.CAJA RURAL DE BAENA was fined by the AEPD 10,000 EUR for breaching data protection principles. The case involved failures in confidentiality and integrity of personal data, which led to unauthorized access by third parties. | ES | AEPD | GDPR | €10,000 | ↗ |
| 17 Feb 2021 | VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD 10,000 EUR for sending an unsolicited commercial SMS to a complainant without prior consent. The authority found that the message was sent without the required authorization. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 11 Feb 2025 | AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD 10,000 EUR for sending unsolicited email messages and failing to properly handle unsubscribe requests. The conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 16 Apr 2015 | Media Lab Italia s.r.l.Media Lab Italia s.r.l. was fined by the Garante EUR 10,000 for processing personal data through a website form without obtaining separate consent for different purposes. The purposes included promotional communications and market research. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 May 2011 | Eredi Trossello dei Fratelli Trossello C.A.R. s.n.c.The company was fined EUR 10,000 by the Garante for operating a video surveillance system without the required privacy notice. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Molise dati S.p.A.Molise dati S.p.A. was fined EUR 10,000 by the Garante for a data breach involving the regional health portal. A system vulnerability allowed unauthorized access to personal data of citizens in the Molise Regional Registry. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Dec 2014 | Comune di NapoliComune di Napoli was fined 10,000 EUR by the Garante for publishing substitute teachers’ personal information, including health-related data, on its institutional website. The authority found that this disclosure breached privacy rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Mar 2023 | Gruppo SAE S.p.A.The Garante fined Gruppo SAE S.p.A. 10,000 EUR for publishing sensitive personal data, including medical information, in an article without proper consent. The case concerns unlawful processing of special-category personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Sept 2019 | ASOCIACION DE MEDICOS DEMOCRATASASOCIACION DE MEDICOS DEMOCRATAS was fined by the AEPD EUR 10,000 for processing the personal data of medical professionals without their consent. The authority found a breach of Article 6(1)(a) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 16 Dec 2021 | ASL LatinaASL Latina was fined for violations of data protection rules. The authority found inadequate measures to prevent data breaches involving health data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Maximum International Corp. S.r.l.Maximum International Corp. S.r.l. was fined by the Garante 10,000 EUR for persistent promotional calls despite objections and for failing to respond to data subject requests. The authority found breaches of GDPR rules on consent and information obligations. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Sept 2025 | La Prima SrlLa Prima Srl was fined EUR 10,000 by the Garante for sending unsolicited emails. The authority also found that the company failed to respond to a data deletion request, in breach of the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Adolfo AllegriniAdolfo Allegrini, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Sept 2017 | Serval s.r.l.Serval s.r.l. was fined by the Garante in the amount of €10,000 for failing to adopt minimum security measures. The authority also found that employees were not appointed as data processors, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |