Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Jul 2024FREE TECHNOLOGIES EXCOM, S.L.FREE TECHNOLOGIES EXCOM, S.L. was fined by the AEPD 10,000 EUR for sending unencrypted emails containing user credentials without prior notice. The authority also noted the absence of two-factor authentication, which constituted a breach of Article 32 GDPR.ESAEPDGDPR€10,000
08 Feb 2007Asl Vibo ValentiaThe health authority Asl Vibo Valentia was fined by Garante for improperly handling sensitive personal data, including genetic and biometric data, without proper authorization. The case concerns a breach of data protection rules and the legal basis required for processing such data.ITGaranteGDPR€10,000
17 Jan 2008Aesculapius s.r.l.Aesculapius s.r.l. was fined by the Garante for missing the deadline to notify personal data processing activities. The breach concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
05 Oct 2017Italprest di Luca Bosimini & C. s.a.s.Italprest di Luca Bosimini & C. s.a.s. was fined €10,000 by the Garante. The authority found that the company failed to implement minimum security measures, including the use of passwords shorter than eight characters, in breach of Article 33 of the Italian Data Protection Code.ITGaranteGDPR€10,000
21 Dec 2023MediafondMediafond was fined EUR 10,000 by the Garante for continuing to use a former employee’s email account after the employment ended. The company also forwarded emails without proper notice, which breached GDPR requirements.ITGaranteGDPR€10,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined 10,000 EUR by the HDPA. The authority found that the bank did not adequately satisfy the data subject’s right of access.GRHDPAGDPR€10,000
13 Feb 2007Asl n. 5 CrotoneAsl n. 5 Crotone was fined by the Garante for failing to notify the processing of sensitive personal data, including genetic and health data. The notification requirement was set out in the Italian Data Protection Code.ITGaranteGDPR€10,000
07 Apr 2022Findomestic Banca spaFindomestic Banca spa was fined by the Garante 10,000 EUR for improperly contacting a third party, namely the debtor’s spouse, about a financial obligation. The authority found that this conduct constituted a GDPR violation.ITGaranteGDPR€10,000
10 Jun 2025Accounting Audit SRLAccounting Audit SRL was fined by ANSPDCP for a data security breach caused by a cyber attack. The incident led to unauthorized disclosure of personal data, including identification data and financial documents, affecting a large number of data subjects, mainly employees of the company’s clients.ROANSPDCPGDPR€10,000
01 Oct 2015dr. Ruben Omar UnzurrunzagaDr. Ruben Omar Unzurrunzaga was fined by the Garante for processing clients’ personal data for medical purposes without obtaining documented consent. The authority found a breach of Article 23 of the Italian Data Protection Code.ITGaranteGDPR€10,000
10 Jul 2025Cooperativa Sociale CoopseliosCooperativa Sociale Coopselios was fined by the Garante €10,000 for failing to properly handle data subject requests. The нарушения concerned the GDPR rights of access, rectification, and data portability.ITGaranteGDPR€10,000
21 Jul 2022Clio s.r.l.Clio s.r.l. was fined by the Italian Garante in the amount of 10,000 EUR for violations related to personal data processing. The case involved inadequate protection of whistleblower identities, in breach of the GDPR and national privacy code provisions.ITGaranteGDPR€10,000
14 Sept 2023Comune di San SeveroThe Municipality of San Severo was fined EUR 10,000 by the Garante for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€10,000
16 Nov 2017Sarida s.r.l.Sarida s.r.l. was fined by the Italian Garante 10,000 EUR for inadequate security measures in the processing of personal data. The authority specifically noted insufficient password requirements for access to the company’s systems.ITGaranteGDPR€10,000
19 Sept 2013Estav Nordovest ToscanaEstav Nordovest Toscana was fined 10,000 EUR by the Garante. The violation concerned the unlawful publication of candidates' judicial data on its website during a recruitment process.ITGaranteGDPR€10,000
09 Jan 2023NANDIVALE, S.L.NANDIVALE, S.L. was fined by the AEPD EUR 10,000 for publishing images of minors on Instagram without parental consent. The authority found this conduct to be in breach of GDPR Article 6(1).ESAEPDGDPR€10,000
23 Mar 2017Ente Nazionale per L’Aviazione Civile (ENAC)ENAC was fined by the Garante in the amount of 10,000 EUR. The authority found that adequate security measures were not implemented, in breach of Articles 33 and 34 of the Italian Data Protection Code.ITGaranteGDPR€10,000
17 Apr 2023SOCIETE D'AIDE A DOMICILE POUR LES PERSONNES AGEES ET HANDICAPEESCNIL imposed a EUR 10,000 penalty on SOCIETE D'AIDE A DOMICILE POUR LES PERSONNES AGEES ET HANDICAPEES in connection with the liquidation of a penalty payment. The case concerns compliance with a prior obligation and the sanction for non-compliance.FRCNILGDPR€10,000
12 Dec 2024Start To Fly S.r.l.Start To Fly S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited emails and SMS messages to a complainant. The complainant was unable to unsubscribe from the mailing list despite multiple attempts.ITGaranteGDPR€10,000
17 Apr 2026Azienda USL ModenaAzienda USL Modena was fined by the Garante in the amount of 10,000 EUR for a data breach caused by a ransomware attack. The authority found a breach of GDPR data security obligations.ITGaranteGDPR€10,000