BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Sept 2021 | Azienda Ospedaliero-Universitaria di ModenaAzienda Ospedaliero-Universitaria di Modena was fined by the Garante for the incorrect handling of sensitive health data, including HIV diagnoses, during the COVID-19 emergency. The case concerned breaches of personal data protection rules and medical confidentiality. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Sept 2021 | La Prima S.r.l.La Prima S.r.l. was fined by the Garante for carrying out promotional activities without a valid legal basis. The authority found that this conduct breached GDPR requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Comune di Montalbano JonicoThe Garante fined Comune di Montalbano Jonico 5,000 EUR for breaching the data minimization principle. The municipality published excessive personal data on its website, including health-related information. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Istituto per Ciechi Ardizzone GioeniIstituto per Ciechi Ardizzone Gioeni was fined by the Garante EUR 5,000 for failing to provide adequate data protection information about the activation of a video surveillance system. The case involved vulnerable guests, including blind and visually impaired persons, who were not properly informed about the processing of their personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Consorzio di Bonifica dell’OristaneseConsorzio di Bonifica dell’Oristanese was fined EUR 5,000 by the Garante for publishing a disciplinary measure on its website that included an employee’s health information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Azienda sanitaria provinciale di CosenzaAzienda sanitaria provinciale di Cosenza was fined by the Garante for unlawfully publishing health data on its institutional website. The case involved breaches of data protection principles and required security measures for sensitive data. | IT | Garante | GDPR | €18,000 | ↗ |
| 16 Sept 2021 | Università Commerciale “Luigi Bocconi” di MilanoUniversità Commerciale “Luigi Bocconi” di Milano was fined EUR 150,000 by the Garante for data protection breaches during remote exams. The authority found an insufficient legal basis, inadequate transparency, and weak security measures for transfers of data to the USA. | IT | Garante | GDPR | €150,000 | ↗ |
| 16 Sept 2021 | Ordine Provinciale di Roma dei Medici Chirurghi e degli OdontoiatriOrdine Provinciale di Roma dei Medici Chirurghi e degli Odontoiatri was fined by the Garante €5,000 for failing to adequately respond to a data subject’s request for access to personal data. The authority found a breach of GDPR Articles 12 and 15. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Istituto Comprensivo - IC Cosenza III “V. Negroni”Istituto Comprensivo - IC Cosenza III “V. Negroni” was fined by the Garante 2,000 EUR for unlawful processing of personal data and inadequate data protection. The authority also noted that personal data were made accessible online, increasing the risk to affected individuals. | IT | Garante | GDPR | €2,000 | ↗ |
| 16 Sept 2021 | Favrskov KommuneFavrskov Kommune was fined 75,000 DKK for failing to implement appropriate security measures, including encryption, to protect sensitive personal data on a stolen laptop. The authority found a breach of GDPR Article 32. | DK | Datatilsynet | GDPR | €10,086 | ↗ |
| 16 Sept 2021 | Accademia di Belle Arti di RomaAccademia di Belle Arti di Roma was fined EUR 5,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data in a disciplinary procedure and the dissemination of sensitive information. | IT | Garante | GDPR | €5,000 | ↗ |
| 10 Sept 2021 | LODEJU, S.L.LODEJU, S.L. was fined EUR 3,000 by the AEPD for excessive video surveillance of public space without proper signage. The authority found a breach of GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €3,000 | ↗ |
| 10 Sept 2021 | LA OFICINA BAR XXXXThe entity installed two surveillance cameras aimed at public areas without justification. This breached data protection principles. | ES | AEPD | GDPR | €1,500 | ↗ |
| 09 Sept 2021 | B.B.B.B.B.B. was fined by the AEPD for installing a CCTV system in a café that recorded public areas without proper signage. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 09 Sept 2021 | PACKLINK SHIPPING S.L.PACKLINK SHIPPING S.L. was fined by the AEPD €2,000 for using non-essential cookies on its website without providing the required information or obtaining explicit user consent. The authority treated this as a breach of data protection rules. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 08 Sept 2021 | Region MidtjyllandRegion Midtjylland was fined for failing to implement adequate access restrictions to an archive containing sensitive patient records. This allowed unauthorized access by patients and staff at a lifestyle center. | DK | Datatilsynet | GDPR | €40,344 | ↗ |
| 07 Sept 2021 | B.B.B.The entity was fined by the AEPD 5,000 EUR for publicly disseminating surveillance footage without justification. The authority found that this conduct breached data protection principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 07 Sept 2021 | ***EMPRESA.1The entity was fined for failing to display visible signage informing individuals about video surveillance. The authority considered this a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 01 Sept 2021 | B.B.B.The entity was fined by the AEPD for operating a video surveillance system that unjustifiably affected the privacy of third parties. The case indicates a lack of adequate safeguards or proportionality in data processing. | ES | AEPD | GDPR | €1,500 | ↗ |
| 01 Sept 2021 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 50,000 EUR for making unsolicited marketing calls and sending messages without consent. The conduct breached data protection principles. | ES | AEPD | GDPR | €50,000 | ↗ |