BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Oct 2023 | A.C. Group S.r.l.s.A.C. Group S.r.l.s. was fined by the Garante 10,000 EUR for making an unsolicited marketing call to a number listed in the Public Register of Objections without prior informed consent. The authority also found that the company failed to adequately respond to a data subject rights request. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2024 | LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD €10,000 for installing non-essential cookies on its website without obtaining valid user consent. The authority found this to be a breach of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 05 Oct 2017 | Qiu JunjieQiu Junjie was fined EUR 10,000 by the Garante for failing to protect video surveillance recordings with a password. The authority found this breached the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Apr 2024 | GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined €10,000 by the AEPD for sending unsolicited advertising SMS messages without providing an opt-out link. The conduct breached the LSSI rules governing electronic marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 24 Oct 2019 | Anonymizováno (ÚOOÚ UOOU-01096/19-19)The entity was fined by the UOOU for sending commercial communications without a valid legal basis. The messages were not properly identified as commercial and the sender was not correctly identified. | CZ | UOOU | ePrivacy | €391 | ↗ |
| 30 Apr 2025 | BITDEFENDER SRLIn April 2025, the Romanian authority ANSPDCP completed an investigation into BITDEFENDER SRL and found a GDPR violation. The company was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 08 Mar 2012 | Comune di Marano PrincipatoThe Municipality of Marano Principato was fined by the Garante for processing personal data without appointing data processors and for failing to adopt minimum security measures. The authority found a breach of Article 33 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Ordinanza ingiunzione - 22 maggio 2018 [9027240]A general practitioner was fined for failing to adopt minimum security measures in a health information system. The deficiencies allowed unauthorized access to the data. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Jan 2020 | CASA GRACIO OPERATION, SLUCASA GRACIO OPERATION, SLU was fined by the AEPD 10,000 EUR for installing a video surveillance system that could capture public areas and access points. The authority found that this processing breached data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 28 Apr 2022 | Ministero della DifesaMinistero della Difesa was fined EUR 10,000 by the Garante for improperly disclosing personal data, including health-related information, to unauthorized personnel. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Jan 2020 | Comune di Francavilla FontanaThe Municipality of Francavilla Fontana was fined 10,000 EUR by the Garante for publishing personal data on its institutional website. The conduct breached data protection rules and triggered supervisory action. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Apr 2026 | Dane anonimowe (Pana L. A. prowadzącego działalność gospodarczą pod nazwą: A.)UODO issued a reprimand to the controller, two agents and a sub-agent, and imposed an administrative fine on the sub-agent. The case concerned GDPR breaches related to processing security, verification of processors, and the principles of confidentiality and accountability. | PL | UODO | GDPR | €2,385 | ↗ |
| 22 Apr 2010 | Cassine di Pietra s.r.l.Cassine di Pietra s.r.l. was fined by the Garante €10,400 for making unsolicited promotional calls using automated systems. The authority found that proper information was not provided and consent had not been obtained, constituting a data protection breach. | IT | Garante | GDPR | €10,400 | ↗ |
| 05 Apr 2012 | XY s.r.l.XY s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial communications by email despite the recipient's repeated objections. The case indicates a breach of data protection rules governing electronic marketing and respect for opt-out requests. | IT | Garante | GDPR | €10,400 | ↗ |
| 15 Nov 2012 | Italiasalute s.r.l.Italiasalute s.r.l. was fined by the Garante EUR 10,400 for processing personal data on its website without providing data subjects with adequate information. The authority also found that consent was obtained in a non-compliant manner, particularly for profiling and marketing purposes. | IT | Garante | GDPR | €10,400 | ↗ |
| 04 Oct 2011 | Mancosu Editore s.r.l.Mancosu Editore s.r.l. was fined by the Garante 10,400 EUR for sending promotional emails without providing the required information to data subjects and without obtaining explicit consent. The conduct breached Articles 13 and 130 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,400 | ↗ |
| 29 Nov 2012 | Eco Education s.r.l.Eco Education s.r.l. was fined by the Garante 10,400 EUR for sending promotional faxes without prior, specific, and informed consent from recipients. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,400 | ↗ |
| 15 Sept 2011 | XY s.r.l.XY s.r.l. was fined by the Garante in the amount of EUR 10,400 for sending an unsolicited promotional fax. The conduct breached data protection and marketing communication rules. | IT | Garante | GDPR | €10,400 | ↗ |
| 09 Nov 2017 | Consorzio di Polizia locale Valle AgnoConsorzio di Polizia locale Valle Agno was fined EUR 10,400 by the Garante for deploying a mobile video surveillance system and a localization system on employee devices without the required information or prior notification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,400 | ↗ |
| 11 Oct 2012 | Professional Pneus sccrlProfessional Pneus sccrl was fined EUR 10,400 by the Garante. The authority found that personal data were processed without giving users the option to refuse consent for marketing purposes, breaching transparency requirements. | IT | Garante | GDPR | €10,400 | ↗ |