BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Jul 2023 | Romagna Dolciumi s.r.l.Romagna Dolciumi s.r.l. was fined by the Garante in the amount of €10,000 for failing to provide an employee with access to their personal data. The authority also found that the company engaged a private investigative agency to carry out defensive investigations without proper authorization, in breach of GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2022 | ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP.The company was fined by the AEPD EUR 10,000 for processing personal data without consent. The authority also found that its website privacy information was insufficient, including missing contact details and information on data subject rights. | ES | AEPD | GDPR | €10,000 | ↗ |
| 05 Jun 2025 | SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EDITION (procédure simplifiée)CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EDITION and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 23 Jan 2008 | Cubo società consulenza aziendale s.r.l.Cubo società consulenza aziendale s.r.l. was fined by the Garante 10,000 EUR for violating data protection rules. The case concerned the processing of personal data in the context of personnel search and selection activities. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2023 | Azienda Sanitaria dell'Alto Adige - Suedtiroler SanitaetsbetriebThe Garante fined Azienda Sanitaria dell'Alto Adige EUR 10,000 for failing to provide an adequate response to a data subject's rights request. The case also concerned the processing of sensitive data related to vaccination status. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2016 | AUTO OJA S.A.AUTO OJA S.A. was fined by the AEPD 10,000 EUR for sending unsolicited promotional emails to a customer. The company continued contacting the recipient despite requests to be removed from the mailing list, which breached the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 13 Mar 2014 | Puglia Service s.r.l.Puglia Service s.r.l. was fined by the Garante €10,000 for making unsolicited promotional phone calls. The conduct violated the right of opposition of a subscriber registered in the public opt-out list. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Aug 2017 | VodafoneThe HDPA imposed a €10,000 fine on Vodafone for unlawfully processing the complainant's credit card data without consent. The case concerns a breach of the legal basis requirements for personal data processing. | GR | HDPA | GDPR | €10,000 | ↗ |
| 21 Aug 2018 | Alpha BankAlpha Bank was fined by the HDPA for failing to maintain and process accurate data of its debtors. The authority found that the bank’s conduct breached data protection requirements. | GR | HDPA | GDPR | €10,000 | ↗ |
| 05 Mar 2015 | Comune di AvolaComune di Avola was fined 10,000 EUR by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its website. The case involved a breach of privacy rules and the unlawful processing of special-category data. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Jul 2012 | Biodiversity S.p.A.Biodiversity S.p.A. was fined by the Garante for failing to timely notify personal data processing activities related to molecular diagnostics. The obligation arose under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Sept 2021 | Solera Italia s.r.l.Solera Italia s.r.l. was fined EUR 10,000 by the Garante for continuing to use an employee's email account after the employment ended. The authority found that the company did not provide proper information about this processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Nov 2017 | Società Alberghi Circeo s.r.l.Società Alberghi Circeo s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company failed to appoint data processing officers for employees handling personal data, in breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Mar 2015 | Comune di Acquarica del CapoThe Municipality of Acquarica del Capo was fined 10,000 EUR by the Garante for unlawfully publishing personal data revealing health information on its website. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 May 2015 | Provincia di FrosinoneProvincia di Frosinone was fined for failing to update the Security Policy Document (DPS) for several years. The authority found this to be a breach of security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Apr 2018 | Comune di DerutaThe Municipality of Deruta was fined 10,000 EUR for unlawfully providing lists of personal data of residents born in 1994–1996 to a private educational institution. The recipient was not entitled to receive the data under public utility exceptions. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Jun 2011 | Porto di Tropea s.p.a.Porto di Tropea s.p.a. was fined by the Garante 10,000 EUR for failing to provide adequate information about video surveillance. The authority also found that data processors were not formally appointed for customer data collected through mooring contracts. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Parnofiello AntonellaParnofiello Antonella, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to a healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl Alto MoliseAsl Alto Molise was fined 10,000 EUR by the Garante for failing to notify data processing activities related to health diagnosis, treatment, and prevention within the required timeframe. The breach violated the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 Aug 2014 | Compass ExpoCompass Expo was fined EUR 10,000 by the HDPA for sending unsolicited electronic communications without recipients' consent. The authority found a breach of Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €10,000 | ↗ |