BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Jul 2017 | Equilibra s.r.l.Equilibra s.r.l. was fined by the Garante for failing to provide adequate data protection information to individuals and for not appointing the required data processing officers. The case concerned breaches of the Italian Data Protection Code. | IT | Garante | GDPR | €12,400 | ↗ |
| 24 Jun 2015 | Telefónica Móviles España SAUTelefónica Móviles España SAU was fined by the AEPD 12,500 EUR for sending unauthorized commercial SMS messages. The authority also found that the company failed to provide a simple opt-out mechanism, in breach of LSSI rules. | ES | AEPD | ePrivacy | €12,500 | ↗ |
| 17 Jul 2025 | Poliambulatorio San Liberale S.r.l.The Garante imposed a EUR 12,500 fine on Poliambulatorio San Liberale S.r.l. for failing to meet information and transparency obligations in the processing of personal data, including health data. The company also did not respond to a data access request, adding a further breach of data subject rights. | IT | Garante | GDPR | €12,500 | ↗ |
| 12 Sept 2013 | European Group Sae, Italian Business GuaranteeEuropean Group Sae was fined EUR 12,800 by the Garante. The authority found that the company sent unsolicited promotional faxes without proper information or consent, in breach of privacy rules. | IT | Garante | GDPR | €12,800 | ↗ |
| 04 Jul 2013 | Global ResearchGlobal Research was fined EUR 12,800 by the Garante for sending unsolicited promotional faxes without the required information and consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €12,800 | ↗ |
| 26 Oct 2011 | Smart s.n.c.Smart s.n.c. was fined EUR 12,800 by the Garante. The authority found that the company sent promotional emails without the recipients’ prior explicit consent. | IT | Garante | GDPR | €12,800 | ↗ |
| 09 Dec 2020 | Dane anonimowe (Z. Sp. z o.o. z siedzibą w U. przy ul.)The President of the Personal Data Protection Office (UODO) imposed a fine of PLN 12,838.2 on Z. Sp. z o.o. The sanction was issued for failing to cooperate with the authority and for not providing access to personal data and other information necessary for the performance of its duties. | PL | UODO | GDPR | €2,902 | ↗ |
| 22 Dec 2025 | Dane anonimowe (Pana K. S. prowadzącego działalność gospodarczą pod firmą B.)The President of UODO imposed an administrative fine of PLN 12,964 on Mr. K. S., operating a business under the name B. The sanction was issued for failing to provide access to all personal data and information necessary for the authority to perform its duties. | PL | UODO | GDPR | €3,077 | ↗ |
| 25 Mar 2021 | Unione dei Comuni Valli del Reno, Lavino e SamoggiaUnione dei Comuni Valli del Reno, Lavino e Samoggia was fined by the Garante EUR 13,000 for improperly publishing personal data on the web. The authority found a breach of GDPR principles on lawfulness and data processing. | IT | Garante | GDPR | €13,000 | ↗ |
| 01 Sept 2020 | Iweb Internet Learning, S.L.Iweb Internet Learning, S.L. was fined by the AEPD EUR 13,000 for failing to inform data subjects about the processing of their personal data. The authority also found the use of storage and retrieval devices without the required notice or consent. | ES | AEPD | ePrivacy | €13,000 | ↗ |
| 20 Dec 2022 | Autoritatea Națională pentru Restituirea Proprietăților (ANRP)The National Authority for Property Restitution (ANRP) was fined 13,000 RON by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,646 | ↗ |
| 13 Apr 2023 | Azienda Ospedaliero Universitaria SeneseThe Garante fined Azienda Ospedaliero Universitaria Senese EUR 13,000 for violations related to the processing of personal data in the health sector. The case concerned data minimization and security measures. | IT | Garante | GDPR | €13,000 | ↗ |
| 01 Aug 2012 | S.I.G.A.T. s.r.l.S.I.G.A.T. s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 13,400. The case concerned the sending of unsolicited promotional faxes without prior consent from recipients. | IT | Garante | GDPR | €13,400 | ↗ |
| 30 Jun 2021 | Dane anonimowe (Fundację)UODO imposed a PLN 13,644 administrative fine on the Foundation for failing to report a personal data breach without undue delay. The Foundation also did not notify the affected individuals about the incident, breaching controller obligations. | PL | UODO | GDPR | €3,018 | ↗ |
| 20 Dec 2012 | Regione Emilia RomagnaRegione Emilia Romagna was fined EUR 14,000 by the Garante for unlawfully disseminating personal data through the Regional Student Registry without a legal basis. The authority also found unauthorized retention of sensitive student data. | IT | Garante | GDPR | €14,000 | ↗ |
| 09 Oct 2014 | Comune di UdineThe Municipality of Udine was fined 14,000 EUR by the Garante. The authority found that the Security Policy Document (DPS) had not been updated from 2005 to 2011, which breached data protection rules. | IT | Garante | GDPR | €14,000 | ↗ |
| 10 Apr 2023 | COLEGIO OFICIAL DE ARQUITECTOS DE GRANADACOLEGIO OFICIAL DE ARQUITECTOS DE GRANADA was fined €14,000 by the AEPD for data protection breaches. The authority found a conflict of interest in the appointment of the Data Protection Officer, missing required information on data processing in complaint forms, and the use of third-party cookies without user consent. | ES | AEPD | ePrivacy | €14,000 | ↗ |
| 13 Jan 2022 | Azienda sanitaria unica regionale MarcheAzienda sanitaria unica regionale Marche was fined EUR 14,000 by the Garante for inadequate data protection measures. The breach involved health data and was linked to QR code generation; improved security measures were later implemented. | IT | Garante | GDPR | €14,000 | ↗ |
| 06 Sept 2019 | Anonymised (CyDPC ΑΝΟΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ δημοσί)A medical practice was fined EUR 14,000 for posting a patient's pre- and post-surgery images on Instagram without consent. The authority found a breach of GDPR rules on personal data processing and the protection of special-category data. | CY | CyDPC | GDPR | €14,000 | ↗ |
| 31 May 2023 | Dane anonimowe (G. Sp. z o.o. z siedzibą w K. przy ul.)The President of UODO imposed an administrative fine of PLN 14,148 on G. Sp. z o.o. The sanction was issued for failing to cooperate with the authority in the performance of its duties and for not providing access to information necessary for those duties. | PL | UODO | GDPR | €3,119 | ↗ |