BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 May 2024 | Urban Home Development S.R.L.Urban Home Development S.R.L. was fined 10,000 RON by ANSPDCP. The sanction was imposed for violating the provisions of Law no. 506/2004. | RO | ANSPDCP | ePrivacy | €2,010 | ↗ |
| 13 Sept 2007 | Asl Benevento 1The Garante fined Asl Benevento 1 10,000 EUR for failing to notify data processing activities within the required timeframe. The breach concerned Article 163 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Mar 2023 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for processing personal data for direct marketing without proper consent and transparency. The authority found breaches of lawfulness, fairness, and purpose limitation. | GR | HDPA | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale della provincia di MantovaThe local health authority in Mantua was fined for failing to notify the processing of personal data revealing health status and sexual life. The case concerned obligations under the privacy code. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Jul 2025 | Partidul Alianța pentru Unirea Românilor (AUR)Partidul Alianța pentru Unirea Românilor (AUR) was fined €10,000 for violations related to data security breaches reported by the party. The case concerned shortcomings in the protection and safeguarding of personal data. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 24 Apr 2024 | C.I.EL. S.p.A.C.I.EL. S.p.A. was fined 10,000 EUR by the Garante following a complaint from a former employee. The case concerned violations related to the right of access to training certificates. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Feb 2018 | AVIS ALQUILE UN COCHE S.A.AVIS ALQUILE UN COCHE S.A. was fined by the AEPD 10,000 EUR for improper handling of personal data. This led to the wrongful publication of an individual's details in the Official State Gazette as the responsible party for a traffic violation they did not commit. | ES | AEPD | GDPR | €10,000 | ↗ |
| 09 Mar 2020 | OLIVEROS USTRELL, S.L.OLIVEROS USTRELL, S.L. was fined 10,000 EUR by the AEPD for unauthorized processing of a customer's personal and banking data. The case involved a fraudulent mobile contract and number portability carried out without a valid legal basis. | ES | AEPD | GDPR | €10,000 | ↗ |
| 12 Mar 2015 | Comune di TorittoComune di Toritto was fined by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its website. The conduct breached privacy rules and triggered enforcement action by the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | B.B.B.B.B.B. was fined by the AEPD in the amount of 10,000 EUR for publishing a patient's medical photos on social media without consent. The conduct breached GDPR Articles 6(1) and 9, which govern lawful processing and special categories of personal data. | ES | AEPD | GDPR | €10,000 | ↗ |
| 04 Feb 2016 | Fondazione IRCCS Cà Granda, Ospedale Maggiore PoliclinicoFondazione IRCCS Cà Granda, Ospedale Maggiore Policlinico was fined by the Garante €10,000 for unlawful processing of personal data. The breach involved the incorrect delivery of documents containing health information of third parties. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2026 | Conversion Media S.r.l.Conversion Media S.r.l. was fined EUR 10,000 by the Garante for failing to meet data protection obligations. The case concerned telemarketing activities in which required transparency and information duties toward data subjects were not fulfilled. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Apr 2022 | Tecnomed Trento s.r.l.Tecnomed Trento s.r.l. was fined by the Garante 10,000 EUR for operating a video surveillance system that did not comply with GDPR and the Italian Privacy Code. The authority found breaches of information duties and general data processing principles. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Dec 2008 | Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c.Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c. was fined for failing to notify the Garante of personal data processing activities within the required timeframe. The case concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Mar 2023 | NATURGESTYGAS, S.L.NATURGESTYGAS, S.L. was fined EUR 10,000 by the AEPD for processing personal data without a legal basis. The company charged a customer despite having no contract or consent, which breached the legality requirement for processing. | ES | AEPD | GDPR | €10,000 | ↗ |
| 14 Jan 2016 | Comune di Santa FlaviaThe Garante fined Comune di Santa Flavia €10,000 for unlawfully publishing documents on its website that disclosed individuals' health data. The case involved the disclosure of sensitive personal data without a lawful basis. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Jul 2015 | Comune di GallipoliThe Municipality of Gallipoli was fined by the Garante for unlawfully publishing personal data revealing health status on its institutional website. The conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Apr 2022 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 10,000 EUR for breaching the principle of data confidentiality. The bank sent debit card transaction notifications to incorrect email addresses, failed to notify the authority of the breach, and did not take timely corrective action. | GR | HDPA | GDPR | €10,000 | ↗ |
| 06 Jul 2023 | AcegasApsAmga S.p.A.AcegasApsAmga S.p.A. was fined €10,000 by the Italian supervisory authority, Garante. The sanction concerned the company’s failure to respond to a data subject’s request for access to personal data, in breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Jul 2021 | Università degli Studi di Milano-BicoccaUniversità degli Studi di Milano-Bicocca was fined EUR 10,000 by the Garante for data protection violations linked to the publication of personal data on its institutional website. The case concerned the disclosure of information on the university’s website, which breached data processing rules. | IT | Garante | GDPR | €10,000 | ↗ |