Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 May 2018Pettirossi AngeloDr Pettirossi Angelo was fined by the Garante for failing to implement minimum security measures for personal data protection. The breach allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
16 Dec 2009Polisportiva Eschilo 1 società sportiva dilettantistica a r.l.Polisportiva Eschilo 1 was fined EUR 10,000 by the Italian Garante. The case concerned processing biometric data without prior notification to the supervisory authority, which breached data protection rules.ITGaranteGDPR€10,000
13 Jan 2023CORREDURÍA DE SEGUROS DE MADRID, S.L.CORREDURÍA DE SEGUROS DE MADRID, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company linked the complainant’s bank account to insurance policies they had not taken out, resulting in unauthorized charges.ESAEPDGDPR€10,000
27 Mar 2014Casa di cura Scarnati srlCasa di cura Scarnati srl was fined €10,000 by the Garante. The authority found that the company failed to properly designate, in writing, the employees authorized to process personal data.ITGaranteGDPR€10,000
13 Feb 2007Asl Basso MoliseAsl Basso Molise was fined by the Garante for failing to notify its data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code.ITGaranteGDPR€10,000
05 Jan 2024B.B.B.The entity was fined for publishing personal images and phone numbers on Telegram channels without the data subjects’ consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€10,000
01 Jan 2019D. B.B.B.The respondent was fined for publishing intimate photos and conversations of the complainant on WhatsApp without consent. The authority found a breach of data protection rules.ESAEPDGDPR€10,000
10 Oct 2022EKO ABEEThe fine was imposed for a violation of Article 15 GDPR because the controller failed to provide the data subject with access to their personal data. The case concerns non-compliance with the obligation to ensure the right of access within the required scope.GRHDPAGDPR€10,000
27 Nov 2024Engineering Ingegneria Informatica S.p.A.The Garante imposed a fine of EUR 10,000 on Engineering Ingegneria Informatica S.p.A. for a data breach involving the Molise regional health portal. A system vulnerability allowed unauthorized access to personal data.ITGaranteGDPR€10,000
31 Jan 2024SOCIETE AYANT POUR ACTIVITE LE SOUTIEN AUX ENTREPRISES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE LE SOUTIEN AUX ENTREPRISES. The decision concerns a breach of rules supervised by the CNIL.FRCNILGDPR€10,000
12 Sept 2013Comune di MantovaThe Municipality of Mantua was fined by the Garante for unlawfully disseminating personal data through its online services without a proper legal basis. The authority found a breach of Article 19 of the Italian Data Protection Code.ITGaranteGDPR€10,000
31 May 2022DKN.5131.51.2021StatusuchylonaTytuUODO imposed an administrative fine of PLN 10,000 for a breach involving the recording and storage of sound in a monitoring system. The case concerned improper use of CCTV monitoring with audio capture.PLUODOGDPR€2,183
04 Apr 2007Azienda sanitaria locale di PescaraAzienda sanitaria locale di Pescara was fined €10,000 by the Garante for breaching data protection rules. The case involved improper handling of sensitive personal data, including genetic and health information, without the required notification to the authority.ITGaranteGDPR€10,000
03 Nov 2021B.B.B.The entity was fined by the AEPD 10,000 EUR for publishing the complainant's phone number on a website without consent. This led to unwanted calls, and despite requests for removal, the number reappeared, breaching GDPR Article 6.ESAEPDGDPR€10,000
17 Jan 2008Assioma selezione e sviluppo s.r.l.Assioma selezione e sviluppo s.r.l. was fined by the Garante in the amount of 10,000 EUR for failing to comply with data protection notification requirements. The breach concerned Article 163 of the Italian Data Protection Code.ITGaranteGDPR€10,000
23 Mar 2017Azienda Sanitaria ULSS 6 di VicenzaAzienda Sanitaria ULSS 6 di Vicenza was fined by the Garante 10,000 EUR for unlawfully communicating an individual's health data to the Comune di Arcugnano without proper authorization. The case involved a breach of lawful processing rules and safeguards for special-category data.ITGaranteGDPR€10,000
26 Sept 2022HERON CITY VALENCIA MANAGEMENT S.L.HERON CITY VALENCIA MANAGEMENT S.L. was fined by the AEPD in the amount of 10,000 EUR for refusing to provide access to surveillance footage. This conduct breached the data subject’s rights, in particular the right of access under Article 15 of the GDPR.ESAEPDGDPR€10,000
25 Aug 2021Amendă în aplicarea Legii nr. 190/2018The operator was fined for failing to respond to the authority's requests during an investigation. The case concerns non-cooperation with ANSPDCP in the course of supervisory proceedings.ROANSPDCPGDPR€2,029
20 Jun 2013Terme di Montecatini s.p.a.Terme di Montecatini s.p.a. was fined by the Garante in the amount of 10,000 EUR. The company processed personal and sensitive data of national health service patients undergoing spa treatments without obtaining consent, in breach of Article 23 of the Italian Data Protection Code.ITGaranteGDPR€10,000
22 Oct 2024political partyThe Hellenic Data Protection Authority imposed a 10,000 EUR fine on a political party for unlawful processing of the personal data of overseas voters. The case concerns data protection breaches in the handling of electoral information.GRHellenic Data Protection AuthorityGDPR€10,000