BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 May 2018 | Pettirossi AngeloDr Pettirossi Angelo was fined by the Garante for failing to implement minimum security measures for personal data protection. The breach allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Dec 2009 | Polisportiva Eschilo 1 società sportiva dilettantistica a r.l.Polisportiva Eschilo 1 was fined EUR 10,000 by the Italian Garante. The case concerned processing biometric data without prior notification to the supervisory authority, which breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Jan 2023 | CORREDURÍA DE SEGUROS DE MADRID, S.L.CORREDURÍA DE SEGUROS DE MADRID, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company linked the complainant’s bank account to insurance policies they had not taken out, resulting in unauthorized charges. | ES | AEPD | GDPR | €10,000 | ↗ |
| 27 Mar 2014 | Casa di cura Scarnati srlCasa di cura Scarnati srl was fined €10,000 by the Garante. The authority found that the company failed to properly designate, in writing, the employees authorized to process personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl Basso MoliseAsl Basso Molise was fined by the Garante for failing to notify its data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Jan 2024 | B.B.B.The entity was fined for publishing personal images and phone numbers on Telegram channels without the data subjects’ consent. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2019 | D. B.B.B.The respondent was fined for publishing intimate photos and conversations of the complainant on WhatsApp without consent. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 10 Oct 2022 | EKO ABEEThe fine was imposed for a violation of Article 15 GDPR because the controller failed to provide the data subject with access to their personal data. The case concerns non-compliance with the obligation to ensure the right of access within the required scope. | GR | HDPA | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Engineering Ingegneria Informatica S.p.A.The Garante imposed a fine of EUR 10,000 on Engineering Ingegneria Informatica S.p.A. for a data breach involving the Molise regional health portal. A system vulnerability allowed unauthorized access to personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 Jan 2024 | SOCIETE AYANT POUR ACTIVITE LE SOUTIEN AUX ENTREPRISES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE LE SOUTIEN AUX ENTREPRISES. The decision concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €10,000 | ↗ |
| 12 Sept 2013 | Comune di MantovaThe Municipality of Mantua was fined by the Garante for unlawfully disseminating personal data through its online services without a proper legal basis. The authority found a breach of Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 May 2022 | DKN.5131.51.2021StatusuchylonaTytuUODO imposed an administrative fine of PLN 10,000 for a breach involving the recording and storage of sound in a monitoring system. The case concerned improper use of CCTV monitoring with audio capture. | PL | UODO | GDPR | €2,183 | ↗ |
| 04 Apr 2007 | Azienda sanitaria locale di PescaraAzienda sanitaria locale di Pescara was fined €10,000 by the Garante for breaching data protection rules. The case involved improper handling of sensitive personal data, including genetic and health information, without the required notification to the authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 03 Nov 2021 | B.B.B.The entity was fined by the AEPD 10,000 EUR for publishing the complainant's phone number on a website without consent. This led to unwanted calls, and despite requests for removal, the number reappeared, breaching GDPR Article 6. | ES | AEPD | GDPR | €10,000 | ↗ |
| 17 Jan 2008 | Assioma selezione e sviluppo s.r.l.Assioma selezione e sviluppo s.r.l. was fined by the Garante in the amount of 10,000 EUR for failing to comply with data protection notification requirements. The breach concerned Article 163 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Mar 2017 | Azienda Sanitaria ULSS 6 di VicenzaAzienda Sanitaria ULSS 6 di Vicenza was fined by the Garante 10,000 EUR for unlawfully communicating an individual's health data to the Comune di Arcugnano without proper authorization. The case involved a breach of lawful processing rules and safeguards for special-category data. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Sept 2022 | HERON CITY VALENCIA MANAGEMENT S.L.HERON CITY VALENCIA MANAGEMENT S.L. was fined by the AEPD in the amount of 10,000 EUR for refusing to provide access to surveillance footage. This conduct breached the data subject’s rights, in particular the right of access under Article 15 of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 25 Aug 2021 | Amendă în aplicarea Legii nr. 190/2018The operator was fined for failing to respond to the authority's requests during an investigation. The case concerns non-cooperation with ANSPDCP in the course of supervisory proceedings. | RO | ANSPDCP | GDPR | €2,029 | ↗ |
| 20 Jun 2013 | Terme di Montecatini s.p.a.Terme di Montecatini s.p.a. was fined by the Garante in the amount of 10,000 EUR. The company processed personal and sensitive data of national health service patients undergoing spa treatments without obtaining consent, in breach of Article 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Oct 2024 | political partyThe Hellenic Data Protection Authority imposed a 10,000 EUR fine on a political party for unlawful processing of the personal data of overseas voters. The case concerns data protection breaches in the handling of electoral information. | GR | Hellenic Data Protection Authority | GDPR | €10,000 | ↗ |