BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Sept 2014 | Happy Fit s.r.l.Happy Fit s.r.l. was fined by the Garante in the amount of EUR 16,400 for making an unsolicited promotional phone call. The company did not provide the required information or obtain consent, breaching data protection rules. | IT | Garante | GDPR | €16,400 | ↗ |
| 13 May 2015 | Barbirato Danilo s.a.s.Barbirato Danilo s.a.s. was fined by the Garante EUR 16,800 for failing to provide the required privacy notice on its website and for improper use of a video surveillance system. The authority cited inadequate CCTV signage and excessive retention of recorded images. | IT | Garante | GDPR | €16,800 | ↗ |
| 24 Jan 2013 | Saverio ProcopioSaverio Procopio was fined €16,800 by the Garante for sending unsolicited promotional emails without obtaining explicit consent from recipients. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €16,800 | ↗ |
| 20 Feb 2014 | Società Editrice Sud s.p.a.Società Editrice Sud s.p.a. was fined by the Garante in the amount of 16,800 EUR for using inadequate information notices on data collection forms. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €16,800 | ↗ |
| 13 May 2015 | Barbirato Danilo s.a.s. di Barbirato Marco e c.Barbirato Danilo s.a.s. was fined by the Garante 16,800 EUR for failing to provide the required privacy notice on its data collection form. The authority also found breaches of CCTV rules, including inadequate signage and excessive retention of recorded images. | IT | Garante | GDPR | €16,800 | ↗ |
| 20 Apr 2017 | Hotel Savoia Genova s.r.l.Hotel Savoia Genova s.r.l. was fined €16,800 by the Garante. The authority found that the company failed to provide the required information to individuals about its video surveillance system and kept surveillance footage longer than permitted. | IT | Garante | GDPR | €16,800 | ↗ |
| 05 Feb 2026 | Dane anonimowe (pana H. G., prowadzącego działalność gospodarczą pod firmą H.)The President of the Polish DPA (UODO) imposed a fine of PLN 16,804 on an anonymous sole proprietor. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for the performance of its duties. | PL | UODO | GDPR | €3,982 | ↗ |
| 26 Sept 2024 | Azienda Sanitaria Territoriale di Ascoli PicenoThe Garante fined Azienda Sanitaria Territoriale di Ascoli Piceno EUR 17,000 for failing to implement procedures that would prevent unauthorized linkage between individuals and health departments. The issue could reveal information about a person's health status. | IT | Garante | GDPR | €17,000 | ↗ |
| 12 Jan 2024 | Alior Bank SA Varșovia Sucursala BucureștiAlior Bank SA, through its Romanian branch, was fined EUR 17,000 by ANSPDCP. The sanction followed an investigation that identified GDPR violations. | RO | ANSPDCP | GDPR | €17,000 | ↗ |
| 25 Oct 2017 | TICKETMASTER SPAIN S.A.Ticketmaster Spain S.A. was fined 17,000 EUR by the AEPD for failing to provide adequate information and obtain valid consent for the use of cookies on its website. The authority found that this conduct breached data protection and privacy rules. | ES | AEPD | ePrivacy | €17,000 | ↗ |
| 29 Jun 2021 | Anonymisé (CNPD decision-24-fr-2021)The company was fined EUR 17,000 by the CNPD for breaching the data minimization principle and for failing to provide adequate information to data subjects. The deficiencies concerned employees and third parties in relation to processing activities. | LU | CNPD | GDPR | €17,000 | ↗ |
| 04 Sept 2025 | SOCIETE COLLECTANT DES DONNEES DE PROSPECTS A PARTIR DE PLUSIEURS SOURCES, NOTAMMENT DES FORMULAIRES DE PARTICIPATION A DES JEUX CONCOURS EN LIGNE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 17,000 on SOCIETE COLLECTANT DES DONNEES DE PROSPECTS A PARTIR DE PLUSIEURS SOURCES, NOTAMMENT DES FORMULAIRES DE PARTICIPATION A DES JEUX CONCOURS EN LIGNE under the simplified procedure. The case concerned the processing of prospect data collected from multiple sources, including online contest entry forms. | FR | CNIL | GDPR | €17,000 | ↗ |
| 07 Jul 2022 | SIA "DEPO DIY"DVI imposed a fine of 17,495 EUR on SIA "DEPO DIY". The decision concerns a breach of obligations and has entered into force. | LV | DVI | GDPR | €17,495 | ↗ |
| 01 Aug 2025 | društvo XThe company failed to implement appropriate organizational and technical security measures, which led to the unauthorized disclosure of personal data of clients involved in credit financing. AZOP imposed a fine of 17,500 EUR. | HR | AZOP | GDPR | €17,500 | ↗ |
| 04 Aug 2021 | Anonymisé (CNPD decision-29-fr-2021)The CNPD found that the organization did not appoint a Data Protection Officer based on the required professional qualities, did not provide the necessary resources, and did not ensure the DPO's autonomy. This constituted breaches of GDPR Articles 37, 38, and 39. | LU | CNPD | GDPR | €17,700 | ↗ |
| 20 Jun 2013 | ASL di SalernoASL di Salerno was fined EUR 18,000 by the Garante for failing to implement minimum security measures. The authority cited, among other issues, the absence of designated data processing managers and the use of common, outdated passwords for electronic systems. | IT | Garante | GDPR | €18,000 | ↗ |
| 08 Nov 2012 | Enterprise Service s.r.l.Enterprise Service s.r.l. was fined by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The authority also found that the required information notice was not provided, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €18,000 | ↗ |
| 26 Jul 2018 | Mercati s.p.aMercati s.p.a was fined 18,000 EUR by the Garante for failing to provide adequate information to users about data collection through a reservation form. The authority also found that the company used a video surveillance system without proper notice, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €18,000 | ↗ |
| 24 May 2024 | G&F&S SECURITY GROUP, S.L.G&F&S SECURITY GROUP, S.L. was fined by the AEPD €18,000 for failing to properly handle a data subject access request. The authority found a breach of Article 15 GDPR and non-compliance with a data protection authority resolution. | ES | AEPD | GDPR | €18,000 | ↗ |
| 26 Dec 2024 | SOCIETE EXPLOITANT DES SUPERMARCHES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 18,000 on SOCIETE EXPLOITANT DES SUPERMARCHES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €18,000 | ↗ |