Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Oct 2023Edizioni Proposta Sud S.r.l.The Garante fined Edizioni Proposta Sud S.r.l. €20,000 for publishing false information about an individual's health status without verifying its accuracy. The authority found this breached GDPR principles on data protection and accuracy.ITGaranteGDPR€20,000
26 Apr 2018Gianluigi GuarinoGianluigi Guarino, director of the online newspaper Casertace.net, was fined by the Garante. The sanction concerned his failure to respond to an information request about data processing, which breached Article 164 of the Italian Privacy Code.ITGaranteGDPR€20,000
31 Jan 2026SC Tensa Art Design SAThe Romanian data protection authority fined SC Tensa Art Design SA, operator of the Lensa brand, EUR 20,000 under the GDPR. The sanction followed the company’s failure to respond to the authority’s investigative request concerning cookie tracking and behavioral advertising on its website.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€20,000
08 Jul 2024COMERCIAL GIRONA DE LLIBRES, S.L.COMERCIAL GIRONA DE LLIBRES, S.L. was fined by the AEPD 20,000 EUR for inadequate security measures. The authority cited, among other issues, the sending of credentials by email, which breached Article 32 of the GDPR.ESAEPDGDPR€20,000
15 Mar 2018Directafin s.p.a.Directafin s.p.a. was fined by the Garante in the amount of EUR 20,000 for using a single consent flag for multiple processing purposes. This included marketing and sharing personal data with third parties without valid consent.ITGaranteGDPR€20,000
01 Jan 2018VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 20,000 EUR by the AEPD for sending unsolicited marketing emails. The authority found that recipients were not given an effective unsubscribe option, despite a request to be removed from the mailing list.ESAEPDePrivacy€20,000
15 Nov 2025Państwowego Powiatowego Inspektora Sanitarnego w M., ul.UODO imposed a PLN 20,000 administrative fine on the State District Sanitary Inspector in M. The authority found that appropriate technical and organizational measures based on a risk assessment were not implemented, and that the effectiveness of safeguards for data processed on external media was not regularly tested. The case concerned a breach of the integrity and confidentiality principle.PLUODOGDPR€4,725
07 Apr 2022Made in Italy s.r.l.s.Made in Italy s.r.l.s. was fined EUR 20,000 by the Garante for carrying out promotional contacts without obtaining consent. The authority also found that the company failed to respond to data subject rights requests, which is a breach of data protection obligations.ITGaranteGDPR€20,000
01 Jun 2023Cooperjob S.p.A.Cooperjob S.p.A. was fined EUR 20,000 by the Garante for failing to respond within the required timeframe to a job applicant’s request to delete personal data. The authority found a breach of GDPR Article 12 on timely handling of data subject requests.ITGaranteGDPR€20,000
09 Oct 2019Vreau Credit S.R.L.Vreau Credit S.R.L. was fined by ANSPDCP in the amount of 20,000 EUR for failing to notify a personal data breach without undue delay. The company had been aware of the incident since December 2018 but did not inform the supervisory authority promptly.ROANSPDCPGDPR€20,000
01 Jan 2016EASYVOYAGE SASEASYVOYAGE SAS was fined by the AEPD in the amount of 20,000 EUR for sending unsolicited commercial emails. The conduct continued despite requests for data cancellation, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€20,000
27 Jan 2025Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€20,000
26 Jul 2012Comune di MilanoThe Garante fined Comune di Milano EUR 20,000 for failing to implement minimum security measures on two computer stations at a primary school. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€20,000
16 Dec 2021FCA Italy s.p.a.FCA Italy s.p.a. was fined 20,000 EUR by the Garante for breaching GDPR provisions on the right of access and transparency obligations. The case arose from a complaint by an English citizen about the handling of their personal data.ITGaranteGDPR€20,000
13 Sept 2017Coleman s.p.a.Coleman s.p.a. was fined by the Garante 20,000 EUR for failing to implement minimum security measures for online booking requests. This allowed access to personal data without authentication.ITGaranteGDPR€20,000
24 Jan 2013United Music s.r.l.United Music s.r.l. was fined for failing to notify the cessation of personal data processing activities related to profiling and personality definition through its websites. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€20,000
16 Feb 2017Consorzio unico di bacino per le Province di Napoli e CasertaConsorzio unico di bacino for the Provinces of Naples and Caserta was fined EUR 20,000 by the Garante. The authority found that the employer processed employees' biometric data, including fingerprints, for attendance tracking without a proper legal basis.ITGaranteGDPR€20,000
07 Mar 2024Banca di Credito Cooperativo Appulo Lucana soc. cooperativaThe Garante fined Banca di Credito Cooperativo Appulo Lucana 20,000 EUR for failing to provide adequate access to personal data requested by a former employee. The authority found a breach of GDPR Article 15 on the right of access.ITGaranteGDPR€20,000
01 Feb 2018Car2Go Italia s.r.l.Car2Go Italia s.r.l. was fined EUR 20,000 by the Garante. The authority found a breach of data protection rules for failing to designate employees as data processors in connection with geolocation data processing.ITGaranteGDPR€20,000
02 Mar 2017MM Group s.r.l.MM Group s.r.l. was fined EUR 20,000 by the Garante for making unsolicited promotional calls. The calls were placed to a number listed in the public opt-out register, which breached data protection rules.ITGaranteGDPR€20,000