BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Dec 2022 | ODRIA COSTAS INTERNACIONAL, S.L.ODRIA COSTAS INTERNACIONAL, S.L. was fined EUR 10,000 by the AEPD for publishing images of minors without consent on a real estate website. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 11 Feb 2016 | E-Via s.p.a.E-Via s.p.a. was fined 10,000 EUR by the Garante for failing to implement minimum security measures in the processing of telematic traffic data. The authority found a breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Jul 2021 | FUTURE VINLINE SLFUTURE VINLINE SL was fined by the AEPD EUR 10,000 for not having an adequate privacy policy on its website. The authority found that the company failed to provide clear and complete information about data processing under Article 13 GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 31 Aug 2023 | RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined by the Garante EUR 10,000 for publishing an article on the Corriere della Sera website. The article included a photograph of a holographic will that disclosed a witness’s personal data without consent. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 May 2022 | Geanonimiseerd (APD 84/2022)The case concerns a complaint by the Ordre des Barreaux Francophones de Belgique against sos-services.be and sos-avocats.be. The authority found that lawyers were listed without a legal basis and with incorrect information, in breach of GDPR and ePrivacy rules. | BE | APD | ePrivacy | €10,000 | ↗ |
| 11 Mar 2025 | LÁSER METALPRINT 3D, S.L.LÁSER METALPRINT 3D, S.L. was fined by the AEPD 10,000 EUR for deploying a video surveillance system without proper data processing agreements. The authority found a breach of GDPR Article 28. | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Oct 2025 | Provvedimento del 23 ottobre 2025 [10210718]The Garante imposed a EUR 10,000 fine on an individual tobacco shop owner for suspicious financial transactions involving the misuse of a third party’s identification data with a prepaid card. The case concerns unauthorized use of personal data in the context of payment operations. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Jun 2017 | Vodafone-PanafonVodafone-Panafon was fined EUR 10,000 by the HDPA for a significant delay in responding to a data subject access request. The authority found a breach of Article 12 of Law L.2472/1997. | GR | HDPA | GDPR | €10,000 | ↗ |
| 05 Feb 2015 | Comune di San Giuseppe JatoComune di San Giuseppe Jato was fined by the Garante for unlawfully publishing sensitive personal data revealing health status on its website. The conduct breached privacy rules governing the processing and disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Sept 2013 | Azienda USL ViterboAzienda USL Viterbo was fined for failing to implement minimum security measures and for not appointing data processing officers. The authority also noted that the security program document was not updated between 2006 and 2010. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Jul 2024 | PUBLICACIONES Y EDICIONES BARACA 208, S.L.The company published personal data, including health information, in a digital newspaper article. The authority found a breach of data minimisation and the rules on special category data under GDPR Articles 5(1)(c) and 9. | ES | AEPD | GDPR | €10,000 | ↗ |
| 06 Jan 2022 | B.B.B.A fine was imposed for the mass dissemination of a video recorded without the victim’s consent on social media and via WhatsApp. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 22 May 2013 | Margiotta Pietro Antonio e ASL TA 1 – Azienda Sanitaria Locale di TarantoThe Garante fined Margiotta Pietro Antonio and ASL TA 1 10,000 EUR for failing to implement minimum security measures. In some departments, unauthorized personnel accessed patient data and shared authentication credentials were used. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE D'HOTELLERIE ET D'HEBERGEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE D'HOTELLERIE ET D'HEBERGEMENT. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 18 Jan 2022 | MAJESTIC SOLUTIONS S.L.MAJESTIC SOLUTIONS S.L. was fined by the AEPD 10,000 EUR for failing to provide all required information to affected individuals after a personal data security breach. The authority found a breach of Article 34(2) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jun 2025 | Călin GeorgescuCălin Georgescu was sanctioned by Romania’s data protection authority after an investigation into his website. Two fines totaling about EUR 10,000 were imposed for installing cookies without consent and collecting personal data without proper notice. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €10,000 | ↗ |
| 01 Jan 2015 | FEVER LABS INCFEVER LABS INC was fined EUR 10,000 by the AEPD for sending unsolicited commercial emails. The authority found that the messages did not include a simple and free way for recipients to opt out of further communications, in breach of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 20 Jun 2024 | TS Food Processing S.r.l.TS Food Processing S.r.l. was fined by the Garante for refusing an employee's request to access personal data related to employment. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Mar 2025 | Casatua S.r.l.Casatua S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited communications via WhatsApp without obtaining proper recipient consent. The company also failed to implement adequate procedures to ensure compliance with data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jun 2013 | Comune di PadovaComune di Padova was fined by the Garante 10,000 EUR for unlawfully publishing personal data online beyond the legally permitted period. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |