BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Jul 2024 | FREE TECHNOLOGIES EXCOM, S.L.FREE TECHNOLOGIES EXCOM, S.L. was fined by the AEPD 10,000 EUR for sending unencrypted emails containing user credentials without prior notice. The authority also noted the absence of two-factor authentication, which constituted a breach of Article 32 GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 08 Feb 2007 | Asl Vibo ValentiaThe health authority Asl Vibo Valentia was fined by Garante for improperly handling sensitive personal data, including genetic and biometric data, without proper authorization. The case concerns a breach of data protection rules and the legal basis required for processing such data. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Jan 2008 | Aesculapius s.r.l.Aesculapius s.r.l. was fined by the Garante for missing the deadline to notify personal data processing activities. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Oct 2017 | Italprest di Luca Bosimini & C. s.a.s.Italprest di Luca Bosimini & C. s.a.s. was fined €10,000 by the Garante. The authority found that the company failed to implement minimum security measures, including the use of passwords shorter than eight characters, in breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Dec 2023 | MediafondMediafond was fined EUR 10,000 by the Garante for continuing to use a former employee’s email account after the employment ended. The company also forwarded emails without proper notice, which breached GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Jun 2023 | Piraeus Bank S.A.Piraeus Bank S.A. was fined 10,000 EUR by the HDPA. The authority found that the bank did not adequately satisfy the data subject’s right of access. | GR | HDPA | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl n. 5 CrotoneAsl n. 5 Crotone was fined by the Garante for failing to notify the processing of sensitive personal data, including genetic and health data. The notification requirement was set out in the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Apr 2022 | Findomestic Banca spaFindomestic Banca spa was fined by the Garante 10,000 EUR for improperly contacting a third party, namely the debtor’s spouse, about a financial obligation. The authority found that this conduct constituted a GDPR violation. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Jun 2025 | Accounting Audit SRLAccounting Audit SRL was fined by ANSPDCP for a data security breach caused by a cyber attack. The incident led to unauthorized disclosure of personal data, including identification data and financial documents, affecting a large number of data subjects, mainly employees of the company’s clients. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 01 Oct 2015 | dr. Ruben Omar UnzurrunzagaDr. Ruben Omar Unzurrunzaga was fined by the Garante for processing clients’ personal data for medical purposes without obtaining documented consent. The authority found a breach of Article 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Jul 2025 | Cooperativa Sociale CoopseliosCooperativa Sociale Coopselios was fined by the Garante €10,000 for failing to properly handle data subject requests. The нарушения concerned the GDPR rights of access, rectification, and data portability. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jul 2022 | Clio s.r.l.Clio s.r.l. was fined by the Italian Garante in the amount of 10,000 EUR for violations related to personal data processing. The case involved inadequate protection of whistleblower identities, in breach of the GDPR and national privacy code provisions. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2023 | Comune di San SeveroThe Municipality of San Severo was fined EUR 10,000 by the Garante for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Nov 2017 | Sarida s.r.l.Sarida s.r.l. was fined by the Italian Garante 10,000 EUR for inadequate security measures in the processing of personal data. The authority specifically noted insufficient password requirements for access to the company’s systems. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Sept 2013 | Estav Nordovest ToscanaEstav Nordovest Toscana was fined 10,000 EUR by the Garante. The violation concerned the unlawful publication of candidates' judicial data on its website during a recruitment process. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Jan 2023 | NANDIVALE, S.L.NANDIVALE, S.L. was fined by the AEPD EUR 10,000 for publishing images of minors on Instagram without parental consent. The authority found this conduct to be in breach of GDPR Article 6(1). | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Mar 2017 | Ente Nazionale per L’Aviazione Civile (ENAC)ENAC was fined by the Garante in the amount of 10,000 EUR. The authority found that adequate security measures were not implemented, in breach of Articles 33 and 34 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Apr 2023 | SOCIETE D'AIDE A DOMICILE POUR LES PERSONNES AGEES ET HANDICAPEESCNIL imposed a EUR 10,000 penalty on SOCIETE D'AIDE A DOMICILE POUR LES PERSONNES AGEES ET HANDICAPEES in connection with the liquidation of a penalty payment. The case concerns compliance with a prior obligation and the sanction for non-compliance. | FR | CNIL | GDPR | €10,000 | ↗ |
| 12 Dec 2024 | Start To Fly S.r.l.Start To Fly S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited emails and SMS messages to a complainant. The complainant was unable to unsubscribe from the mailing list despite multiple attempts. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Apr 2026 | Azienda USL ModenaAzienda USL Modena was fined by the Garante in the amount of 10,000 EUR for a data breach caused by a ransomware attack. The authority found a breach of GDPR data security obligations. | IT | Garante | GDPR | €10,000 | ↗ |