BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Jan 2017 | D’Agostino Domenico FedeleD’Agostino Domenico Fedele was fined EUR 9,600 by the Garante for failing to provide individuals with the required data protection information. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,600 | ↗ |
| 11 Dec 2023 | C*** Bank AGC*** Bank AG was fined by the DSB EUR 9,500 for breaching Article 15 GDPR. The bank treated an access request as a deletion request and deleted the data instead of providing the requested information. | AT | DSB | GDPR | €9,500 | ↗ |
| 05 Oct 2022 | Dane anonimowe (D. sp. z o.o. sp. k. z siedzibą w P. przy ul.)The President of UODO imposed a fine of PLN 9,139 on the company. The sanction was issued because the company failed to comply with an order contained in an administrative decision of the data protection authority. | PL | UODO | GDPR | €1,907 | ↗ |
| 20 Oct 2022 | Azienda Ospedaliero-Universitaria Careggi di FirenzeAzienda Ospedaliero-Universitaria Careggi di Firenze was fined by the Garante 9,000 EUR for violations involving the processing of sensitive health data. The authority cited inadequate safeguards in the handling of histological examinations. | IT | Garante | GDPR | €9,000 | ↗ |
| 19 Jan 2011 | Center Gross Sicilia S.r.l.Center Gross Sicilia S.r.l. was fined EUR 9,000 by the Garante. The authority found that the required privacy notice was not provided for three external surveillance cameras, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 11 Sept 2025 | Università degli Studi di VeronaUniversità degli Studi di Verona was fined by the Garante €9,000 for improperly handling personal data during a research project. The authority found a breach of GDPR requirements for lawful, fair, and transparent processing. | IT | Garante | GDPR | €9,000 | ↗ |
| 09 Feb 2011 | Futurgroup s.r.l.Futurgroup s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 9,000. The case concerned the failure to provide timely information to the data subject as required by the data protection code. | IT | Garante | GDPR | €9,000 | ↗ |
| 19 May 2011 | Limbiati oreficeria orologeria ottica s.n.c. di L. Limbiati & C.Limbiati oreficeria orologeria ottica s.n.c. was fined by the Garante for collecting personal data through its website without providing adequate information or obtaining the required consent. The authority found this to be a breach of the Italian Privacy Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 18 Jun 2025 | SUNERIS, S.A.SUNERIS, S.A. was fined by the AEPD in the amount of 9,000 EUR for improper handling of personal data. The case involved copying a guest’s information without consent and leaving a master key card accessible, which breached data protection principles. | ES | AEPD | GDPR | €9,000 | ↗ |
| 11 Mar 2010 | Teleservizi s.r.l.Teleservizi s.r.l. was fined EUR 9,000 by the Garante for processing personal data without providing the required information to data subjects. The case concerned a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 03 Feb 2011 | Able Tech s.r.l.Able Tech s.r.l. was fined EUR 9,000 by the Garante for failing to provide timely information to the data subject. The breach concerned the obligation under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 10 Apr 2025 | Agenzia Mobilità Ambiente e Territorio S.r.l.The Garante fined Agenzia Mobilità Ambiente e Territorio S.r.l. 9,000 EUR for failing to provide sufficient transparency to data subjects. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €9,000 | ↗ |
| 22 May 2014 | COMERCIAL POLINDUS 21, S.L.COMERCIAL POLINDUS 21, S.L. was fined by the AEPD 9,000 EUR for sending unsolicited commercial SMS messages. The authority found that recipients were not given an opt-out option, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €9,000 | ↗ |
| 16 Feb 2011 | Bioacqua s.r.l.Bioacqua s.r.l. was fined EUR 9,000 by the Garante for using phone numbers for commercial communications without explicit consent and without providing the required information notice. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 06 Aug 2025 | YUNEXPRESS SPAIN, S.L.YUNEXPRESS SPAIN, S.L. was fined EUR 9,000 by the AEPD for failing to formalize a data processing agreement and for inaccuracies in data handling. The authority found breaches of GDPR Articles 28(3) and 5(1)(d). | ES | AEPD | GDPR | €9,000 | ↗ |
| 22 Oct 2025 | εκδοτικός οίκοςThe Greek Data Protection Authority fined a publishing house EUR 9,000 for disclosing an author's personal and special-category data in an email sent to 55 recipients. It also found failures to implement data protection by design and to notify both the authority and the data subject of the breach. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €9,000 | ↗ |
| 19 Sept 2024 | CRIDOLMA BARCELONA S.L.CRIDOLMA BARCELONA S.L. was fined €9,000 by the AEPD for failing to properly handle a data subject access request. The case concerned a breach of Article 15 GDPR and non-compliance with a data protection authority resolution. | ES | AEPD | GDPR | €9,000 | ↗ |
| 15 Jun 2011 | Azienda Multiservizi e Igiene Urbana S.p.A.Azienda Multiservizi e Igiene Urbana S.p.A. was fined for collecting personal data through a web form without providing users with the required privacy notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 17 Dec 2015 | Orange s.r.l.Orange s.r.l. was fined by the Garante in the amount of 8,800 EUR for processing personal data without the required information and consent. The authority also found that the company used a video surveillance system without providing adequate simplified information. | IT | Garante | GDPR | €8,800 | ↗ |
| 29 Apr 2026 | Azienda Sanitaria Locale di MateraAzienda Sanitaria Locale di Matera was fined by the Garante EUR 8,600 after a data breach caused by a ransomware attack. The incident led to the exfiltration of personal data, and the authority found inadequate technical and organizational measures to protect data security. | IT | Garante | GDPR | €8,600 | ↗ |