BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 May 2023 | La Gazzetta di Parma S.r.l.La Gazzetta di Parma S.r.l. was fined by the Garante EUR 10,000 for publishing an image of a presumed murderer in breach of privacy rules. The person was shown in a state of physical restraint without proper anonymization. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Aug 2023 | BODY LINE SRLIn July 2023, the Romanian authority ANSPDCP completed an investigation at BODY LINE SRL and found violations of GDPR provisions. The operator was fined 49,322 lei, equivalent to EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 30 Jul 2015 | Comune di MontallegroComune di Montallegro was fined for publishing documents on its website that contained sensitive personal data revealing individuals' health conditions. This constituted a breach of data protection law. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 Aug 2023 | Provvedimento del 31 agosto 2023 [9938463]The decision concerned a breach of rules on the processing of health data by a medical center. Garante imposed a fine of EUR 10,000. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 May 2023 | Dane anonimowe (Burmistrza Miasta i Gminy W.)UODO imposed an administrative fine of PLN 10,000 on the Mayor of the City and Commune of W. for failing to implement organisational measures appropriate to the risk of data processing. The deficiency resulted in an employee unlawfully copying personal data from a work computer to a portable storage device. | PL | UODO | GDPR | €2,187 | ↗ |
| 10 Dec 2024 | un operatorANSPDCP imposed a fine of 10,000 RON on un operator for non-compliance with the law. A warning was also issued. | RO | ANSPDCP | GDPR | €2,012 | ↗ |
| 22 Jan 2015 | Comune di RealmonteComune di Realmonte was fined by the Garante for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Mar 2023 | Alianța pentru Unirea RomânilorThe fine was imposed for collecting personal data through a website without informing the data subjects and without meeting the conditions for lawful processing. The breach affected a significant number of individuals and indicates non-compliance with basic transparency and legality requirements. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 29 Apr 2025 | Energia Pulita S.r.l.Energia Pulita S.r.l. was fined by the Garante for improper handling of personal data in telemarketing activities. The authority also noted failure to cooperate with the supervisory authority and incorrect identification of roles in data processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Jul 2021 | Regione CalabriaThe Garante imposed a 10,000 EUR fine on Regione Calabria for publishing personal data on its website. The conduct breached GDPR rules on lawful processing and protection of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Feb 2025 | ESTUDIO ALCAZAR DEL GENIL 2022, S.L.ESTUDIO ALCAZAR DEL GENIL 2022, S.L. was fined EUR 10,000 by the AEPD for collecting and storing personal data taken from mailboxes without consent or notice to the data subjects. The authority found breaches of the lawful basis and transparency requirements under GDPR Articles 6(1) and 14. | ES | AEPD | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale di PiacenzaAzienda sanitaria locale di Piacenza was fined for failing to notify the Garante about processing data relating to health and sexual life. The authority treated this as a breach of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Dec 2024 | Comune di BresciaThe Garante fined the Municipality of Brescia EUR 10,000 for violations related to the processing of personal data at a cemetery. The case concerned the unauthorized disclosure of individuals’ identities. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Jan 2023 | Εκδόσεις Αρκτίνος ΛτδThe decision concerns the unlawful publication of names and photos of police investigators by the newspaper “Politis”. The authority found a breach of the data minimization principle under the GDPR. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 03 Jul 2025 | BANCO INVERSIS, S.A.Banco Inversis, S.A. was fined by the AEPD in the amount of 10,000 EUR for a personal data breach. The case involved unauthorized access to personal data, which breached Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 15 Sept 2022 | Bper Banca S.p.A.Bper Banca S.p.A. was fined by the Garante for a delayed and inadequate response to requests for deletion of personal data. The authority found breaches of GDPR Articles 12 and 17. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Mar 2022 | Brav s.r.l.Brav s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate technical and organizational security measures. The issue concerned data processing linked to the management of contraventions by the local police of the Municipality of Genoa. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Nov 2024 | Thermogen S.r.l.Thermogen S.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The conduct breached the GDPR and national privacy laws. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 Jun 2023 | Liguria News S.r.l.Liguria News S.r.l. was fined by Garante EUR 10,000 for publishing an article that breached privacy rules. The article disclosed personal and sensitive information about individuals involved in the reported incident, including a minor. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | De Nittis MicheleDe Nittis Michele, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This deficiency allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |