BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2021 | B.B.B.B.B.B. was fined by the AEPD 10,000 EUR for publishing personal data, including DNI/NIF, on a website. The authority found a breach of data minimization principles and GDPR requirements. | ES | AEPD | GDPR | €10,000 | ↗ |
| 07 Mar 2024 | BdM Banca S.p.a.BdM Banca S.p.a. was fined 10,000 EUR by the Garante for failing to provide an adequate response to a data access request submitted by an heir. The authority found that the response did not meet the requirements of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Oct 2019 | JOKER PREMIUM INVEX, S.L.JOKER PREMIUM INVEX, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited commercial communications. The company used personal data taken from public sources without the individuals’ consent. | ES | AEPD | GDPR | €10,000 | ↗ |
| 11 Jan 2024 | DESPACHO TORRENTE, S.L.P.DESPACHO TORRENTE, S.L.P. was fined by the AEPD 10,000 EUR for improperly disclosing personal data, including sensitive information, in a letter concerning damage at public facilities. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 04 Jul 2024 | Nomodidattica S.r.l.Nomodidattica S.r.l. was fined EUR 10,000 by the Garante for publishing a court ruling online without anonymizing minors' data. The authority found this breached GDPR data protection principles. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Dec 2009 | BonassisaLab s.r.l.BonassisaLab s.r.l. was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jan 2010 | Servizi sanitari s.r.l. – Istituto cardiovascolare CamogliServizi sanitari s.r.l. was fined by the Garante 10,000 EUR for violations related to the processing of personal data without the required notification. The case concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2015 | ORANGE ESPAGNE, S.A.U.JAZZ TELECOM S.A.U. was fined for sending unsolicited SMS advertising to a non-customer. The authority found that the conduct breached the LSSI rules on marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 19 Mar 2024 | LOCAL VERTICALS, S.L.LOCAL VERTICALS, S.L. was fined by the AEPD 10,000 EUR for storing cookies without user consent and for failing to provide a legal notice on its website. The case concerns breaches of data protection rules and website transparency obligations. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 15 Jul 2010 | Comune di VentimigliaComune di Ventimiglia was fined by the Garante for processing employees’ biometric data without the required notification. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Azienda Ospedaliero Universitaria di ParmaAzienda Ospedaliero Universitaria di Parma was fined by the Garante for violations related to the handling of health data. The violations resulted in a data breach, which led to the 10,000 EUR penalty. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Mar 2021 | Anonymizováno (ÚOOÚ UOOU-00681/20-18)The entity was fined for sending unsolicited commercial communications by email without the recipients' consent. This breached Czech electronic communications rules. | CZ | UOOU | ePrivacy | €382 | ↗ |
| 10 Jan 2017 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited commercial SMS messages. The messages were sent despite the complainant being registered on the Robinson List, breaching Articles 21.1 and 21.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 01 Jun 2016 | Midica s.r.l.Midica s.r.l. was fined by the Garante for making promotional calls without the consent of the individuals concerned. The company also failed to respond to information requests from the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Jul 2018 | Primo s.r.l.Primo s.r.l., a dental center, was fined by the Italian Garante in the amount of 10,000 EUR. The authority found inadequate security measures in the processing of patients’ personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Mar 2025 | Tensa Art Design S.A.The Romanian data protection authority investigated Tensa Art Design S.A., operator of lensa.ro, in March 2025. It found GDPR violations involving direct marketing without valid consent and improper handling of data subject access and erasure requests. Two fines totaling 15,000 EUR were imposed. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 26 Apr 2018 | Falotico Luca CarmeloFalotico Luca Carmelo, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Jul 2018 | BUSITALIA VENETO S.p.A.BUSITALIA VENETO S.p.A. was fined by the Garante for unlawful processing of personal data through the installation of a geolocation system on its public transport vehicles. The measure infringed employee privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Oct 2014 | San Petronio s.r.l.San Petronio s.r.l. was fined by the Garante for failing to appoint data processing officers and for providing inadequate information about video surveillance. The authority found that these practices breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jul 2020 | COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD for publishing a resident’s personal data on a community notice board. The conduct breached data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |