BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Feb 2022 | Anonymisé (CNPD decision-01-fr-2022)The entity breached GDPR requirements on data minimization, retention limitation, and the duty to inform data subjects, including employees and third parties, about processing activities. CNPD imposed a fine of EUR 10,000. | LU | CNPD | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Azienda Ospedaliero Universitaria SeneseAzienda Ospedaliero Universitaria Senese was fined by the Garante in the amount of 10,000 EUR for breaches of data protection rules in the healthcare sector. The case concerned the processing of sensitive personal data in a medical setting. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Nov 2023 | Alpha BankAlpha Bank was fined for failing to satisfy the complainant’s request for access to personal data. The authority found breaches of GDPR Articles 15 and 5. | GR | HDPA | GDPR | €10,000 | ↗ |
| 24 Jun 2020 | Azienda Sanitaria Universitaria Giuliano IsontinaAzienda Sanitaria Universitaria Giuliano Isontina was fined by the Garante for unlawfully communicating health data without an adequate legal basis. The conduct breached Article 20 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Nov 2010 | Fitness Solution società sportiva dilettantistica s.r.l.Fitness Solution was fined EUR 10,000 by the Garante. The authority found that biometric personal data were processed without proper consent and retained longer than necessary. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Sept 2025 | La Fântâna S.R.L.In July 2025, ANSPDCP completed an investigation into La Fântâna S.R.L. and found a breach of GDPR provisions. As a result, the operator was fined 10,000 EUR. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 23 Jan 2008 | Deas Desideri e associati s.r.l.Deas Desideri e associati s.r.l. was fined €10,000 by the Garante for failing to notify the processing of sensitive personal data within the required timeframe. The authority found a breach of Article 163 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2016 | BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 10,000 EUR for failing to provide the required cookie information and for not obtaining consent on its website. The case concerns breaches of notice and consent obligations for website cookies. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 01 Jan 2020 | PERSONAL MARK, S.L.PERSONAL MARK, S.L. was fined by the AEPD 10,000 EUR for failing to diligently delete personal data from its databases despite the complainant’s requests. The case indicates inadequate handling of data erasure obligations. | ES | AEPD | GDPR | €10,000 | ↗ |
| 11 Jan 2024 | Build Lenders S.r.l.Build Lenders S.r.l. was fined EUR 10,000 by the Garante for unlawfully publishing personal data and failing to respond to a data deletion request. The authority found that the company breached GDPR rules on data protection and data subject rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Jul 2024 | IstitutoThe Garante fined Istituto EUR 10,000 for violations related to the processing of personal data in the context of medical and scientific research. The authority found that retention periods were not defined and transparency toward data subjects was insufficient. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Apr 2022 | SOPHIE ET VOILA, S.L.SOPHIE ET VOILA, S.L. was fined EUR 10,000 by the AEPD for publishing a photo on Instagram without the data subject’s consent. The authority found a breach of Article 6 GDPR on lawful processing. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | FRESHLY COSMETICS, S.L.FRESHLY COSMETICS, S.L. was fined by the AEPD EUR 10,000 for using advertising cookies on its website without user consent. The authority found this breached Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 12 May 2011 | Jnternet srlJnternet srl was fined by the Italian data protection authority, Garante, in the amount of EUR 10,000. The case concerned the failure to respond to requests for information about compliance with data protection obligations in connection with promotional emails sent without proper consent. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Jul 2018 | Comune di VollaComune di Volla was fined by the Garante EUR 10,000 for allowing all employees access to sensitive and judicial personal data through its electronic protocol system. The authority found that this setup failed to meet required data protection safeguards. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Dental Leader S.p.A.Dental Leader S.p.A. was fined EUR 10,000 by the Garante. The authority found that the company required consent to process personal data for promotional purposes in order to complete an online order, even though this was not necessary for contract performance. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2014 | Tenacta Group s.p.a.Tenacta Group s.p.a. was fined €10,000 by the Garante for making an unsolicited promotional phone call. The conduct breached the complainant’s right to object, as recorded in the public opt-out list. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2015 | Comune di Castelvetrano SelinunteComune di Castelvetrano Selinunte was fined by the Garante for unlawfully publishing personal data revealing health conditions on its website. The case involved a breach of data protection rules and the confidentiality of sensitive information. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Jul 2021 | Dane anonimowe (Prezesa Sądu Rejonowego w M. za naruszenie art. 5 ust. 1 lit. f), art. 25 ust. 1, art. 32 ust. 1 lit. b) i d) oraz art. 32 ust. 2 rozporządzenia 2016/679)UODO imposed a fine of PLN 10,000 on the President of the District Court for failing to implement appropriate technical and organizational measures. The authority found that the security level did not match the risk associated with processing data using portable external storage devices. | PL | UODO | GDPR | €2,189 | ↗ |
| 21 Mar 2022 | RESTAURANTCNIL imposed a fine of EUR 10,000 on RESTAURANT. The case concerned a regulatory breach, with no further details provided. | FR | CNIL | GDPR | €10,000 | ↗ |