Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Jun 2018Luigi Di CesareLuigi Di Cesare was fined EUR 10,000 by the Garante for failing to implement minimum security measures. The breach led to the unauthorized disclosure of medical reports to a third party.ITGaranteGDPR€10,000
20 Mar 2017Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined EUR 10,000 by the HDPA. The authority found that the bank did not adequately satisfy the complainant’s right of access to recorded telephone conversations. The case concerned the legal obligation to provide access to such recordings.GRHDPAGDPR€10,000
13 Sept 2007Azienda sanitaria locale di Lanciano/VastoAzienda sanitaria locale di Lanciano/Vasto was fined by the Garante 10,000 EUR for improper handling of sensitive personal data. The case involved genetic and biometric data processed without proper authorization.ITGaranteGDPR€10,000
12 Dec 2024SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT under a simplified procedure. The decision dates from 12 December 2024.FRCNILGDPR€10,000
19 Dec 2023Sąd Okręgowy w Krakowie za naruszenie art. 33 ust. 1 i ust. 2 oraz art. 34 ust. 1 i ust. 2 rozporządzenia 2016/679UODO imposed an administrative fine of 10,000 PLN on the Regional Court in Kraków. The case concerns breaches of obligations related to personal data breach notification and informing affected individuals.PLUODOGDPR€2,306
07 Mar 2019Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined for unlawfully processing judicial data by communicating information about an ongoing criminal proceeding without a legal basis. The case concerned a breach of the rules governing the lawful processing of sensitive data.ITGaranteGDPR€10,000
01 Jan 2023LOCAL VERTICALS, S.L.The company was fined by the AEPD in the amount of 10,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 of the GDPR.ESAEPDGDPR€10,000
05 Feb 2015Azienda Regionale per il diritto allo studio universitario della ToscanaAzienda Regionale per il diritto allo studio universitario della Toscana was fined EUR 10,000 by the Garante. The authority found that its website unlawfully disclosed personal data revealing the health status of students with disabilities.ITGaranteGDPR€10,000
21 Mar 2018Società agricola Medici Claudio s.r.l.The company was fined for failing to comply with data protection obligations. The breach concerned not providing personal data and information related to employment management when requested by the Garante.ITGaranteGDPR€10,000
27 May 2024KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD 10,000 EUR for requiring a customer to provide a photo with their ID to cancel a loan. The authority found that this processing breached GDPR principles of data minimisation and proportionality.ESAEPDGDPR€10,000
23 Jun 2025Società Autocooperative Trasporti Italiani S.p.A.The company was fined by the Garante for unlawfully disclosing sensitive personal data about employee absences, including the reasons for absence. The information was posted on company notice boards and sent by email to employees.ITGaranteGDPR€10,000
26 Jun 2008Contact point s.r.l.Contact point s.r.l. was fined by the Garante 10,000 EUR for breaching data protection rules. The case concerned improper handling of personal data during opinion surveys.ITGaranteGDPR€10,000
13 Feb 2014Roma CapitaleRoma Capitale was fined for unlawfully publishing personal data related to a disciplinary action on its institutional website. The authority found that this conduct violated Article 19 of the Italian Data Protection Code.ITGaranteGDPR€10,000
20 Jun 2023Dante International SADante International SA was fined EUR 10,000 by ANSPDCP for additional violations related to complaints from three individuals in Hungary. The case concerned irregularities identified during the handling of those complaints.ROANSPDCPGDPR€10,000
11 Jan 2023Società Europea di Edizioni S.p.a.The Garante fined Società Europea di Edizioni S.p.a. EUR 10,000 for publishing non-anonymized personal data concerning an individual's health status in an article. This constituted a breach of data protection rules.ITGaranteGDPR€10,000
05 Feb 2015Comune di MerìComune di Merì was fined EUR 10,000 by the Garante for unlawfully publishing sensitive personal data on its website. The disclosure included information about individuals' health status and mandatory medical treatments, breaching data protection rules.ITGaranteGDPR€10,000
13 Sept 2007Asl Enna 4The Garante fined Asl Enna 4 EUR 10,000 for processing personal data, including genetic and biometric data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
16 Jan 2026Πυροσβεστικό ΣώμαThe Hellenic Data Protection Authority imposed a €10,000 fine on the Fire Service for unlawfully processing an employee’s special-category health data. The authority found breaches of GDPR lawfulness and data minimization principles and noted that the data were accessible through an internal electronic application.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€10,000
19 Feb 2015Andrea AngeloniAndrea Angeloni was fined by the Garante for sending unsolicited promotional letters. The entity also failed to respond to information requests from the supervisory authority.ITGaranteGDPR€10,000
20 Sept 2019IBERDROLA CLIENTES, SAUIBERDROLA CLIENTES, SAU was fined by the AEPD 10,000 EUR for including personal data in the SOLCENT file without the required authorization. The authority found this to be a breach of data protection rules.ESAEPDGDPR€10,000