BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2019 | EL PERIODICO DE CATALUNYA, S.L.EL PERIODICO DE CATALUNYA, S.L. was fined by the AEPD 10,000 EUR for sending a commercial email after a data deletion request. The authority found this conduct to be in breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 05 Apr 2018 | Comune di Magliano SabinaThe Municipality of Magliano Sabina was fined 10,000 EUR by the Garante for unlawfully disclosing personal data to a private educational institution without a valid legal basis. The authority found that this conduct breached the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Apr 2017 | Effepì Credit s.r.l.Effepì Credit s.r.l. was fined by the Garante in the amount of EUR 10,000 for inadequate security measures. The authority cited weak and outdated passwords as a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Jul 2018 | Anonymizováno (ÚOOÚ UOOU-00944/18-13)The entity processed sensitive personal data about users’ sexual orientation on a website without a valid legal basis. It also failed to provide the required information to data subjects, which breached Czech data protection rules. | CZ | UOOU | GDPR | €386 | ↗ |
| 11 Mar 2021 | Università degli Studi di Napoli Federico IIUniversità degli Studi di Napoli Federico II was fined by the Garante in the amount of 10,000 EUR for breaches of data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization in the processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Jun 2026 | Artmark Holding SRLArtmark Holding SRL was fined by ANSPDCP 10,000 RON for sending unsolicited commercial emails without obtaining prior explicit consent from recipients. The case concerns a breach of rules on electronic marketing communications and consent requirements. | RO | ANSPDCP | ePrivacy | €1,908 | ↗ |
| 08 Oct 2019 | Министър на вътрешните работиThe Ministry of Interior was fined for unlawfully processing and sharing the personal data of a Finnish citizen with Togo authorities without a legal basis. The authority found a breach of GDPR principles on lawful processing and data disclosure. | BG | CPDP | GDPR | €5,113 | ↗ |
| 13 Feb 2025 | Thomas FeroDr Thomas Fero was fined by the Garante EUR 10,000 for sending patients electoral campaign emails without their consent. The authority found this to be a breach of GDPR rules on personal data processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Nov 2016 | Aurora Jonica soc. coop.Aurora Jonica soc. coop. was fined by the Garante 10,000 EUR for making an unsolicited promotional call. The phone number was registered in the public opt-out list, which breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 May 2018 | Ordinanza ingiunzione - 16 maggio 2018 [9023208]A general practitioner was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This failure allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 May 2025 | CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.CURENERGÍA was fined EUR 10,000 by the AEPD for sharing personal data with IBERDROLA without the data subject’s consent. The disclosure led to a contract offer at a higher price than requested. | ES | AEPD | GDPR | €10,000 | ↗ |
| 25 Sept 2023 | UAT Comuna AlbeniANSPDCP imposed a 10,000 RON fine on UAT Comuna Albeni for failing to implement measures previously ordered by the authority. The entity also did not respond to the authority’s requests. | RO | ANSPDCP | GDPR | €2,013 | ↗ |
| 10 Nov 2016 | Marketing & Comunicazione s.r.l.Marketing & Comunicazione s.r.l. was fined by the Garante for making an unsolicited promotional call to a number listed in the public opposition registry. The conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Nov 2014 | Ruggiero FerdinandoRuggiero Ferdinando was fined EUR 10,000 by the Garante. The sanction concerned failing to provide a complete response to a request for information during a privacy investigation. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2023 | EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.EL ESPAÑOL was fined 10,000 EUR by the AEPD for publishing a private video without the consent of the data subject. The case concerns a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 24 Nov 2016 | Unione Comunale del Chianti fiorentinoUnione Comunale del Chianti fiorentino was fined by the Garante 10,000 EUR for publishing on its website the personal data of individuals who were not admitted to a financial benefit. The conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Asl FerraraAsl Ferrara was fined by the Garante for processing genetic, health, and sexual life data without the required notification. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Feb 2026 | Radio Immagine Uno S.r.l.The Garante imposed a €10,000 fine on Radio Immagine Uno S.r.l. for failing to respond to a data subject's request to remove an online article containing personal data. The company did not comply with the right to be forgotten, resulting in a data protection breach. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Jul 2014 | Comune di OrbetelloThe Municipality of Orbetello was fined EUR 10,000 by the Italian data protection authority, Garante. The sanction concerned the publication of individuals’ personal health data on the municipality’s official website, in breach of privacy rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Feb 2022 | Regione ToscanaRegione Toscana was fined by the Garante EUR 10,000 for failing to implement adequate security measures, which resulted in a data breach. The breach was mitigated by the region’s prompt response to reduce the negative effects on affected individuals. | IT | Garante | GDPR | €10,000 | ↗ |