BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 Mar 2023 | Banca Cambiano 1884 S.p.A.Banca Cambiano 1884 S.p.A. was fined by the Garante 10,000 EUR for failing to respond within the required timeframe to a data subject's request for access to personal data. The authority found a breach of GDPR Articles 15 and 12. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 May 2018 | Greco LuigiGreco Luigi, a general practitioner, was fined for failing to implement minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | Azienda ULSS 6 EuganeaThe Garante fined Azienda ULSS 6 Euganea 10,000 EUR for the incorrect handling of health-related documents. The authority found breaches of GDPR Articles 5, 6, and 32. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Asl VercelliAsl Vercelli was fined by the Garante for processing special-category personal data, including genetic and health data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Feb 2021 | Arma dei carabinieriArma dei carabinieri was fined by the Garante for improperly handling sensitive and judicial data without adequate safeguards against unauthorized access. The authority found breaches of the GDPR and the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Apr 2015 | Web performance s.r.l.Web performance s.r.l. was fined by the Garante for collecting personal data through website forms without proper consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Mar 2025 | XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited SMS advertisements to a number registered on the Robinson List. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 13 Nov 2024 | Spinacqua S.r.l.Spinacqua S.r.l. was fined by the Garante €10,000 for making unsolicited promotional calls to a number listed in the Public Opposition Register. The company did not obtain consent and failed to verify the number’s registration status before contacting it. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Jul 2025 | Asilo nido “La Combricola Dei Birichini Di Betty”The Garante imposed a 10,000 EUR fine on the nursery for failing to provide parents with the required information about the processing of children's images. It also found that no data protection impact assessment had been carried out for the surveillance system. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Feb 2021 | PINTODIS, S.L.PINTODIS, S.L. was fined by the AEPD for installing surveillance cameras that recorded employees in private areas without sufficient justification. The authority found this to be a breach of data protection principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 26 Jun 2020 | ESLORA PROYECTOS, S.L.ESLORA PROYECTOS, S.L. was fined by the AEPD 10,000 EUR for failing to provide cookie information and for not obtaining user consent before using cookies. The authority cited a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 23 Apr 2015 | Comune di AostaComune di Aosta was fined for publishing personal data that revealed health information on its website. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Sept 2024 | Comune di VeronaThe Garante fined Comune di Verona €10,000 for violations of GDPR Articles 5, 6 and 9, as well as Article 2-ter of the Italian Privacy Code. The case concerned the processing of personal data in a manner not compliant with legal requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Oct 2024 | Profi Rom Food SrlProfi Rom Food Srl was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 24 Jan 2013 | Evolution chirurgia estetica s.r.l.Evolution chirurgia estetica s.r.l. was fined 10,000 EUR by the Garante. The authority found that the website contact form required mandatory acceptance of the privacy notice, which breached consent requirements under the Italian privacy code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Oct 2022 | IPM Group NVThe case concerned the use of cookies on the L'Avenir website operated by IPM Group NV. A settlement was reached under which the company agreed to pay 10,000 EUR to the Belgian treasury. | BE | APD | ePrivacy | €10,000 | ↗ |
| 18 Mar 2010 | Alma s.r.l.Alma s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 10,000 EUR. The case concerned the processing of personal data without the notification required under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jun 2023 | Provvedimento del 1° giugno 2023 [9909889]The Garante imposed a 10,000 EUR fine on a healthcare center for incorrectly sending automatic SMS reminders to a patient due to a data misattribution error. The case concerned GDPR provisions on data processing and security. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Roma CapitaleRoma Capitale was fined EUR 10,000 by the Garante for publishing the personal data of a minor and the minor’s mother on its official website without a proper legal basis. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Jan 2024 | HUELLAS AVENTURA, S.L.The company was fined by the AEPD for tying consent for a school trip service to acceptance of data protection policies and commercial communications. The authority also found that users were not given an option to object to the processing of minors' images. | ES | AEPD | GDPR | €10,000 | ↗ |