Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Aug 2022niegoThe President of UODO imposed a fine of PLN 6,854 on an individual for processing the complainant’s image through video surveillance. The breach consisted of failing to cooperate with the authority and not providing information necessary for it to perform its duties.PLUODOGDPR€1,450
10 Feb 2026Dane anonimowe (R.)The UODO imposed a PLN 6,700 fine on Anonymous data (R.) for failing to notify a personal data breach within 72 hours and for not informing affected individuals without undue delay. The authority also found deficiencies in the appointment of the data protection officer, including missing contact details, failure to notify the supervisory authority, and a conflict of interest because the role was assigned to a board member.PLUODOGDPR€1,589
02 Feb 2022Anonymisé (CNPD decision-02-fr-2022)The company was fined by the CNPD 6,600 EUR for breaches of GDPR requirements. The authority found deficiencies in data minimization, retention, security of processing, and the information provided to data subjects in connection with video surveillance and geolocation systems.LUCNPDGDPR€6,600
04 Aug 2021Anonymisé (CNPD decision-30-fr-2021)The public establishment failed to communicate the DPO’s contact details to the supervisory authority and did not provide the DPO with the resources needed to perform the role effectively. CNPD found breaches of GDPR Articles 37(7), 38(2), and 39(1)(b) and imposed a fine of 6,600 EUR.LUCNPDGDPR€6,600
17 Oct 2024Giancarlo FranciniThe Garante imposed a EUR 6,500 fine on Giancarlo Francini for breaches related to the processing of health data. The authority found failures to meet transparency obligations and noted that data subject requests were answered only after a complaint was filed.ITGaranteGDPR€6,500
11 Feb 2021Azienda Sanitaria Locale n. 2 Lanciano-Vasto-ChietiAzienda Sanitaria Locale n. 2 Lanciano-Vasto-Chieti was fined by the Garante 6,500 EUR for violations related to the processing of health data. The нарушения led to a data breach incident.ITGaranteGDPR€6,500
27 Oct 2016Studio Medico Odontoiatrico Associato Gimmelli B. & G.Studio Medico Odontoiatrico Associato Gimmelli B. & G. was fined by the Garante for unlawfully processing personal data by disclosing it to Ina Assitalia s.p.a. without obtaining the required informed consent from the data subject. The case reflects a breach of core lawful-processing requirements.ITGaranteGDPR€6,400
14 Feb 2013Impresa individuale Mail TrainingThe company was fined for making an unsolicited promotional phone call without providing the required information or obtaining consent. The authority treated this as a breach of data protection rules.ITGaranteGDPR€6,400
07 Mar 2013Paolo RanieriPaolo Ranieri was fined 6,400 EUR by the Italian data protection authority, Garante. The sanction concerned sending an electoral email without the required information and without obtaining consent from recipients.ITGaranteGDPR€6,400
21 Feb 2013Forum Media Edizioni s.r.l.Forum Media Edizioni s.r.l. was fined by the Italian Garante in the amount of €6,400. The case concerned the sending of unsolicited promotional faxes without the required information and without obtaining consent, in breach of Articles 13 and 130 of the Italian Data Protection Code.ITGaranteGDPR€6,400
01 Jun 2016Ordinanza ingiunzione - 1 giugno 2016 [5423590]A paramedical professional processed clients’ personal data for health purposes without providing the required privacy notice or obtaining consent. The Garante found violations of Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€6,400
21 Mar 2013Pologest s.r.l.Pologest s.r.l. was fined by the Garante €6,400 for sending unsolicited promotional communications by fax. The conduct breached data protection rules governing marketing communications.ITGaranteGDPR€6,400
20 Jul 2017S.I.T. s.r.l.S.I.T. s.r.l. was fined by the Garante in the amount of EUR 6,400 for unauthorized access to surveillance images and for processing customer data without proper notice to data subjects. The authority found that these actions breached data protection rules.ITGaranteGDPR€6,400
13 Dec 2012Studio Immobiliare Conca D'Oro s.r.l.Studio Immobiliare Conca D'Oro s.r.l. was fined by the Garante 6,400 EUR for making promotional phone calls without providing the required information notice and without obtaining consent. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€6,400
19 Sept 2013Cooperativa di servizi AggregoCooperativa di servizi Aggrego was fined €6,400 by the Garante. The case concerned the sending of unsolicited promotional faxes without prior consent, in breach of data protection rules.ITGaranteGDPR€6,400
02 Oct 2019Tgroup s.r.l.Tgroup s.r.l. was fined 6,400 EUR by the Italian data protection authority, Garante. The case concerned the activation of a SIM card without the user's knowledge, which breached data protection rules.ITGaranteGDPR€6,400
11 Feb 2016Anteprima Group srlAnteprima Group srl was fined EUR 6,400 by the Garante. The case concerned an unsolicited promotional call made without prior information to the recipient and without obtaining consent.ITGaranteGDPR€6,400
24 Sept 2015Acquapark di Milillo Rosa & C. s.a.s.Acquapark di Milillo Rosa & C. s.a.s. was fined EUR 6,400 by the Garante for collecting personal data without providing the required information notice and for publishing user photos without consent. The case concerns failures to meet transparency obligations and lawful processing requirements.ITGaranteGDPR€6,400
30 Jan 2014impresa individuale Otelma di Belelli Marco AmletoThe sole proprietorship Otelma di Belelli Marco Amleto was fined EUR 6,400 by the Garante for failing to implement minimum security measures when processing sensitive data via its website. The breaches included not appointing a data processor and not preparing a security program document.ITGaranteGDPR€6,400
11 Mar 2021dott. Gregorio GrecoDott. Gregorio Greco was fined 6,400 EUR by the Garante for failing to provide information to data subjects and for processing patients' health-related personal data without consent. The case concerns patient data and breaches of transparency and lawful basis requirements.ITGaranteGDPR€6,400