BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Apr 2022 | B.B.B.The entity was fined by the AEPD in the amount of EUR 10,000 for publishing personal data, including images and videos, without the consent of the data subjects. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 04 Oct 2011 | Il Marmo s.r.l.Il Marmo s.r.l. was fined by the Garante in the amount of 10,000 EUR for failing to provide the required privacy notice on its website, specifically in the contact form. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Sept 2011 | Enterprise Service s.r.l.Enterprise Service s.r.l. was fined by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The company also failed to provide the required information notice under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Ordinanza ingiunzione - 22 maggio 2018 [9037459]A general practitioner failed to implement minimum security measures to protect patients' personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Jun 2023 | Anonymisiert (DSB 2023-0.420.407)The responsible party unlawfully processed special categories of personal data by publishing health data in response to an online review. This breached GDPR principles of lawfulness, purpose limitation, and data minimization. | AT | DSB | GDPR | €10,000 | ↗ |
| 04 Jun 2015 | Direzione Casa Circondariale di BariDirezione Casa Circondariale di Bari was fined €10,000 by the Garante for unlawfully processing sensitive data. The authority found that it collected, stored, and communicated the names of participants in a union demonstration without initiating any disciplinary proceedings, in breach of data protection law. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Dec 2022 | SUDREZIDENȚIAL Broker S.R.L.The company was fined for failing to inform data subjects about a personal data breach. The authority found a violation of Article 34 of the GDPR. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 19 Feb 2015 | Comune di MesoracaComune di Mesoraca was fined by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its institutional website. The case involved unauthorized disclosure of medical information made publicly accessible. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 Feb 2023 | SOCIETE EXERCANT UNE ACTIVITE DE DETAIL D'HABILLEMENT EN MAGASIN SPECIALISE (procédure simplifiée)CNIL imposed a fine of 10,000 EUR on SOCIETE EXERCANT UNE ACTIVITE DE DETAIL D'HABILLEMENT EN MAGASIN SPECIALISE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 16 Dec 2021 | Centro di Medicina preventiva s.r.l.Centro di Medicina preventiva s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate measures to prevent unauthorized access to personal data. The deficiency resulted in a data breach. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jul 2022 | Stay Over s.r.l.Stay Over s.r.l. was fined by the Garante EUR 10,000 for a delayed and inadequate response to a data access request. The authority also found unlawful processing of a former employee's email account after employment ended. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Oct 2017 | Antea Service soc. coop.Antea Service soc. coop. was fined by the Garante 10,000 EUR for unlawfully processing biometric data of employees. The data were used to monitor workplace attendance. The case concerns a breach of personal data protection rules in an employment context. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Oct 2012 | Umbra Acque S.p.a.Umbra Acque S.p.a. was fined by the Garante 10,000 EUR for breaches of data protection rules. The authority found that the company failed to designate data processing officers and did not adopt minimum security measures for its video surveillance system. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Luigi PagnanelliLuigi Pagnanelli, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Feb 2015 | Comune di BellizziComune di Bellizzi was fined for unlawfully publishing sensitive personal data revealing health information on its institutional website. The conduct breached privacy rules governing the processing and disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Comune di Motta Sant'AnastasiaThe Garante imposed a EUR 10,000 fine on Comune di Motta Sant'Anastasia for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 03 Nov 2020 | LOSADA ADVOCATS S.L.LOSADA ADVOCATS S.L. was fined by the AEPD EUR 10,000 for sending an email without using BCC. This exposed recipients’ email addresses and breached data protection principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Apr 2009 | Casa di cura Sant'Antonio s.p.a.Casa di cura Sant'Antonio s.p.a. was fined by the Italian data protection authority, Garante. The case concerned processing personal data without the required notification under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Mar 2015 | HYUNDAY MOTOR ESPAÑA, S.L.U.HYUNDAY MOTOR ESPAÑA, S.L.U. was fined 10,000 EUR by the AEPD. The sanction concerned sending unsolicited commercial emails without recipient consent, in breach of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 13 Feb 2025 | Claudio BattagliaDr. Claudio Battaglia, an oncologist, was fined for using patient data for electoral propaganda without consent. The case indicates a breach of GDPR principles on lawfulness and purpose limitation. | IT | Garante | GDPR | €10,000 | ↗ |