BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Jul 2021 | LABORATORIOS GONZÁLEZ, S.L.LABORATORIOS GONZÁLEZ, S.L. was fined by the AEPD 20,000 EUR for sharing an employee’s COVID-19 antibody test result with the employee’s superior without consent. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €20,000 | ↗ |
| 27 Jan 2016 | Planetcall s.r.l.Planetcall s.r.l. was fined €20,000 by the Garante for failing to designate data processors and for using inadequate authentication credentials. The case concerned breaches of the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 10 Nov 2022 | Sportitalia, società sportiva dilettantistica a responsabilità limitataSportitalia was fined €20,000 by the Italian supervisory authority, Garante. The case concerned the use of a biometric system to record employee attendance without a proper legal basis, in breach of GDPR rules on data processing and special categories of data. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Jul 2018 | Active Network S.p.a.Active Network S.p.a. was fined by the Garante 20,000 EUR for retaining telematic traffic data for more than 12 months. The authority found that this practice breached data protection rules in the context of crime detection and repression. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Apr 2015 | Novelli DonataNovelli Donata was fined EUR 20,000 by the Garante. The case concerned the activation of eight phone cards in the names of four individuals without their knowledge, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 08 Nov 2023 | SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA MISE EN OEUVRE DE LOGICIELS DE SURVEILLANCE DES EMPLOYES (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on the company under a simplified procedure. The decision concerns breaches linked to the company's activity in employee monitoring software. | FR | CNIL | GDPR | €20,000 | ↗ |
| 27 Dec 2012 | Euro-Catering O.E.The company installed a CCTV system without notifying the supervisory authority, failed to display required informational signs, and collected excessive data. These actions breached privacy protection rules. | GR | HDPA | GDPR | €20,000 | ↗ |
| 26 Nov 2020 | Concentrix Cvg Italy s.r.l.Concentrix Cvg Italy s.r.l. was fined 20,000 EUR by the Garante for violating GDPR principles. The case concerned a company policy that improperly handled employees' personal data, including a requirement to keep personal items visible on desks. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Dec 2023 | Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 02 Mar 2017 | Trilogy s.r.l.Trilogy s.r.l. and Fastweb s.p.a. were fined for making unsolicited promotional calls to a phone number listed in the public opt-out register. The conduct breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale città di MilanoAzienda sanitaria locale città di Milano was fined by the Garante EUR 20,000 for improperly processing personal data concerning health and sexual life without adequate safeguards. The authority found that the processing breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 28 Apr 2022 | Comune di TarantoComune di Taranto was fined by the Garante in the amount of EUR 20,000 for violations related to the installation of surveillance cameras without proper data protection measures. The authority found a lack of transparency and a failure to provide the required information to data subjects. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Feb 2018 | Casa della legalità e della cultura onlusCasa della legalità e della cultura onlus was fined EUR 20,000 by the Garante. The authority found a data protection breach because the organization failed to respond to requests for information about the publication of personal data on its websites. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Mar 2025 | NOVATES ALIMENTACIÓN MADRID, S.L.NOVATES ALIMENTACIÓN MADRID, S.L. was fined by the AEPD for a personal data protection breach involving the improper handling of video surveillance footage. The footage was shared via WhatsApp without adequate security measures, increasing the risk of unauthorized access. | ES | AEPD | GDPR | €20,000 | ↗ |
| 16 Sept 2021 | Azienda Ospedaliero-Universitaria di ModenaAzienda Ospedaliero-Universitaria di Modena was fined by the Garante for the incorrect handling of sensitive health data, including HIV diagnoses, during the COVID-19 emergency. The case concerned breaches of personal data protection rules and medical confidentiality. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Dec 2024 | CENTRE D'APPEL (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on CENTRE D'APPEL under a simplified procedure. The case concerned a confirmed regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €20,000 | ↗ |
| 04 Nov 2015 | VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD €20,000 for sending unauthorized commercial communications to a user after they had unsubscribed from the newsletter. The case indicates a failure to respect consent and opt-out requirements for marketing communications. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 23 Oct 2025 | Hearst Magazines Italia S.p.A.Hearst Magazines Italia S.p.A. was fined EUR 20,000 by the Garante for publishing personal data relating to an individual's health without a legal basis. The authority found a breach of the principles of lawfulness and fairness in processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Jan 2017 | Perrone Rosaria e Azienda Universitaria Ospedaliera Ospedali Riuniti di TriestePerrone Rosaria and Azienda Universitaria Ospedaliera Ospedali Riuniti di Trieste were fined by the Garante 20,000 EUR. The sanction concerned unauthorized access by medical staff to personal health data, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jan 2019 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALIberia was fined by the AEPD 20,000 EUR for continuing to send emails to a customer who had requested removal from the loyalty program and deletion of personal data. The authority found this conduct to be a breach of GDPR Article 6. | ES | AEPD | GDPR | €20,000 | ↗ |