BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2024 | HIGHCLIFFE ESTATES MARBELLA, S.L.HIGHCLIFFE ESTATES MARBELLA, S.L. was fined by the AEPD 8,500 EUR for publishing personal data, including names and images, on its website without the data subjects’ consent. The authority found this to be a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €8,500 | ↗ |
| 26 Jun 2014 | Omnia energia s.p.a.Omnia energia s.p.a. was fined EUR 8,400 by the Garante for failing to provide adequate simplified information about its video surveillance system. The authority also found that required information was not provided on the company’s website, in breach of data protection rules. | IT | Garante | GDPR | €8,400 | ↗ |
| 11 Jun 2015 | Quotidiano Il Tempo s.r.l.Quotidiano Il Tempo s.r.l. was fined by the Garante EUR 8,400 for processing personal data without providing adequate information to subscribers. The authority also found that the company used a video surveillance system without the simplified notice required under privacy rules. | IT | Garante | GDPR | €8,400 | ↗ |
| 03 Oct 2013 | Forum Sport Center società sportiva dilettantistica S.r.l.Forum Sport Center società sportiva dilettantistica S.r.l. was fined by the Italian Garante in the amount of €8,400. The sanction concerned inadequate data protection notices for personal data collection and video surveillance systems. | IT | Garante | GDPR | €8,400 | ↗ |
| 08 Jun 2023 | Marcozzi Brand s.r.l.Marcozzi Brand s.r.l. was fined €8,400 by the Garante. The case concerned the failure to provide the complainant with the name of the occupational physician and the specific reasons for a negative fitness-for-work assessment, breaching GDPR transparency and access rights. | IT | Garante | GDPR | €8,400 | ↗ |
| 23 May 2024 | Azienda USL della RomagnaThe Garante imposed a fine of EUR 8,400 on Azienda USL della Romagna for violations related to data processing operations. The processes were largely manual and dependent on operator diligence, which led to a data breach. | IT | Garante | GDPR | €8,400 | ↗ |
| 29 Apr 2022 | TelemarkkinointiyritysA telemarketing company was fined for failing to comply with a Data Protection Ombudsman's order to provide a data subject access to a call recording. The case concerned a breach of GDPR Article 15 on the right of access. | FI | TSV | GDPR | €8,300 | ↗ |
| 01 Jan 2012 | CENTRE DE REDISTRIBUCIO DE MERCADERIES, S.L.The entity was fined by the AEPD for sending unsolicited commercial emails without prior recipient consent. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €8,200 | ↗ |
| 24 Jul 2018 | TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined by the AEPD 8,100 EUR for sending unsolicited advertising emails without prior recipient consent. The case concerned a breach of Article 21 of the LSSI and reflects unlawful direct marketing practices. | ES | AEPD | ePrivacy | €8,100 | ↗ |
| 14 Jan 2021 | Agenzia regionale protezione ambientale Campania (ARPAC)ARPAC was fined by the Garante EUR 8,000 for violations concerning data security measures and data breach notification obligations. The case involved non-compliance with GDPR Articles 5 and 32. | IT | Garante | GDPR | €8,000 | ↗ |
| 29 Jan 2015 | Abruzzo Vigilanza s.r.l.Abruzzo Vigilanza s.r.l. was fined €8,000 by the Garante for using a vehicle tracking system without the required notification. The case concerns non-compliance with data protection notification obligations. | IT | Garante | GDPR | €8,000 | ↗ |
| 09 Oct 2025 | Arienti & C. s.r.l. a socio unicoThe Garante fined Arienti & C. s.r.l. a socio unico EUR 8,000 for denying a former employee access to their email account after the employment contract ended. The authority found this breached GDPR Article 15 on the right of access to personal data. | IT | Garante | GDPR | €8,000 | ↗ |
| 04 May 2015 | CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank. The case concerned the bank’s failure to satisfy the complainant’s right of access to personal data. | GR | HDPA | GDPR | €8,000 | ↗ |
| 02 Oct 2014 | Comune di Piana degli AlbanesiThe Municipality of Piana degli Albanesi was fined EUR 8,000 by the Garante for failing to appoint data processing officers. The authority also found that the required security program document had not been drafted, in breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 27 Aug 2024 | YThe case concerns a football club that obtained a member list during a takeover and used the personal data for commercial mailings without a valid legal basis. The authority found breaches of several GDPR provisions and imposed a monetary fine. | BE | APD | GDPR | €8,000 | ↗ |
| 04 Dec 2020 | BORJAMOTOR, S.A.BORJAMOTOR, S.A. was fined by the AEPD €8,000 for sending commercial SMS messages without explicit consent from recipients. The authority also identified improper consent practices for personal data processing on the company’s website. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 13 Nov 2024 | Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 8,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data. The decision indicates non-compliance with core rules on lawful and proper processing. | IT | Garante | GDPR | €8,000 | ↗ |
| 15 Dec 2011 | dott. Mancini Endriodott. Mancini Endrio was fined EUR 8,000 by the Garante for violating data protection rules. The case concerned inadequate compliance with data security requirements under Article 162, paragraph 2-bis, of the Italian Privacy Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 20 Aug 2024 | Ana Hotels SRLAna Hotels SRL was fined by ANSPDCP €8,000 after a data security incident caused by a ransomware attack. The incident led to unauthorized disclosure of personal data belonging to a significant number of employees. | RO | ANSPDCP | GDPR | €8,000 | ↗ |
| 17 Jul 2025 | Smart R.E. S.r.l.Smart R.E. S.r.l. was fined EUR 8,000 by the Italian authority Garante for failing to comply with a former employee’s deletion request. After the employment ended, the assigned email account remained active and redirected messages to another company account. | IT | Garante | GDPR | €8,000 | ↗ |