BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Jun 2017 | Vodafone-PanafonVodafone-Panafon was fined EUR 10,000 by the HDPA for a significant delay in responding to a data subject access request. The authority found a breach of Article 12 of Law L.2472/1997. | GR | HDPA | GDPR | €10,000 | ↗ |
| 05 Feb 2015 | Comune di San Giuseppe JatoComune di San Giuseppe Jato was fined by the Garante for unlawfully publishing sensitive personal data revealing health status on its website. The conduct breached privacy rules governing the processing and disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Sept 2013 | Azienda USL ViterboAzienda USL Viterbo was fined for failing to implement minimum security measures and for not appointing data processing officers. The authority also noted that the security program document was not updated between 2006 and 2010. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Jul 2024 | PUBLICACIONES Y EDICIONES BARACA 208, S.L.The company published personal data, including health information, in a digital newspaper article. The authority found a breach of data minimisation and the rules on special category data under GDPR Articles 5(1)(c) and 9. | ES | AEPD | GDPR | €10,000 | ↗ |
| 06 Jan 2022 | B.B.B.A fine was imposed for the mass dissemination of a video recorded without the victim’s consent on social media and via WhatsApp. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 22 May 2013 | Margiotta Pietro Antonio e ASL TA 1 – Azienda Sanitaria Locale di TarantoThe Garante fined Margiotta Pietro Antonio and ASL TA 1 10,000 EUR for failing to implement minimum security measures. In some departments, unauthorized personnel accessed patient data and shared authentication credentials were used. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE D'HOTELLERIE ET D'HEBERGEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE D'HOTELLERIE ET D'HEBERGEMENT. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 18 Jan 2022 | MAJESTIC SOLUTIONS S.L.MAJESTIC SOLUTIONS S.L. was fined by the AEPD 10,000 EUR for failing to provide all required information to affected individuals after a personal data security breach. The authority found a breach of Article 34(2) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jun 2025 | Călin GeorgescuCălin Georgescu was sanctioned by Romania’s data protection authority after an investigation into his website. Two fines totaling about EUR 10,000 were imposed for installing cookies without consent and collecting personal data without proper notice. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €10,000 | ↗ |
| 01 Jan 2015 | FEVER LABS INCFEVER LABS INC was fined EUR 10,000 by the AEPD for sending unsolicited commercial emails. The authority found that the messages did not include a simple and free way for recipients to opt out of further communications, in breach of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 20 Jun 2024 | TS Food Processing S.r.l.TS Food Processing S.r.l. was fined by the Garante for refusing an employee's request to access personal data related to employment. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Mar 2025 | Casatua S.r.l.Casatua S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited communications via WhatsApp without obtaining proper recipient consent. The company also failed to implement adequate procedures to ensure compliance with data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jun 2013 | Comune di PadovaComune di Padova was fined by the Garante 10,000 EUR for unlawfully publishing personal data online beyond the legally permitted period. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Apr 2024 | GS S.p.A.GS S.p.A. was fined by the Garante for failing to respond to an employee's access request. The request concerned disciplinary records and work time stamps, which constitutes a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Dec 2012 | Euro-Catering O.E.The company was fined for failing to comply with a prior decision by the authority. It was noted that it no longer operated the stores concerned and that its financial situation was difficult. | GR | HDPA | GDPR | €10,000 | ↗ |
| 21 Jul 2016 | Comune di CanicattìComune di Canicattì was fined for publishing personal data, including health information, on its website. The authority found that this breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Sept 2007 | Azienda sanitaria locale Avellino 1Azienda sanitaria locale Avellino 1 was fined by the Garante in the amount of 10,000 EUR. The authority found that the entity failed to notify the processing of sensitive personal data, including genetic and biometric data, as required by the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Feb 2020 | Azienda Unità Sanitaria Locale Toscana CentroAzienda Unità Sanitaria Locale Toscana Centro was fined by the Garante 10,000 EUR for violations related to data processing in the health sector. The case concerned the handling of patient data without full compliance with GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Jun 2017 | F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante in the amount of 10,000 EUR for making unsolicited promotional calls to a number listed in the public opposition registry. The conduct breached data protection rules and the right to object to direct marketing. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale n. 6 di CirièASL Ciriè was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The breach concerned obligations under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |