Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Apr 2023Comune di AdelfiaThe Garante fined Comune di Adelfia EUR 8,000 for violations related to the publication of personal data on its institutional website. The data were later removed.ITGaranteGDPR€8,000
19 Sept 2024GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.GACM Seguros was fined 8,000 EUR by the AEPD for improperly sharing personal data related to an insurance claim with another insured party. The authority found a breach of data protection rules.ESAEPDGDPR€8,000
06 Jun 2018SECCHI Elettroservice S.r.l.SECCHI Elettroservice S.r.l. was fined by the Garante 8,000 EUR for failing to properly notify employees about the use of a geolocation system on company vehicles. The authority found a breach of data protection rules.ITGaranteGDPR€8,000
01 Jan 2016BANCO SANTANDER, S.A.Banco Santander, S.A. was fined by the AEPD €8,000 for sending unsolicited commercial emails. The authority found that the messages did not provide a valid email address for recipients to opt out, breaching Article 21 of the LSSI.ESAEPDePrivacy€8,000
26 Feb 2020Comune di AstiComune di Asti was fined EUR 8,000 by the Garante for unlawfully publishing personal data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€8,000
25 Oct 2012Dario Flaccovio Editore s.r.l.Dario Flaccovio Editore s.r.l. was fined by the Garante 8,000 EUR for sending unsolicited promotional faxes without prior explicit consent. The conduct breached data protection rules and the requirement for lawful processing.ITGaranteGDPR€8,000
11 Jan 2024Società David S.r.l.The Garante imposed an €8,000 fine on Società David S.r.l. for posting on Instagram a video of a patient undergoing a cosmetic procedure without a lawful basis. The authority found breaches of the GDPR principles of lawfulness, fairness, transparency, and purpose limitation.ITGaranteGDPR€8,000
06 Jun 2018Maganetti Spedizioni S.p.A.Maganetti Spedizioni S.p.A. was fined by the Italian Garante in the amount of €8,000. The case concerned the use of GPS devices on vehicles without adequate personal data protection measures.ITGaranteGDPR€8,000
13 Apr 2023Azienda Ospedaliera Universitaria di CagliariAzienda Ospedaliera Universitaria di Cagliari was fined EUR 8,000 by the Garante for unlawfully publishing personal data related to a disciplinary procedure online. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€8,000
18 Dec 2013Comune di MonticianoThe Municipality of Monticiano was fined 8,000 EUR by the Garante. The authority found a privacy violation after the municipality failed to provide requested information about the publication of personal data on its institutional website.ITGaranteGDPR€8,000
03 May 2018Omis s.p.a.Omis s.p.a. was fined by the Garante 8,000 EUR for failing to notify the processing of geolocation data from vehicles. This notification was required under privacy regulations.ITGaranteGDPR€8,000
10 Jul 2025Università degli Studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined €8,000 by the Garante for failing to comply with data protection rules. The case concerned improper handling of personal data requests and deficiencies in administrative procedures.ITGaranteGDPR€8,000
15 Dec 2022Comune di VicchioComune di Vicchio was fined by the Garante 8,000 EUR for using fingerprints to monitor employee attendance without appropriate legal basis and safeguards. The authority found that the biometric processing breached GDPR requirements.ITGaranteGDPR€8,000
04 Jun 2025Comune di RoccaforzataComune di Roccaforzata was fined EUR 8,000 by the Garante for publishing sensitive health data, including an employee’s disability percentage, in a council resolution. The authority found a breach of the GDPR and national privacy code provisions.ITGaranteGDPR€8,000
11 Oct 2017SANTANDER CONSUMER EFC, S.A.SANTANDER CONSUMER EFC, S.A. was fined by the AEPD for sending promotional SMS messages without the recipient’s consent. The authority also noted that the messages were sent despite the recipient’s objection to receiving advertising.ESAEPDePrivacy€8,000
05 Mar 2026Altex România S.R.L.The National Supervisory Authority for Personal Data Processing imposed fines totaling EUR 8,000 on Altex România S.R.L. for GDPR violations. The case followed complaints from data subjects.ROANSPDCPGDPR€8,000
14 May 2026Comune di VentassoComune di Ventasso was fined EUR 8,000 by the Garante. The authority found breaches of the principles of lawful, fair and transparent processing of personal data, as well as data minimization.ITGaranteGDPR€8,000
12 Feb 2021HIGHCLIFFE ESTATES MARBELLA, S.L.The company was fined by the AEPD for not providing a legal notice, privacy policy, or consent checkbox on its website. The authority also found that it used an individual's image without consent, breaching GDPR Articles 13 and 6(1).ESAEPDGDPR€8,000
17 Oct 2024ComuneThe Garante fined Comune EUR 8,000 for breaches of GDPR Articles 5, 6 and 9, and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data in the context of public employment and administrative transparency.ITGaranteGDPR€8,000
19 Jul 2013ALL THE WORLD - COSMOS ONLINEThe company was fined for sending unsolicited marketing emails without obtaining prior consent from recipients. This conduct breached ePrivacy rules governing electronic communications.GRHDPAePrivacy€8,000