BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Feb 2021 | VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD 10,000 EUR for sending an unsolicited commercial SMS to a complainant without prior consent. The authority found that the message was sent without the required authorization. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 11 Feb 2025 | AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD 10,000 EUR for sending unsolicited email messages and failing to properly handle unsubscribe requests. The conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 16 Apr 2015 | Media Lab Italia s.r.l.Media Lab Italia s.r.l. was fined by the Garante EUR 10,000 for processing personal data through a website form without obtaining separate consent for different purposes. The purposes included promotional communications and market research. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 May 2011 | Eredi Trossello dei Fratelli Trossello C.A.R. s.n.c.The company was fined EUR 10,000 by the Garante for operating a video surveillance system without the required privacy notice. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Molise dati S.p.A.Molise dati S.p.A. was fined EUR 10,000 by the Garante for a data breach involving the regional health portal. A system vulnerability allowed unauthorized access to personal data of citizens in the Molise Regional Registry. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Dec 2014 | Comune di NapoliComune di Napoli was fined 10,000 EUR by the Garante for publishing substitute teachers’ personal information, including health-related data, on its institutional website. The authority found that this disclosure breached privacy rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Mar 2023 | Gruppo SAE S.p.A.The Garante fined Gruppo SAE S.p.A. 10,000 EUR for publishing sensitive personal data, including medical information, in an article without proper consent. The case concerns unlawful processing of special-category personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Sept 2019 | ASOCIACION DE MEDICOS DEMOCRATASASOCIACION DE MEDICOS DEMOCRATAS was fined by the AEPD EUR 10,000 for processing the personal data of medical professionals without their consent. The authority found a breach of Article 6(1)(a) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 16 Dec 2021 | ASL LatinaASL Latina was fined for violations of data protection rules. The authority found inadequate measures to prevent data breaches involving health data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Maximum International Corp. S.r.l.Maximum International Corp. S.r.l. was fined by the Garante 10,000 EUR for persistent promotional calls despite objections and for failing to respond to data subject requests. The authority found breaches of GDPR rules on consent and information obligations. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Sept 2025 | La Prima SrlLa Prima Srl was fined EUR 10,000 by the Garante for sending unsolicited emails. The authority also found that the company failed to respond to a data deletion request, in breach of the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Adolfo AllegriniAdolfo Allegrini, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Sept 2017 | Serval s.r.l.Serval s.r.l. was fined by the Garante in the amount of €10,000 for failing to adopt minimum security measures. The authority also found that employees were not appointed as data processors, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Dec 2022 | ODRIA COSTAS INTERNACIONAL, S.L.ODRIA COSTAS INTERNACIONAL, S.L. was fined EUR 10,000 by the AEPD for publishing images of minors without consent on a real estate website. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 11 Feb 2016 | E-Via s.p.a.E-Via s.p.a. was fined 10,000 EUR by the Garante for failing to implement minimum security measures in the processing of telematic traffic data. The authority found a breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Jul 2021 | FUTURE VINLINE SLFUTURE VINLINE SL was fined by the AEPD EUR 10,000 for not having an adequate privacy policy on its website. The authority found that the company failed to provide clear and complete information about data processing under Article 13 GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 31 Aug 2023 | RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined by the Garante EUR 10,000 for publishing an article on the Corriere della Sera website. The article included a photograph of a holographic will that disclosed a witness’s personal data without consent. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 May 2022 | Geanonimiseerd (APD 84/2022)The case concerns a complaint by the Ordre des Barreaux Francophones de Belgique against sos-services.be and sos-avocats.be. The authority found that lawyers were listed without a legal basis and with incorrect information, in breach of GDPR and ePrivacy rules. | BE | APD | ePrivacy | €10,000 | ↗ |
| 11 Mar 2025 | LÁSER METALPRINT 3D, S.L.LÁSER METALPRINT 3D, S.L. was fined by the AEPD 10,000 EUR for deploying a video surveillance system without proper data processing agreements. The authority found a breach of GDPR Article 28. | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Oct 2025 | Provvedimento del 23 ottobre 2025 [10210718]The Garante imposed a EUR 10,000 fine on an individual tobacco shop owner for suspicious financial transactions involving the misuse of a third party’s identification data with a prepaid card. The case concerns unauthorized use of personal data in the context of payment operations. | IT | Garante | GDPR | €10,000 | ↗ |