Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
18 Oct 2022a natural personA natural person was fined EUR 150 by ANSPDCP for violating the General Data Protection Regulation. The case concerned a breach of GDPR requirements.ROANSPDCPGDPR€150
18 Oct 2022SC Materiale Constructii Online SRLSC Materiale Constructii Online SRL was fined by ANSPDCP in the amount of EUR 2,000 for violating the General Data Protection Regulation (GDPR). The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
20 Oct 2022I.S.P.R.O.The Italian Data Protection Authority fined I.S.P.R.O. EUR 7,000 for violations related to the processing of health data. The case concerned improper handling of sensitive data, creating a material compliance risk.ITGaranteGDPR€7,000
20 Oct 2022Limit Call S.r.l.s.Limit Call S.r.l.s. was fined by the Garante in the amount of 10,000 EUR for making numerous unsolicited phone calls. The authority found that this conduct breached Article 5 of the GDPR.ITGaranteGDPR€10,000
20 Oct 2022Promofarma Sviluppo s.r.l.Promofarma Sviluppo s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate data security measures and for lacking transparency in the authentication process on vaccine booking portals. These shortcomings made the system vulnerable to fraudulent access and misuse.ITGaranteGDPR€10,000
20 Oct 2022Azienda Ospedaliero-Universitaria Careggi di FirenzeAzienda Ospedaliero-Universitaria Careggi di Firenze was fined by the Garante 9,000 EUR for violations involving the processing of sensitive health data. The authority cited inadequate safeguards in the handling of histological examinations.ITGaranteGDPR€9,000
20 Oct 2022Fondazione Teatro Regio di TorinoFondazione Teatro Regio di Torino was fined EUR 5,000 by the Garante for publishing an individual's personal data on its website. The authority found a breach of the GDPR principles of lawful, fair, and transparent processing.ITGaranteGDPR€5,000
20 Oct 2022Comune di SalentoComune di Salento was fined for unlawful processing of personal data through video surveillance systems. The authority found that retention periods for surveillance images were not set and that free access to personal data was not ensured, breaching GDPR transparency and access rights.ITGaranteGDPR€12,000
20 Oct 2022Occhiali24.it S.r.l.Occhiali24.it S.r.l. was fined by the Garante 20,000 EUR for sending unsolicited marketing communications without prior consent. The authority also found that the company failed to respond to data subject rights requests, indicating non-compliance with data protection obligations.ITGaranteGDPR€20,000
20 Oct 2022Comune di Calvi RisortaThe Municipality of Comune di Calvi Risorta was fined 2,000 EUR by the Garante. The sanction resulted from a delayed response to the supervisory authority's request for information, which breached data protection rules.ITGaranteGDPR€2,000
20 Oct 2022Istituto di Istruzione Superiore “G. Renda” di Polistena, Reggio CalabriaIstituto di Istruzione Superiore “G. Renda” was fined EUR 900 by the Garante for unlawfully processing personal data. The school published sensitive information about an employee’s contract termination without a legal basis, breaching GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€900
20 Oct 2022Associazione Covid-Healer ODVThe Garante fined Associazione Covid-Healer ODV 500 EUR for breaches linked to the processing of health data through its app, which was active for a short period. The authority cited inadequate transparency and deficiencies in the data protection impact assessment.ITGaranteGDPR€500
20 Oct 2022Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined by the Garante €40,000 for failing to provide a data subject with access to personal data relating to derivative transactions. The authority found a breach of the principles of lawful, fair, and transparent processing.ITGaranteGDPR€40,000
20 Oct 2022Douglas Italia S.p.A.Douglas Italia S.p.A. was fined by the Italian Garante in the amount of €1,400,000. The authority found inadequate responses to data subject requests and a lack of clear separation between the privacy policy and cookie policy in the app. The conduct breached multiple GDPR provisions.ITGaranteGDPR€1,400,000
20 Oct 2022Policlinico Casilino di RomaPoliclinico Casilino di Roma was fined by the Garante for violations related to the handling of personal data in the healthcare sector. The case concerned improper processing of patient data and privacy compliance requirements.ITGaranteGDPR€15,000
21 Oct 2022IPM Group NVThe case concerned the use of cookies on the L'Avenir website operated by IPM Group NV. A settlement was reached under which the company agreed to pay 10,000 EUR to the Belgian treasury.BEAPDePrivacy€10,000
21 Oct 2022CASAL DE L'ESPLUGA DE FRANCOLÍCASAL DE L'ESPLUGA DE FRANCOLÍ was fined by the AEPD for publishing a video on social media without consent. The recording showed a minor during a sports event, which constituted a breach of data protection rules.ESAEPDGDPR€5,000
26 Oct 2022FUNDACIÓN CITIZENGOFUNDACIÓN CITIZENGO was fined by the AEPD EUR 5,000 for sending unsolicited emails without recipients’ consent. The authority found a breach of Article 7 GDPR on valid consent.ESAEPDGDPR€5,000
27 Oct 2022COPY COFFEE, S.L.COPY COFFEE, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails despite the recipient's prior objection. The authority found a breach of Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€5,000
28 Oct 2022FORMAESTUDIO, C.B.FORMAESTUDIO, C.B. was fined €6,000 by the AEPD for requiring students to disclose their COVID vaccination status and present a passport as a condition for participating in teaching practice. The authority found that this processing breached data protection rules.ESAEPDGDPR€6,000