BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Oct 2021 | Società LARCSocietà LARC was fined EUR 8,000 by the Garante for violations related to the processing of health data. The authority found non-compliance with GDPR requirements in the handling of these data. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Sept 2017 | NO QUIERO PERDER EL TIEMPO, S.L.The company was fined by the AEPD for displaying the AEPD quality seal and another association’s seal on its website without authorization. The authority also found inadequate information and no valid consent for data collection. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 16 Mar 2017 | Roma TPL s.c.a.r.l.Roma TPL s.c.a.r.l. was fined EUR 8,000 by the Garante for processing personal data through AVM systems on buses without full compliance with data protection rules. The case concerned improper use of monitoring and data-processing systems affecting passengers. | IT | Garante | GDPR | €8,000 | ↗ |
| 17 Nov 2025 | PGS SOFA & CO SRLIn October 2025, ANSPDCP completed an investigation at PGS SOFA & CO SRL and found a GDPR violation. The authority imposed a fine of EUR 8,000. | RO | ANSPDCP | GDPR | €8,000 | ↗ |
| 08 Sept 2022 | Realmedia Network SARealmedia Network SA was fined EUR 8,000 by ANSPDCP for a data processing security breach. The incident involved a service used to operate the imobiliare.ro platform. | RO | ANSPDCP | GDPR | €8,000 | ↗ |
| 05 Jul 2018 | Gianolini Servizi e Trasporti s.r.l.Gianolini Servizi e Trasporti s.r.l. was fined €8,000 by the Garante for failing to notify the authority about its use of a vehicle localization system with GPS devices. The conduct was found to breach notification obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 18 Jun 2024 | FUNDACIÓ PRIVADA DE SERVEIS PER ALS USUARIS DEL HABITATGE SOCIAL DE CATALUNYAThe organization changed the bank account for a community water bill to its own account without authorization. The AEPD found this breached the lawfulness of processing under GDPR Article 6(1). | ES | AEPD | GDPR | €8,000 | ↗ |
| 11 Sept 2025 | J&D di ZAMBRANO AGUIRRE Ruth JohannaThe Garante imposed a fine of 8,000 EUR on J&D di ZAMBRANO AGUIRRE Ruth Johanna for violations related to the use of a video surveillance system. The authority found that the system was not fully compliant with GDPR requirements. | IT | Garante | GDPR | €8,000 | ↗ |
| 04 May 2015 | CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank for unlawful processing of the complainant’s creditworthiness data. The case concerned a breach of the rules governing lawful processing of personal data. | GR | HDPA | GDPR | €8,000 | ↗ |
| 31 Jan 2019 | Comune di BardolinoThe Municipality of Bardolino was fined EUR 8,000 by the Garante for publishing personal data on its institutional website without an appropriate legal basis. The disclosure included names and tax codes of beneficiaries of economic contributions, as well as personal information of two municipal employees. | IT | Garante | GDPR | €8,000 | ↗ |
| 07 Aug 2023 | FORMACIÓN Y EMPLEO DE EXTREMADURA, S.L.The company sent emails to multiple recipients without using BCC, allowing each recipient to see the other recipients’ email addresses. AEPD treated this as a breach of data protection rules and imposed an 8,000 EUR fine. | ES | AEPD | GDPR | €8,000 | ↗ |
| 13 Dec 2018 | Ordinanza ingiunzione - 13 dicembre 2018 [9124641]The sole proprietorship acting as an agent for Western Union carried out unauthorized money transfers using personal data without consent. The authority found a breach of data protection rules and imposed a EUR 8,000 fine. | IT | Garante | GDPR | €8,000 | ↗ |
| 29 Sept 2011 | Jenius Communication sasJenius Communication sas was fined by the Garante 8,000 EUR for sending an unsolicited promotional email. The case concerns a breach of data protection rules governing marketing communications. | IT | Garante | GDPR | €8,000 | ↗ |
| 15 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE DE COMMERCE D'ALIMENTATION GENERALE SPECIALISEE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 8,000 on SOCIETE EXERCANT UNE ACTIVITE DE COMMERCE D'ALIMENTATION GENERALE SPECIALISEE and issued an injunction. The case was handled under simplified proceedings. | FR | CNIL | GDPR | €8,000 | ↗ |
| 25 Sept 2025 | Provincia Autonoma di TrentoProvincia Autonoma di Trento was fined for processing personal data without a legal basis, lacking transparency, and failing to conduct a data protection impact assessment. The authority found breaches of several GDPR provisions. | IT | Garante | GDPR | €8,000 | ↗ |
| 21 Jun 2018 | Comune di PozzalloComune di Pozzallo was fined for publishing personal and judicial data online without a valid legal basis. It also failed to respond to information requests from the Garante. | IT | Garante | GDPR | €8,000 | ↗ |
| 02 Nov 2022 | Dane anonimowe (Wójta Gminy U. za naruszenie przepisów art. 5 ust. 1 lit. f), art. 5 ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679)The Polish DPA (UODO) imposed an administrative fine of PLN 8,000 on the Mayor of U. Commune. The authority found that personal data were processed without adequate security, in breach of Articles 5, 25 and 32 of the GDPR. | PL | UODO | GDPR | €1,701 | ↗ |
| 09 May 2018 | SO.LOG. SrlSO.LOG. Srl was fined EUR 8,000 by the Italian data protection authority, Garante. The sanction concerned the failure to properly notify processing activities related to vehicle geolocation, in breach of the Italian Privacy Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Jan 2026 | PREMIER RESTAURANTS ROMANIA SRLThe National Supervisory Authority for Personal Data Processing imposed a fine on PREMIER RESTAURANTS ROMANIA SRL for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €8,000 | ↗ |
| 10 Apr 2025 | Undici S.r.l.s.Undici S.r.l.s. was fined 8,000 EUR by the Garante for making unsolicited telemarketing calls. The authority found that the company did not verify the lawfulness of the data used for contact, breaching GDPR requirements on consent and data processing. | IT | Garante | GDPR | €8,000 | ↗ |