BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Nov 2025 | Maviglia Assicurazioni snc di Gherardo Maviglia & c.Maviglia Assicurazioni was fined by the Garante 10,000 EUR for unlawful processing of personal data. The case involved automatic email redirection and indefinite retention of email logs and content, which breached GDPR principles. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Jun 2024 | RETSINNAL GROUP, S.L.U.RETSINNAL GROUP, S.L.U. was fined by the AEPD in the amount of 10,000 EUR for failing to comply with cookie management rules on its website. The breach concerned Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 27 Apr 2010 | Consiglio dell'ordine degli avvocati di Santa Maria Capua VetereConsiglio dell'ordine degli avvocati di Santa Maria Capua Vetere was fined by the Garante for using a biometric system to verify trainee lawyers' attendance without proper authorization. This constituted a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl di Maglie (Lecce)Asl di Maglie (Lecce) was fined by the Garante for failing to notify personal data processing activities within the required timeframe. This constituted a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 03 Jul 2014 | Tenacta Group s.p.a.Tenacta Group s.p.a. was fined 10,000 EUR by the Garante for making unsolicited promotional phone calls. The company failed to consult the public opposition register, thereby violating the subscriber's right to object. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Oct 2013 | Comune di BolzanoComune di Bolzano was fined 10,000 EUR by the Garante for publishing sensitive health-related information about an employee’s absence on its institutional website. The authority found a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Nov 2016 | Provincia di VercelliProvincia di Vercelli was fined EUR 10,000 by the Garante for unlawfully publishing personal data on its institutional website. The disclosed information included photocopies of identity cards and bank account numbers, without an appropriate legal basis. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Dec 2022 | UNIVERSITE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on UNIVERSITE (procédure simplifiée). The record indicates a regulatory breach, but no further details are provided. | FR | CNIL | GDPR | €10,000 | ↗ |
| 08 Feb 2007 | Asl OristanoAsl Oristano was fined EUR 10,000 by the Garante for failing to notify the processing of personal data concerning health and sexual life. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Feb 2015 | Comune di MontagnarealeThe Garante fined Comune di Montagnareale 10,000 EUR for unlawfully publishing personal data revealing health status on its institutional website. The breach involved disclosure of sensitive data without an adequate legal basis or safeguards. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Jun 2023 | B.B.B.B.B.B. was fined by the AEPD 10,000 EUR for uploading sexual and personal content of an ex-partner to YouTube and ForoCoches without consent. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 07 Dec 2023 | H**** Gemeinnützige Wohnungs AGThe entity was fined for failing to cooperate with the Data Protection Authority during a complaint procedure. It did not respond to requests for statements, which constitutes a breach of Article 31 GDPR. | AT | DSB | GDPR | €10,000 | ↗ |
| 22 Feb 2022 | RAMONA FILMS, S.L.RAMONA FILMS, S.L. was fined 10,000 EUR by the AEPD. The authority found processing of personal data of minors under 14 without proper consent and non-compliance with website cookie policy requirements. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 11 Sept 2025 | COMMUNE (procédure simplifiée)CNIL imposed an administrative fine of EUR 10,000 on COMMUNE under a simplified procedure and issued a warning. The case concerns a breach of rules requiring supervisory intervention. | FR | CNIL | GDPR | €10,000 | ↗ |
| 29 May 2026 | Unicredit Bank SAUnicredit Bank SA was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements and should be considered in compliance risk assessments. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 14 Mar 2019 | Comune di Porto Sant’ElpidioThe Garante fined Comune di Porto Sant’Elpidio EUR 10,000 for publishing documents on its website that contained personal data revealing the health status of individuals with disabilities. The authority found a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 May 2023 | Libra Internet Bank SALibra Internet Bank SA was fined EUR 10,000 by ANSPDCP for another breach of GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 31 May 2017 | Unit Contact s.r.l.Unit Contact s.r.l. was fined by the Garante EUR 10,000 for making unsolicited promotional calls to a number listed in the public opt-out register. The conduct breached data protection rules and telephone marketing requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Sept 2025 | SOCIETE EXERCANT UNE ACTIVITE DE BANQUE ET ASSURANCE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE DE BANQUE ET ASSURANCE. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 27 Dec 2023 | COMITE SOCIAL ECONOMIQUE D'ENTREPRISES (procédure simplifiée)The CNIL imposed an administrative fine of 10,000 EUR on COMITE SOCIAL ECONOMIQUE D'ENTREPRISES under a simplified procedure. The case concerns a confirmed regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €10,000 | ↗ |