Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Jun 2017Vodafone-PanafonVodafone-Panafon was fined EUR 10,000 by the HDPA for a significant delay in responding to a data subject access request. The authority found a breach of Article 12 of Law L.2472/1997.GRHDPAGDPR€10,000
05 Feb 2015Comune di San Giuseppe JatoComune di San Giuseppe Jato was fined by the Garante for unlawfully publishing sensitive personal data revealing health status on its website. The conduct breached privacy rules governing the processing and disclosure of sensitive data.ITGaranteGDPR€10,000
12 Sept 2013Azienda USL ViterboAzienda USL Viterbo was fined for failing to implement minimum security measures and for not appointing data processing officers. The authority also noted that the security program document was not updated between 2006 and 2010.ITGaranteGDPR€10,000
05 Jul 2024PUBLICACIONES Y EDICIONES BARACA 208, S.L.The company published personal data, including health information, in a digital newspaper article. The authority found a breach of data minimisation and the rules on special category data under GDPR Articles 5(1)(c) and 9.ESAEPDGDPR€10,000
06 Jan 2022B.B.B.A fine was imposed for the mass dissemination of a video recorded without the victim’s consent on social media and via WhatsApp. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€10,000
22 May 2013Margiotta Pietro Antonio e ASL TA 1 – Azienda Sanitaria Locale di TarantoThe Garante fined Margiotta Pietro Antonio and ASL TA 1 10,000 EUR for failing to implement minimum security measures. In some departments, unauthorized personnel accessed patient data and shared authentication credentials were used.ITGaranteGDPR€10,000
04 Dec 2025SOCIETE EXERCANT UNE ACTIVITE D'HOTELLERIE ET D'HEBERGEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE D'HOTELLERIE ET D'HEBERGEMENT. The case was handled under a simplified procedure.FRCNILGDPR€10,000
18 Jan 2022MAJESTIC SOLUTIONS S.L.MAJESTIC SOLUTIONS S.L. was fined by the AEPD 10,000 EUR for failing to provide all required information to affected individuals after a personal data security breach. The authority found a breach of Article 34(2) GDPR.ESAEPDGDPR€10,000
01 Jun 2025Călin GeorgescuCălin Georgescu was sanctioned by Romania’s data protection authority after an investigation into his website. Two fines totaling about EUR 10,000 were imposed for installing cookies without consent and collecting personal data without proper notice.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€10,000
01 Jan 2015FEVER LABS INCFEVER LABS INC was fined EUR 10,000 by the AEPD for sending unsolicited commercial emails. The authority found that the messages did not include a simple and free way for recipients to opt out of further communications, in breach of the LSSI.ESAEPDePrivacy€10,000
20 Jun 2024TS Food Processing S.r.l.TS Food Processing S.r.l. was fined by the Garante for refusing an employee's request to access personal data related to employment. The authority found a breach of GDPR Article 15.ITGaranteGDPR€10,000
13 Mar 2025Casatua S.r.l.Casatua S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited communications via WhatsApp without obtaining proper recipient consent. The company also failed to implement adequate procedures to ensure compliance with data protection rules.ITGaranteGDPR€10,000
27 Jun 2013Comune di PadovaComune di Padova was fined by the Garante 10,000 EUR for unlawfully publishing personal data online beyond the legally permitted period. The authority found this to be a breach of data protection rules.ITGaranteGDPR€10,000
11 Apr 2024GS S.p.A.GS S.p.A. was fined by the Garante for failing to respond to an employee's access request. The request concerned disciplinary records and work time stamps, which constitutes a breach of GDPR Article 15.ITGaranteGDPR€10,000
27 Dec 2012Euro-Catering O.E.The company was fined for failing to comply with a prior decision by the authority. It was noted that it no longer operated the stores concerned and that its financial situation was difficult.GRHDPAGDPR€10,000
21 Jul 2016Comune di CanicattìComune di Canicattì was fined for publishing personal data, including health information, on its website. The authority found that this breached data protection rules.ITGaranteGDPR€10,000
13 Sept 2007Azienda sanitaria locale Avellino 1Azienda sanitaria locale Avellino 1 was fined by the Garante in the amount of 10,000 EUR. The authority found that the entity failed to notify the processing of sensitive personal data, including genetic and biometric data, as required by the Italian Data Protection Code.ITGaranteGDPR€10,000
06 Feb 2020Azienda Unità Sanitaria Locale Toscana CentroAzienda Unità Sanitaria Locale Toscana Centro was fined by the Garante 10,000 EUR for violations related to data processing in the health sector. The case concerned the handling of patient data without full compliance with GDPR requirements.ITGaranteGDPR€10,000
15 Jun 2017F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante in the amount of 10,000 EUR for making unsolicited promotional calls to a number listed in the public opposition registry. The conduct breached data protection rules and the right to object to direct marketing.ITGaranteGDPR€10,000
14 Sept 2006Azienda sanitaria locale n. 6 di CirièASL Ciriè was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The breach concerned obligations under the Italian Privacy Code.ITGaranteGDPR€10,000