BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Oct 2022 | Codess Sociale, Soc. Coop. socialeCodess Sociale, Soc. Coop. sociale was fined EUR 10,000 by the Garante. The authority found that the company failed to respond to a data subject's request to exercise GDPR rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 May 2017 | Brennercom s.p.a.Brennercom s.p.a. was fined 10,000 EUR by the Garante for inadequate password security measures. The authority found that the company's practices breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Aug 2025 | APARELLS ORTOPEDICS CURTO, S.L.APARELLS ORTOPEDICS CURTO, S.L. did not provide complete personal data and medical records in response to an access request. The AEPD found this to be a breach of data protection rules and imposed a fine of 10,000 EUR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 07 Apr 2021 | Anonymizováno (ÚOOÚ UOOU-03058/20-30)The entity did not respond to a data subject's request to delete personal data from a publicly accessible auction notice. The authority found this to be a breach of GDPR rights and imposed a monetary penalty. | CZ | UOOU | GDPR | €386 | ↗ |
| 03 Apr 2025 | SOCIETE DE COURTAGE EN TRAVAUX, CONSULTING EN BATIMENT ET TRAVAUX PUBLICS, ACHAT ET REVENTE DE MATERIEL, TRANSACTION IMMOBILIERE ET MAITRISE D'ŒUVRE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 20 Oct 2022 | Promofarma Sviluppo s.r.l.Promofarma Sviluppo s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate data security measures and for lacking transparency in the authentication process on vaccine booking portals. These shortcomings made the system vulnerable to fraudulent access and misuse. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Mar 2015 | Comune di SortinoComune di Sortino was fined for unlawfully publishing personal data revealing health information on its institutional website. The case concerned a breach of data protection rules and the improper disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2016 | Agenzia di promozione economica della ToscanaAgenzia di promozione economica della Toscana was fined 10,000 EUR by the Garante for publishing lists of disabled candidates admitted to competitive exams on its institutional websites. The authority found that this disclosure breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Mar 2025 | Οργανισμός Χρηματοδοτήσεως ΣτέγηςThe Housing Finance Corporation was fined by the CyDPC in the amount of €10,000 for retaining personal data beyond the legal retention period. The authority found this breached GDPR storage limitation and data accuracy requirements. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 31 Jan 2024 | Sectorul 1 al Municipiului BucureștiThe National Supervisory Authority for Personal Data Processing fined Sectorul 1 of Bucharest Municipality for GDPR violations. The entity failed to demonstrate compliance with a remediation measure, which formed the basis for the sanction. | RO | ANSPDCP | GDPR | €2,010 | ↗ |
| 18 May 2017 | Terrecablate reti e servizi s.r.l.Terrecablate reti e servizi s.r.l. was fined by the Garante €10,000 for inadequate security measures. The violation concerned weak password authentication on servers storing telephone traffic data. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 May 2015 | Pelamatti GiacomoPelamatti Giacomo was fined by the Garante EUR 10,000 for activating phone cards in the names of individuals without their knowledge. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 May 2024 | Azzurro Club Hotels S.r.l.Azzurro Club Hotels S.r.l. was fined by the Garante 10,000 EUR for sending promotional emails without consent. The company also failed to respond to a data subject’s request for information under Article 15 GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 May 2018 | Bolignari PietroBolignari Pietro, a general practitioner, was fined for failing to implement minimum security measures for personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Mar 2024 | NH HOTEL GROUP S.A.NH HOTEL GROUP S.A. was fined by the AEPD EUR 10,000 for using cookies on its website without obtaining user consent. The authority found this to be a breach of the LSSI rules on cookie consent. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 30 May 2022 | ASOCIACIÓN CONTRA LA CORRUPCION Y EN DEFENSA DE LA ACCIÓN PÚBLICAACODAP was fined EUR 10,000 by the AEPD for publishing complainants’ personal data on its website without anonymization. The authority found this conduct to be contrary to GDPR Article 5(1)(b). | ES | AEPD | GDPR | €10,000 | ↗ |
| 26 Oct 2020 | ***EMPRESA.1.The company was fined by the AEPD 10,000 EUR for sending an email containing personal data of a former employee to a third party without authorization. The case involved a breach of data protection principles and unauthorized disclosure of information. | ES | AEPD | GDPR | €10,000 | ↗ |
| 31 Oct 2022 | B OEThe company was fined for violations related to the operation of a video surveillance system. The authority found non-compliance with data processing principles and insufficient data minimization. | GR | HDPA | GDPR | €10,000 | ↗ |
| 16 Nov 2017 | Terre Etrusche e di Maremma Credito CooperativoThe Garante fined Terre Etrusche e di Maremma Credito Cooperativo EUR 10,000 for inadequate password security measures. The case concerned non-compliance with data protection requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Feb 2026 | GENPACT ROMANIA SRLThe National Supervisory Authority for Personal Data Processing completed an investigation into GENPACT ROMANIA SRL and found a GDPR violation. The company was fined EUR 10,000 due to the severity of the circumstances. | RO | ANSPDCP | GDPR | €10,000 | ↗ |