BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Apr 2015 | Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e LagunaThe Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e Laguna was fined 4,000 EUR by the Garante. The authority found that personal data had been unlawfully communicated to private entities without an appropriate legal basis, in breach of Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Mar 2021 | Comune di MonteiasiComune di Monteiasi was fined by the Garante €4,000 for breaching the data minimization principle. The municipality published personal data on its website, including names and IBANs, that were not necessary for transparency purposes. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Oct 2022 | B.B.B.A tenant complained that the landlord installed a surveillance camera in the kitchen of the rented property without consent. The AEPD found a breach of data protection rules and imposed a EUR 4,000 fine. | ES | AEPD | GDPR | €4,000 | ↗ |
| 13 Feb 2025 | Comune di TuscaniaThe Garante imposed a 4,000 EUR fine on Comune di Tuscania for violating data protection rules. The authority took into account the limited financial resources of the small municipality when setting the sanction. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Mar 2014 | Comune di ConversanoComune di Conversano was fined 4,000 EUR by the Garante for failing to update the annual Security Policy Document. The breach concerned compliance with data protection obligations. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 Nov 2018 | Comune di BuccinoComune di Buccino was fined for unlawfully publishing personal data online without a legal basis. This violated Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Oct 2016 | Comune di FurnariThe Municipality of Furnari was fined 4,000 EUR by the Garante. The authority found that personal data remained published on the institutional website beyond the legally permitted period. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Nov 2015 | G.M.C. - Giuseppe Marra Communications s.a.p.a.G.M.C. - Giuseppe Marra Communications s.a.p.a. was fined by the Garante in the amount of €4,000 for unlawfully obtaining consent for data processing through a newsletter subscription. The form included marketing purposes beyond the stated intent, which breached Article 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 11 Dec 2014 | Progetto Acqua Firenze s.r.l.Progetto Acqua Firenze s.r.l. was fined by the Garante for making an unsolicited promotional phone call. The conduct infringed the complainant's right to object as recorded in the public opt-out list. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jun 2022 | Anonymisé (CNPD decision-12-fr-2022)CNPD imposed a EUR 4,000 fine on Anonymisé for failing to inform data subjects, including employees and third parties, about data processing activities. The authority found breaches of GDPR transparency requirements and data minimization principles. | LU | CNPD | GDPR | €4,000 | ↗ |
| 23 Nov 2017 | Fantozzi Marinella e Banca Nazionale del Lavoro S.p.A.Fantozzi Marinella and Banca Nazionale del Lavoro S.p.A. were fined by the Garante in the amount of 4,000 EUR for breaches of data protection measures under the Italian Privacy Code. The case concerned non-compliance with requirements for the protection of personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 May 2019 | Regione AbruzzoThe Garante fined Regione Abruzzo EUR 4,000 for violations linked to data processing through public service apps. The authority found that adequate data protection and security measures were not ensured. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Jul 2020 | CALLESGARCIA S.C.CALLESGARCIA S.C. was fined by the AEPD €4,000 for using a wedding photo in business advertising without authorization. The authority found a breach of Article 6 GDPR on lawful processing of personal data. | ES | AEPD | GDPR | €4,000 | ↗ |
| 21 Jul 2016 | Planet Book Service di Mario Manna & C. s.a.s.Planet Book Service di Mario Manna & C. s.a.s. was fined by the Garante for failing to respond to an information request. The conduct breached Article 157 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Oct 2015 | Comune di Montelupo FiorentinoThe Municipality of Comune di Montelupo Fiorentino was fined 4,000 EUR by the Garante for unlawfully publishing personal data online. The case concerned the results of participants in a competitive examination disclosed without a proper legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Jun 2015 | SIAS srlSIAS srl was fined EUR 4,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unlawful processing of personal data, including the acquisition of income data without consent. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Nov 2025 | COLLECTIVITE TERRITORIALE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on COLLECTIVITE TERRITORIALE under a simplified procedure. The decision concerns a breach of data protection rules. | FR | CNIL | GDPR | €4,000 | ↗ |
| 23 Oct 2025 | Istituto d'Istruzione Superiore “Statista Aldo Moro” di Fara SabinaThe school published on its website a document containing personal data related to a student's disciplinary proceeding. Garante found that this breached the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Jan 2021 | MAX2PROTECT, S.L.MAX2PROTECT, S.L. was fined by the AEPD 4,000 EUR for sending spam emails without recipient consent. The authority also found unlawful processing of personal data collected from public websites without proper legal basis. | ES | AEPD | GDPR | €4,000 | ↗ |
| 02 Apr 2015 | Ministero dell'Interno – Dipartimento della Pubblica SicurezzaThe Ministry of the Interior – Department of Public Security was fined 4,000 EUR for publishing a ranking list containing personal data without a legal or regulatory basis. This constituted a breach of Article 19 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |