BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Jun 2018 | Luigi Di CesareLuigi Di Cesare was fined EUR 10,000 by the Garante for failing to implement minimum security measures. The breach led to the unauthorized disclosure of medical reports to a third party. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Mar 2017 | Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined EUR 10,000 by the HDPA. The authority found that the bank did not adequately satisfy the complainant’s right of access to recorded telephone conversations. The case concerned the legal obligation to provide access to such recordings. | GR | HDPA | GDPR | €10,000 | ↗ |
| 13 Sept 2007 | Azienda sanitaria locale di Lanciano/VastoAzienda sanitaria locale di Lanciano/Vasto was fined by the Garante 10,000 EUR for improper handling of sensitive personal data. The case involved genetic and biometric data processed without proper authorization. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Dec 2024 | SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT under a simplified procedure. The decision dates from 12 December 2024. | FR | CNIL | GDPR | €10,000 | ↗ |
| 19 Dec 2023 | Sąd Okręgowy w Krakowie za naruszenie art. 33 ust. 1 i ust. 2 oraz art. 34 ust. 1 i ust. 2 rozporządzenia 2016/679UODO imposed an administrative fine of 10,000 PLN on the Regional Court in Kraków. The case concerns breaches of obligations related to personal data breach notification and informing affected individuals. | PL | UODO | GDPR | €2,306 | ↗ |
| 07 Mar 2019 | Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined for unlawfully processing judicial data by communicating information about an ongoing criminal proceeding without a legal basis. The case concerned a breach of the rules governing the lawful processing of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2023 | LOCAL VERTICALS, S.L.The company was fined by the AEPD in the amount of 10,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 05 Feb 2015 | Azienda Regionale per il diritto allo studio universitario della ToscanaAzienda Regionale per il diritto allo studio universitario della Toscana was fined EUR 10,000 by the Garante. The authority found that its website unlawfully disclosed personal data revealing the health status of students with disabilities. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Mar 2018 | Società agricola Medici Claudio s.r.l.The company was fined for failing to comply with data protection obligations. The breach concerned not providing personal data and information related to employment management when requested by the Garante. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 May 2024 | KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD 10,000 EUR for requiring a customer to provide a photo with their ID to cancel a loan. The authority found that this processing breached GDPR principles of data minimisation and proportionality. | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Jun 2025 | Società Autocooperative Trasporti Italiani S.p.A.The company was fined by the Garante for unlawfully disclosing sensitive personal data about employee absences, including the reasons for absence. The information was posted on company notice boards and sent by email to employees. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Jun 2008 | Contact point s.r.l.Contact point s.r.l. was fined by the Garante 10,000 EUR for breaching data protection rules. The case concerned improper handling of personal data during opinion surveys. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2014 | Roma CapitaleRoma Capitale was fined for unlawfully publishing personal data related to a disciplinary action on its institutional website. The authority found that this conduct violated Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Jun 2023 | Dante International SADante International SA was fined EUR 10,000 by ANSPDCP for additional violations related to complaints from three individuals in Hungary. The case concerned irregularities identified during the handling of those complaints. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 11 Jan 2023 | Società Europea di Edizioni S.p.a.The Garante fined Società Europea di Edizioni S.p.a. EUR 10,000 for publishing non-anonymized personal data concerning an individual's health status in an article. This constituted a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Feb 2015 | Comune di MerìComune di Merì was fined EUR 10,000 by the Garante for unlawfully publishing sensitive personal data on its website. The disclosure included information about individuals' health status and mandatory medical treatments, breaching data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Sept 2007 | Asl Enna 4The Garante fined Asl Enna 4 EUR 10,000 for processing personal data, including genetic and biometric data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Jan 2026 | Πυροσβεστικό ΣώμαThe Hellenic Data Protection Authority imposed a €10,000 fine on the Fire Service for unlawfully processing an employee’s special-category health data. The authority found breaches of GDPR lawfulness and data minimization principles and noted that the data were accessible through an internal electronic application. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €10,000 | ↗ |
| 19 Feb 2015 | Andrea AngeloniAndrea Angeloni was fined by the Garante for sending unsolicited promotional letters. The entity also failed to respond to information requests from the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Sept 2019 | IBERDROLA CLIENTES, SAUIBERDROLA CLIENTES, SAU was fined by the AEPD 10,000 EUR for including personal data in the SOLCENT file without the required authorization. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |