Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Apr 2015Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e LagunaThe Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e Laguna was fined 4,000 EUR by the Garante. The authority found that personal data had been unlawfully communicated to private entities without an appropriate legal basis, in breach of Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
25 Mar 2021Comune di MonteiasiComune di Monteiasi was fined by the Garante €4,000 for breaching the data minimization principle. The municipality published personal data on its website, including names and IBANs, that were not necessary for transparency purposes.ITGaranteGDPR€4,000
13 Oct 2022B.B.B.A tenant complained that the landlord installed a surveillance camera in the kitchen of the rented property without consent. The AEPD found a breach of data protection rules and imposed a EUR 4,000 fine.ESAEPDGDPR€4,000
13 Feb 2025Comune di TuscaniaThe Garante imposed a 4,000 EUR fine on Comune di Tuscania for violating data protection rules. The authority took into account the limited financial resources of the small municipality when setting the sanction.ITGaranteGDPR€4,000
27 Mar 2014Comune di ConversanoComune di Conversano was fined 4,000 EUR by the Garante for failing to update the annual Security Policy Document. The breach concerned compliance with data protection obligations.ITGaranteGDPR€4,000
07 Nov 2018Comune di BuccinoComune di Buccino was fined for unlawfully publishing personal data online without a legal basis. This violated Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
06 Oct 2016Comune di FurnariThe Municipality of Furnari was fined 4,000 EUR by the Garante. The authority found that personal data remained published on the institutional website beyond the legally permitted period.ITGaranteGDPR€4,000
18 Nov 2015G.M.C. - Giuseppe Marra Communications s.a.p.a.G.M.C. - Giuseppe Marra Communications s.a.p.a. was fined by the Garante in the amount of €4,000 for unlawfully obtaining consent for data processing through a newsletter subscription. The form included marketing purposes beyond the stated intent, which breached Article 23 of the Italian Data Protection Code.ITGaranteGDPR€4,000
11 Dec 2014Progetto Acqua Firenze s.r.l.Progetto Acqua Firenze s.r.l. was fined by the Garante for making an unsolicited promotional phone call. The conduct infringed the complainant's right to object as recorded in the public opt-out list.ITGaranteGDPR€4,000
22 Jun 2022Anonymisé (CNPD decision-12-fr-2022)CNPD imposed a EUR 4,000 fine on Anonymisé for failing to inform data subjects, including employees and third parties, about data processing activities. The authority found breaches of GDPR transparency requirements and data minimization principles.LUCNPDGDPR€4,000
23 Nov 2017Fantozzi Marinella e Banca Nazionale del Lavoro S.p.A.Fantozzi Marinella and Banca Nazionale del Lavoro S.p.A. were fined by the Garante in the amount of 4,000 EUR for breaches of data protection measures under the Italian Privacy Code. The case concerned non-compliance with requirements for the protection of personal data.ITGaranteGDPR€4,000
06 May 2019Regione AbruzzoThe Garante fined Regione Abruzzo EUR 4,000 for violations linked to data processing through public service apps. The authority found that adequate data protection and security measures were not ensured.ITGaranteGDPR€4,000
29 Jul 2020CALLESGARCIA S.C.CALLESGARCIA S.C. was fined by the AEPD €4,000 for using a wedding photo in business advertising without authorization. The authority found a breach of Article 6 GDPR on lawful processing of personal data.ESAEPDGDPR€4,000
21 Jul 2016Planet Book Service di Mario Manna & C. s.a.s.Planet Book Service di Mario Manna & C. s.a.s. was fined by the Garante for failing to respond to an information request. The conduct breached Article 157 of the Italian Data Protection Code.ITGaranteGDPR€4,000
22 Oct 2015Comune di Montelupo FiorentinoThe Municipality of Comune di Montelupo Fiorentino was fined 4,000 EUR by the Garante for unlawfully publishing personal data online. The case concerned the results of participants in a competitive examination disclosed without a proper legal basis.ITGaranteGDPR€4,000
04 Jun 2015SIAS srlSIAS srl was fined EUR 4,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unlawful processing of personal data, including the acquisition of income data without consent.ITGaranteGDPR€4,000
04 Nov 2025COLLECTIVITE TERRITORIALE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on COLLECTIVITE TERRITORIALE under a simplified procedure. The decision concerns a breach of data protection rules.FRCNILGDPR€4,000
23 Oct 2025Istituto d'Istruzione Superiore “Statista Aldo Moro” di Fara SabinaThe school published on its website a document containing personal data related to a student's disciplinary proceeding. Garante found that this breached the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
01 Jan 2021MAX2PROTECT, S.L.MAX2PROTECT, S.L. was fined by the AEPD 4,000 EUR for sending spam emails without recipient consent. The authority also found unlawful processing of personal data collected from public websites without proper legal basis.ESAEPDGDPR€4,000
02 Apr 2015Ministero dell'Interno – Dipartimento della Pubblica SicurezzaThe Ministry of the Interior – Department of Public Security was fined 4,000 EUR for publishing a ranking list containing personal data without a legal or regulatory basis. This constituted a breach of Article 19 of the Italian Privacy Code.ITGaranteGDPR€4,000