BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Apr 2024 | GS S.p.A.GS S.p.A. was fined by the Garante for failing to respond to an employee's access request. The request concerned disciplinary records and work time stamps, which constitutes a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Dec 2012 | Euro-Catering O.E.The company was fined for failing to comply with a prior decision by the authority. It was noted that it no longer operated the stores concerned and that its financial situation was difficult. | GR | HDPA | GDPR | €10,000 | ↗ |
| 21 Jul 2016 | Comune di CanicattìComune di Canicattì was fined for publishing personal data, including health information, on its website. The authority found that this breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Sept 2007 | Azienda sanitaria locale Avellino 1Azienda sanitaria locale Avellino 1 was fined by the Garante in the amount of 10,000 EUR. The authority found that the entity failed to notify the processing of sensitive personal data, including genetic and biometric data, as required by the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Feb 2020 | Azienda Unità Sanitaria Locale Toscana CentroAzienda Unità Sanitaria Locale Toscana Centro was fined by the Garante 10,000 EUR for violations related to data processing in the health sector. The case concerned the handling of patient data without full compliance with GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Jun 2017 | F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante in the amount of 10,000 EUR for making unsolicited promotional calls to a number listed in the public opposition registry. The conduct breached data protection rules and the right to object to direct marketing. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale n. 6 di CirièASL Ciriè was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The breach concerned obligations under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Jun 2018 | Luigi Di CesareLuigi Di Cesare was fined EUR 10,000 by the Garante for failing to implement minimum security measures. The breach led to the unauthorized disclosure of medical reports to a third party. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Mar 2017 | Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined EUR 10,000 by the HDPA. The authority found that the bank did not adequately satisfy the complainant’s right of access to recorded telephone conversations. The case concerned the legal obligation to provide access to such recordings. | GR | HDPA | GDPR | €10,000 | ↗ |
| 13 Sept 2007 | Azienda sanitaria locale di Lanciano/VastoAzienda sanitaria locale di Lanciano/Vasto was fined by the Garante 10,000 EUR for improper handling of sensitive personal data. The case involved genetic and biometric data processed without proper authorization. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Dec 2024 | SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT under a simplified procedure. The decision dates from 12 December 2024. | FR | CNIL | GDPR | €10,000 | ↗ |
| 19 Dec 2023 | Sąd Okręgowy w Krakowie za naruszenie art. 33 ust. 1 i ust. 2 oraz art. 34 ust. 1 i ust. 2 rozporządzenia 2016/679UODO imposed an administrative fine of 10,000 PLN on the Regional Court in Kraków. The case concerns breaches of obligations related to personal data breach notification and informing affected individuals. | PL | UODO | GDPR | €2,306 | ↗ |
| 07 Mar 2019 | Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined for unlawfully processing judicial data by communicating information about an ongoing criminal proceeding without a legal basis. The case concerned a breach of the rules governing the lawful processing of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2023 | LOCAL VERTICALS, S.L.The company was fined by the AEPD in the amount of 10,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 05 Feb 2015 | Azienda Regionale per il diritto allo studio universitario della ToscanaAzienda Regionale per il diritto allo studio universitario della Toscana was fined EUR 10,000 by the Garante. The authority found that its website unlawfully disclosed personal data revealing the health status of students with disabilities. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Mar 2018 | Società agricola Medici Claudio s.r.l.The company was fined for failing to comply with data protection obligations. The breach concerned not providing personal data and information related to employment management when requested by the Garante. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 May 2024 | KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD 10,000 EUR for requiring a customer to provide a photo with their ID to cancel a loan. The authority found that this processing breached GDPR principles of data minimisation and proportionality. | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Jun 2025 | Società Autocooperative Trasporti Italiani S.p.A.The company was fined by the Garante for unlawfully disclosing sensitive personal data about employee absences, including the reasons for absence. The information was posted on company notice boards and sent by email to employees. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Jun 2008 | Contact point s.r.l.Contact point s.r.l. was fined by the Garante 10,000 EUR for breaching data protection rules. The case concerned improper handling of personal data during opinion surveys. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2014 | Roma CapitaleRoma Capitale was fined for unlawfully publishing personal data related to a disciplinary action on its institutional website. The authority found that this conduct violated Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |