BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 18 Oct 2022 | a natural personA natural person was fined EUR 150 by ANSPDCP for violating the General Data Protection Regulation. The case concerned a breach of GDPR requirements. | RO | ANSPDCP | GDPR | €150 | ↗ |
| 18 Oct 2022 | SC Materiale Constructii Online SRLSC Materiale Constructii Online SRL was fined by ANSPDCP in the amount of EUR 2,000 for violating the General Data Protection Regulation (GDPR). The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 20 Oct 2022 | I.S.P.R.O.The Italian Data Protection Authority fined I.S.P.R.O. EUR 7,000 for violations related to the processing of health data. The case concerned improper handling of sensitive data, creating a material compliance risk. | IT | Garante | GDPR | €7,000 | ↗ |
| 20 Oct 2022 | Limit Call S.r.l.s.Limit Call S.r.l.s. was fined by the Garante in the amount of 10,000 EUR for making numerous unsolicited phone calls. The authority found that this conduct breached Article 5 of the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Oct 2022 | Promofarma Sviluppo s.r.l.Promofarma Sviluppo s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate data security measures and for lacking transparency in the authentication process on vaccine booking portals. These shortcomings made the system vulnerable to fraudulent access and misuse. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Oct 2022 | Azienda Ospedaliero-Universitaria Careggi di FirenzeAzienda Ospedaliero-Universitaria Careggi di Firenze was fined by the Garante 9,000 EUR for violations involving the processing of sensitive health data. The authority cited inadequate safeguards in the handling of histological examinations. | IT | Garante | GDPR | €9,000 | ↗ |
| 20 Oct 2022 | Fondazione Teatro Regio di TorinoFondazione Teatro Regio di Torino was fined EUR 5,000 by the Garante for publishing an individual's personal data on its website. The authority found a breach of the GDPR principles of lawful, fair, and transparent processing. | IT | Garante | GDPR | €5,000 | ↗ |
| 20 Oct 2022 | Comune di SalentoComune di Salento was fined for unlawful processing of personal data through video surveillance systems. The authority found that retention periods for surveillance images were not set and that free access to personal data was not ensured, breaching GDPR transparency and access rights. | IT | Garante | GDPR | €12,000 | ↗ |
| 20 Oct 2022 | Occhiali24.it S.r.l.Occhiali24.it S.r.l. was fined by the Garante 20,000 EUR for sending unsolicited marketing communications without prior consent. The authority also found that the company failed to respond to data subject rights requests, indicating non-compliance with data protection obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Oct 2022 | Comune di Calvi RisortaThe Municipality of Comune di Calvi Risorta was fined 2,000 EUR by the Garante. The sanction resulted from a delayed response to the supervisory authority's request for information, which breached data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 20 Oct 2022 | Istituto di Istruzione Superiore “G. Renda” di Polistena, Reggio CalabriaIstituto di Istruzione Superiore “G. Renda” was fined EUR 900 by the Garante for unlawfully processing personal data. The school published sensitive information about an employee’s contract termination without a legal basis, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €900 | ↗ |
| 20 Oct 2022 | Associazione Covid-Healer ODVThe Garante fined Associazione Covid-Healer ODV 500 EUR for breaches linked to the processing of health data through its app, which was active for a short period. The authority cited inadequate transparency and deficiencies in the data protection impact assessment. | IT | Garante | GDPR | €500 | ↗ |
| 20 Oct 2022 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined by the Garante €40,000 for failing to provide a data subject with access to personal data relating to derivative transactions. The authority found a breach of the principles of lawful, fair, and transparent processing. | IT | Garante | GDPR | €40,000 | ↗ |
| 20 Oct 2022 | Douglas Italia S.p.A.Douglas Italia S.p.A. was fined by the Italian Garante in the amount of €1,400,000. The authority found inadequate responses to data subject requests and a lack of clear separation between the privacy policy and cookie policy in the app. The conduct breached multiple GDPR provisions. | IT | Garante | GDPR | €1,400,000 | ↗ |
| 20 Oct 2022 | Policlinico Casilino di RomaPoliclinico Casilino di Roma was fined by the Garante for violations related to the handling of personal data in the healthcare sector. The case concerned improper processing of patient data and privacy compliance requirements. | IT | Garante | GDPR | €15,000 | ↗ |
| 21 Oct 2022 | IPM Group NVThe case concerned the use of cookies on the L'Avenir website operated by IPM Group NV. A settlement was reached under which the company agreed to pay 10,000 EUR to the Belgian treasury. | BE | APD | ePrivacy | €10,000 | ↗ |
| 21 Oct 2022 | CASAL DE L'ESPLUGA DE FRANCOLÍCASAL DE L'ESPLUGA DE FRANCOLÍ was fined by the AEPD for publishing a video on social media without consent. The recording showed a minor during a sports event, which constituted a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 26 Oct 2022 | FUNDACIÓN CITIZENGOFUNDACIÓN CITIZENGO was fined by the AEPD EUR 5,000 for sending unsolicited emails without recipients’ consent. The authority found a breach of Article 7 GDPR on valid consent. | ES | AEPD | GDPR | €5,000 | ↗ |
| 27 Oct 2022 | COPY COFFEE, S.L.COPY COFFEE, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails despite the recipient's prior objection. The authority found a breach of Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 28 Oct 2022 | FORMAESTUDIO, C.B.FORMAESTUDIO, C.B. was fined €6,000 by the AEPD for requiring students to disclose their COVID vaccination status and present a passport as a condition for participating in teaching practice. The authority found that this processing breached data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |