Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Apr 2021CREATOR ENERGY, S.L.CREATOR ENERGY, S.L. was fined by the AEPD 6,000 EUR for using personal data without consent to contract gas, electricity, and maintenance services. The authority found this conduct breached Article 6(1)(b) GDPR.ESAEPDGDPR€6,000
05 Sept 2013Maria Vita PezzellaMaria Vita Pezzella was fined EUR 6,000 by Garante for failing to provide the required privacy notice in a video surveillance system. The case concerned a breach of the Italian Privacy Code and the duty to inform individuals subject to monitoring.ITGaranteGDPR€6,000
01 Jan 2016VODAFONE ONO, S.A.U.Vodafone Ono, S.A.U. was fined by the AEPD 6,000 EUR for sending unsolicited advertising SMS messages to a complainant. The complainant's data had previously been canceled, indicating a breach of data handling and marketing communication rules.ESAEPDePrivacy€6,000
10 Jan 2026MULTISPORTS GALICIA, S.L.MULTISPORTS GALICIA, S.L. was fined by the AEPD EUR 6,000 for failing to implement appropriate technical and organizational measures proportionate to the risk. The weakness allowed easy access to personal data of race participants through its website.ESAEPDGDPR€6,000
30 Jan 2025Azienda Ospedaliero - Universitaria Città della Salute e della Scienza di TorinoThe Garante fined Azienda Ospedaliero - Universitaria Città della Salute e della Scienza di Torino 6,000 EUR for unlawful processing of personal data, including health data. The authority found that the processing lacked an appropriate legal basis. The case concerned sensitive data handling in the healthcare sector.ITGaranteGDPR€6,000
16 Jan 2026Azienda Ospedaliera S. Pio di BeneventoAzienda Ospedaliera S. Pio di Benevento was fined by the Garante EUR 6,000 for violations related to the processing of personal data. The case concerned special categories of data and disclosure to third parties.ITGaranteGDPR€6,000
26 Oct 2023Azienda Sanitaria Locale TO3Azienda Sanitaria Locale TO3 was fined by the Garante for a health data breach affecting four individuals. The incident lasted nine days and was deemed negligent.ITGaranteGDPR€6,000
12 Dec 2024Comune di PorticiThe Garante fined Comune di Portici EUR 6,000 for breaches of data protection principles, including lawfulness, fairness, and transparency. The authority also found that the municipality failed to carry out a data protection impact assessment before processing personal data through video surveillance.ITGaranteGDPR€6,000
23 Dec 2010Bitmovers s.r.l.Bitmovers s.r.l. was fined by the Garante 6,000 EUR for collecting personal data through its website without the required information notice. The case concerned a breach of the Italian Data Protection Code.ITGaranteGDPR€6,000
12 May 2022Comune di VillabateComune di Villabate was fined 6,000 EUR for failing to update the Data Protection Officer’s contact details on its website and in communications with the Authority. The conduct was found to breach the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€6,000
09 Oct 2025Ordine Interprovinciale dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche della Riabilitazione e della Prevenzione di AQ - CH - PE - TEThe Garante fined Ordine Interprovinciale dei Tecnici Sanitari 6,000 EUR for keeping an online disciplinary suspension record available despite the suspension being contested. The authority found breaches of lawfulness, fairness, transparency, data minimization, and accuracy.ITGaranteGDPR€6,000
25 Nov 2021Società H San Raffaele Resnati s.r.l.The Garante imposed a fine of EUR 6,000 on Società H San Raffaele Resnati s.r.l. for violations of data protection rules in the health sector. The case involved a data breach incident, which triggered supervisory action.ITGaranteGDPR€6,000
18 Feb 2010Fibrille s.r.l.Fibrille s.r.l. was fined EUR 6,000 by the Garante for processing personal data from job applicants' CVs without providing the required information. The authority found a breach of the notice obligation under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
11 Mar 2010Impresa individuale Bellusci MirellaThe company was fined for processing personal data by receiving CVs from aspiring agents without providing the required privacy notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
26 Jul 2012Meeting s.r.l.Meeting s.r.l. was fined by the Garante in the amount of 6,000 EUR for providing inadequate information to clients. The case concerned a breach of Article 13 of the Italian Data Protection Code, which requires proper notice to data subjects.ITGaranteGDPR€6,000
09 Dec 2010Circolo Privato PirliCircolo Privato Pirli was fined EUR 6,000 by the Garante for failing to provide the required privacy notice to individuals entering the premises. The breach concerned the Italian Data Protection Code and the Garante's video surveillance guidelines.ITGaranteGDPR€6,000
29 Apr 2022ECOZONO Y CULTURA, S.L.ECOZONO Y CULTURA, S.L. collected personal data through surveys without a valid legal basis. The data were intended for later marketing contact with the individuals concerned. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€6,000
01 Jan 2020DESOLASOL RESTAURACIÓN, S.L.The restaurant disclosed a customer's complaint form to other patrons, breaching data protection principles. The case involved unauthorized disclosure of personal information contained in the complaint document.ESAEPDGDPR€6,000
11 Sept 2025Comune di BuccinoComune di Buccino was fined by the Garante EUR 6,000 for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. The case involved improper handling of personal data.ITGaranteGDPR€6,000
07 Apr 2011Enterprise Service s.r.l.Enterprise Service s.r.l. was fined EUR 6,000 by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The authority also found that the required privacy notice was not provided, constituting a breach of privacy rules.ITGaranteGDPR€6,000