BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Apr 2023 | Tensa Art Design SAThe National Supervisory Authority completed an investigation in March 2023 at Tensa Art Design SA and found violations of GDPR provisions. As a result, the company was fined 1,000 EUR. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 26 Apr 2023 | CARTONAJES BAÑERES, S.A.CARTONAJES BAÑERES, S.A. was fined by the AEPD 220,000 EUR for processing biometric data without the required data protection impact assessment. The authority also found a failure to comply with data subjects’ access rights. | ES | AEPD | GDPR | €220,000 | ↗ |
| 26 Apr 2023 | Regionstyrelsen i Region SkåneRegionstyrelsen i Region Skåne was fined by IMY for storing unencrypted sensitive patient data on a USB drive that was lost. The authority found this to be a breach of Article 32 GDPR, which requires appropriate technical and organisational security measures. | SE | IMY | GDPR | €17,566 | ↗ |
| 27 Apr 2023 | ADENET SYSTEMS, S.L.ADENET SYSTEMS, S.L. was fined EUR 6,000 by the AEPD for failing to provide access. The authority treated this as a breach of Article 58(1) GDPR and an obstruction of its investigative functions. | ES | AEPD | GDPR | €6,000 | ↗ |
| 27 Apr 2023 | Ministero dell’Istruzione e del Merito - Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di LecceMinistero dell’Istruzione e del Merito - Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce was fined 15,000 EUR by the Garante for publishing personal data on its website. The case concerns a breach of data protection rules through unauthorized disclosure of information. | IT | Garante | GDPR | €15,000 | ↗ |
| 27 Apr 2023 | Ama S.p.a.Ama S.p.a. was fined €239,000 by the Garante for the unlawful processing and dissemination of personal health data concerning women who had terminated pregnancies. The identities were displayed on crosses at a cemetery, resulting in an unlawful disclosure of sensitive data. | IT | Garante | GDPR | €239,000 | ↗ |
| 27 Apr 2023 | Roma CapitaleRoma Capitale was fined EUR 176,000 by the Garante for the unlawful processing and dissemination of personal health data relating to women who had terminated pregnancies. The sensitive information was displayed on crosses at a cemetery, creating a serious data protection breach. | IT | Garante | GDPR | €176,000 | ↗ |
| 27 Apr 2023 | Provvedimento del 27 aprile 2023 [9896468]A fine of EUR 400 was imposed for improper use of a video surveillance system that captured images of a public street without the required authorization. The case concerned a breach of personal data processing rules in the context of video monitoring. | IT | Garante | GDPR | €400 | ↗ |
| 27 Apr 2023 | Checcoro di Nigro FrancescoThe company was fined EUR 2,000 by the Italian data protection authority, Garante. The sanction concerned the use of surveillance cameras without appropriate informational signage, in breach of GDPR requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Apr 2023 | B.B.B.The entity installed a surveillance camera without informing tenants or obtaining their consent. The camera captured shared areas, which constituted a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 27 Apr 2023 | Geico S.p.A.Geico S.p.A. was fined 40,000 EUR by the Garante for keeping former employees' email accounts active after the employment relationship ended. The authority found that the company accessed the contents of those accounts in breach of GDPR requirements. | IT | Garante | GDPR | €40,000 | ↗ |
| 27 Apr 2023 | Comune di AdelfiaThe Garante fined Comune di Adelfia EUR 8,000 for violations related to the publication of personal data on its institutional website. The data were later removed. | IT | Garante | GDPR | €8,000 | ↗ |
| 27 Apr 2023 | Benetton Group S.r.l.Benetton Group S.r.l. was fined €240,000 by the Italian data protection authority, Garante. The authority found violations in the processing of personal data for marketing and profiling purposes, including the retention of former customers’ data for more than 10 years without proper justification. | IT | Garante | GDPR | €240,000 | ↗ |
| 27 Apr 2023 | Università degli studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined EUR 4,000 by the Garante for improperly disclosing a complainant’s personal data to all Italian universities. The disclosure also included data relating to criminal offenses, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Apr 2023 | Tiziana Life Science LimitedTiziana Life Science Limited was fined by the Italian Garante in the amount of EUR 30,000. The case concerned failure to provide information and obtain consent for processing personal and genetic data acquired from the bankrupt company Shar.Dna S.p.A. for scientific research purposes. | IT | Garante | GDPR | €30,000 | ↗ |
| 27 Apr 2023 | B.B.B.The entity was fined by the AEPD in the amount of EUR 1,000 for installing surveillance cameras without proper signage and justification. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 02 May 2023 | KópavogsbærKópavogsbær was fined 4,000,000 ISK by Persónuvernd for using the Seesaw student system in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which requires a lawful basis and appropriate safeguards. | IS | Persónuvernd | GDPR | €26,720 | ↗ |
| 02 May 2023 | InternetThe company was fined for failing to implement adequate security measures for personal data processing. The deficiency led to a data breach involving user accounts, including accounts protected by weak passwords. | CZ | UOOU | GDPR | €63,600 | ↗ |
| 03 May 2023 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined EUR 20,000 by the AEPD for irregularities in the cookie policy on its website. The authority found a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 03 May 2023 | B.B.B.A small hospitality establishment was fined 500 EUR by the AEPD for installing a surveillance camera that excessively recorded public areas. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €500 | ↗ |