Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Apr 2025Unione Montana Appennino Parma EstUnione Montana Appennino Parma Est was fined by the Italian supervisory authority, Garante, in the amount of EUR 8,000. The authority found a lack of required transparency in data processing and failure to carry out a data protection impact assessment for workplace video surveillance.ITGaranteGDPR€8,000
23 Feb 2017Avv. Silvana VassalliAvv. Silvana Vassalli was fined by the Garante for unlawful processing of personal data. The breach involved transmitting an email containing personal data without proper authorization.ITGaranteGDPR€8,000
04 Feb 2016Istituto Tecnico Industriale Ettore MajoranaIstituto Tecnico Industriale Ettore Majorana was fined for processing biometric data for attendance tracking without the required notification to the Garante. This breached the Italian Privacy Code.ITGaranteGDPR€8,000
19 Oct 2017Pittaluga servizio containers S.p.A.Pittaluga servizio containers S.p.A. was fined by the Garante €8,000 for using a geolocation system on its vehicles without full compliance with data protection rules. The case concerned improper processing of location data linked to vehicles or employees.ITGaranteGDPR€8,000
16 Nov 2023SOCIETE AYANT UNE ACTIVITE DE SOUTIEN AUX ENTREPRISES, NOTAMMENT POUR LES EVENEMENTS TELEVISES (procédure simplifiée)The CNIL imposed a fine of EUR 8,000 on SOCIETE AYANT UNE ACTIVITE DE SOUTIEN AUX ENTREPRISES, NOTAMMENT POUR LES EVENEMENTS TELEVISES. The case was handled under a simplified procedure.FRCNILGDPR€8,000
01 Dec 2022Comune di Reggio EmiliaThe Municipality of Reggio Emilia was fined 8,000 EUR by the Garante for unlawfully publishing personal data, including health information, of a former employee on its website. The case concerned an unauthorized disclosure of sensitive information in breach of data protection rules.ITGaranteGDPR€8,000
05 May 2011Mondolibri s.p.a.Mondolibri s.p.a. was fined EUR 8,000 by the Garante for collecting personal email addresses through its website without providing adequate information to the data subjects. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€8,000
31 Jan 2013Smart s.n.c.Smart s.n.c. was fined by the Garante in the amount of 8,000 EUR. The case concerned the sending of unsolicited promotional faxes without obtaining explicit consent, which breached data protection rules.ITGaranteGDPR€8,000
11 Sept 2025Ente Parco Regionale Migliarino San Rossore MassaciuccoliEnte Parco Regionale Migliarino San Rossore Massaciuccoli was fined EUR 8,000 by the Garante for failing to implement adequate technical and organizational measures. The authority found that more personal data was processed than necessary, in breach of the GDPR and national data protection rules.ITGaranteGDPR€8,000
19 Jan 2023A startup football clubThe Belgian data protection authority, GBA, imposed an EUR 8,000 fine on a startup football club. The case involved failure to respond to a data subject access request, as well as additional GDPR breaches concerning transparency and processor-contract requirements.BEGegevensbeschermingsautoriteit (GBA)GDPR€8,000
10 Mar 2011Gruppo Guide Italia s.r.l.Gruppo Guide Italia s.r.l. was fined 8,000 EUR by the Garante for publishing personal data without authorization in a guide. The case concerned a breach of data protection rules.ITGaranteGDPR€8,000
28 Jun 2018Autotrasporti Viviani s.r.l.Autotrasporti Viviani s.r.l. was fined by the Garante 8,000 EUR for failing to comply with notification obligations related to the geolocation system installed on its transport vehicles. The case concerned missing required notices regarding the processing of data.ITGaranteGDPR€8,000
23 Jan 2025SOCIETE DE TRANSPORT ROUTIER DE MARCHANDISES (procédure simplifiée)CNIL imposed an administrative fine of 8,000 EUR on SOCIETE DE TRANSPORT ROUTIER DE MARCHANDISES. The case was handled under a simplified procedure.FRCNILGDPR€8,000
14 Mar 2013Unitelma SapienzaUnitelma Sapienza was fined EUR 8,000 by the Garante for failing to provide information to data subjects and for not obtaining consent to process sensitive data. The violations occurred during online registration for university courses.ITGaranteGDPR€8,000
05 Mar 2020Azienda Sanitaria Locale di Ciriè, Chivasso e Ivrea (ASL TO4)ASL TO4 was fined by the Garante EUR 8,000 for unlawful data processing through video surveillance. The authority found that the required agreements with unions were not in place.ITGaranteGDPR€8,000
11 Sept 2025Provvedimento dell'11 settembre 2025 [10184654]The decision imposes a fine on a healthcare company for cybersecurity-related breaches following a security incident involving patient data. The authority found non-compliance with Articles 25 and 32 GDPR.ITGaranteGDPR€8,000
27 Nov 2025CANDIDAT AUX ELECTIONS AU PARLEMENT EUROPEEN DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of €8,000 on CANDIDAT AUX ELECTIONS AU PARLEMENT EUROPEEN DE 2024 and issued an injunction. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€8,000
24 Oct 2013ASL n.1 – Avezzano/Sulmona/L'AquilaASL n.1 – Avezzano/Sulmona/L'Aquila was fined EUR 8,000 by the Garante. The authority found a breach consisting of failure to make the notification required under the Italian Data Protection Code.ITGaranteGDPR€8,000
24 May 2017LAM Centro Biomedico s.r.l.LAM Centro Biomedico s.r.l. was fined by the Garante for failing to notify the corporate name change following a merger. The case involved processing sensitive personal data, which required informing the supervisory authority.ITGaranteGDPR€8,000
01 Jan 2014BONANZA DIGITAL SERVICES S.L.BONANZA DIGITAL SERVICES S.L. was fined by the AEPD 8,000 EUR for sending unsolicited SMS messages promoting “Tarot del Alba”. The company did not provide an opt-out mechanism, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€8,000