BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Jun 2017 | Azienda Policlinico Umberto IAzienda Policlinico Umberto I was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate data processing officers and provide them with the necessary instructions, breaching minimum security measures under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Sept 2021 | Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 04 Sept 2023 | ASSOCIACIO OASIS CULTURALASSOCIACIO OASIS CULTURAL was fined by the AEPD EUR 10,000 for unlawful processing of personal data. The case concerned the publication on TikTok of a video showing minors performing dances with sexual connotations without a legal basis under Article 6(1) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 26 Nov 2024 | ASSOCIATION AYANT POUR ACTIVITE L'ACTION SOCIALE SANS HEBERGEMENT ET LA GESTION D'ETABLISSEMENTS MEDICO-SOCIAUX ET SANITAIRES (procédure simplifiée)CNIL imposed an administrative fine of 10,000 EUR on ASSOCIATION AYANT POUR ACTIVITE L'ACTION SOCIALE SANS HEBERGEMENT ET LA GESTION D'ETABLISSEMENTS MEDICO-SOCIAUX ET SANITAIRES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 19 Jan 2023 | ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal and banking data without consent. The conduct occurred in connection with a contract renewal offer presented as if it came from the complainant's electricity supplier. | ES | AEPD | GDPR | €10,000 | ↗ |
| 17 Sept 2019 | Geanonimiseerd (APD 06/2019)The case concerned a complaint about the use of electronic identity cards to create customer cards. The Litigation Chamber found breaches of data minimization, lawful basis for processing, and information duties under the GDPR, and imposed a fine of EUR 10,000. | BE | APD | GDPR | €10,000 | ↗ |
| 19 Jan 2017 | Bertolotto Michele e Azienda Universitaria Ospedaliera Ospedali Riuniti di TriesteThe Garante imposed a 10,000 EUR fine on Bertolotto Michele and Azienda Universitaria Ospedaliera Ospedali Riuniti di Trieste. The case concerned unauthorized access by two doctors to personal health data, including Bertolotto’s data. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Jun 2023 | ELECTRAWORKS - CEUTA, S.A.ELECTRAWORKS - CEUTA, S.A. did not comply with a data deletion request and retained personal data for 10 years without proper justification. The AEPD found this to be a breach of Article 13 GDPR and imposed a 10,000 EUR fine. | ES | AEPD | GDPR | €10,000 | ↗ |
| 22 Jun 2022 | B.B.B.An individual's personal data was used without consent to publish an online advertisement for sexual services, resulting in harassment. The responsible entity was fined for violating Article 6(1) of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 10 Apr 2025 | Azienda Ospedaliera Universitaria Integrata VeronaAzienda Ospedaliera Universitaria Integrata Verona was fined by the Garante for failing to adequately protect personal data. After a ransomware attack, 612 GB of data was published on the dark web, indicating serious security shortcomings. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl Centro MoliseAsl Centro Molise was fined by the Garante for processing personal data, including genetic and biometric data, without the required notification. The breach concerned obligations under the Italian data protection code. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Jan 2025 | CENTRE DE FORMATION A DISTANCE D'APPRENTIS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on CENTRE DE FORMATION A DISTANCE D'APPRENTIS and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 30 May 2018 | Alpha BankAlpha Bank was fined by the HDPA for failing to respond to a data subject access request within the prescribed timeframe. The case concerned Article 12 of Law 2472/1997 and the bank’s obligations to facilitate data subject rights. | GR | HDPA | GDPR | €10,000 | ↗ |
| 07 Jul 2011 | F.B. Aurum di Ferrero Wilma e Barathier Sergio s.n.c.F.B. Aurum di Ferrero Wilma e Barathier Sergio s.n.c. was fined by the Garante 10,000 EUR for operating a video surveillance system without providing the required notice to data subjects. This constituted a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Oct 2010 | Clinica Luccioni S.p.a.Clinica Luccioni S.p.a. was fined by the Garante for failing to timely notify the authority of personal data processing activities required under the Italian Data Protection Code. The case concerned a breach of the notification obligation to the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | Grizzaffi Management S.r.l.Grizzaffi Management S.r.l. was fined by the Garante in the amount of 10,000 EUR for sending unsolicited promotional emails without recipient consent. The conduct breached GDPR rules on electronic marketing and consent for commercial communications. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Jan 2008 | Laboratorio di analisi cliniche Pasini MarioLaboratorio di analisi cliniche Pasini Mario was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Aug 2020 | Anonymizováno (ÚOOÚ UOOU-05284/19-36)The entity was fined for publishing a partially anonymized criminal order on Facebook that still contained personal data. The authority found a breach of GDPR principles governing lawful processing and personal data protection. | CZ | UOOU | GDPR | €383 | ↗ |
| 11 Jul 2013 | Patronato ENCALPatronato ENCAL was fined by the Garante 10,000 EUR for failing to implement minimum security measures in the assignment and use of authentication credentials for access to INPS databases. The breach concerned inadequate access control over systems containing sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 May 2022 | РТК ЕООДThe company processed personal data without a lawful basis by including an individual's data in a public register without a valid contract or consent. The authority found this to be a breach of data protection principles and imposed a fine. | BG | CPDP | GDPR | €5,113 | ↗ |