BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Sept 2020 | PLAY ORENES, S.L.PLAY ORENES, S.L. was fined by the AEPD €20,000 for improperly positioning surveillance cameras. The cameras captured public areas, which breached data protection rules. | ES | AEPD | GDPR | €20,000 | ↗ |
| 03 May 2023 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined EUR 20,000 by the AEPD for irregularities in the cookie policy on its website. The authority found a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 11 Jan 2024 | dott. BagnatoA doctor was fined by the Garante for breaching privacy rules. The case involved improper handling of medical prescriptions outside the office, which could expose sensitive personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 04 Apr 2007 | Asl Brindisi 1The Garante fined Asl Brindisi 1 for failing to notify the processing of personal data under the Italian Data Protection Code. Article 37 was violated, and the fine amounted to EUR 20,000. | IT | Garante | GDPR | €20,000 | ↗ |
| 30 Mar 2017 | Provincia di CasertaProvincia di Caserta was fined EUR 20,000 by the Garante. The authority found that the province failed to designate data processing officers and did not update the security program document required under the data protection code. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Oct 2022 | Occhiali24.it S.r.l.Occhiali24.it S.r.l. was fined by the Garante 20,000 EUR for sending unsolicited marketing communications without prior consent. The authority also found that the company failed to respond to data subject rights requests, indicating non-compliance with data protection obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Nov 2017 | Superbeton S.p.a.Superbeton S.p.a. was fined 20,000 EUR by the Garante for failing to properly notify the use of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 17 Nov 2010 | Azienda trasporti di MessinaAzienda trasporti di Messina was fined 20,000 EUR by the Garante for processing sensitive personal data without providing the required information notice and without obtaining consent from the data subjects. The case concerns breaches of core transparency and lawful-processing obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 06 Apr 2017 | Regione AbruzzoThe Garante fined Regione Abruzzo EUR 20,000 for unlawfully publishing lists on its website that revealed candidates' health status. The case involved the disclosure of sensitive personal data relating to individuals with disabilities. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Nov 2014 | GROUPALIA COMPRA COLECTIVA, S.L.GROUPALIA COMPRA COLECTIVA, S.L. was fined by the AEPD 20,000 EUR for continuing to send commercial emails after the user requested deletion of personal data and opted out of communications. The case indicates a failure to respect the data subject’s withdrawal of consent and request to stop marketing processing. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 07 Apr 2021 | MZN HELLAS A.E.The company was fined for sending unsolicited marketing SMS messages to a customer who had explicitly objected to such communications. The authority found this to be a breach of GDPR rules on data subject rights and data protection by design. | GR | HDPA | GDPR | €20,000 | ↗ |
| 12 Dec 2024 | Ambiente 2000 S.r.l.Ambiente 2000 S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company required employees to disclose passwords to their work email and files containing personal data, in breach of the GDPR. | IT | Garante | GDPR | €20,000 | ↗ |
| 02 Apr 2015 | Ales Groupe Italia S.p.A.Ales Groupe Italia S.p.A. was fined EUR 20,000 by the Garante for violations related to data processing on its website. Users were asked to provide personal data without proper consent mechanisms. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Nov 2025 | SOCIETE EXPLOITANT UN FONDS DE COMMERCE DE DISTRIBUTION A DOMINANTE ALIMENTAIRE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on the company. The case concerns a breach of rules under the data protection authority’s supervision. | FR | CNIL | GDPR | €20,000 | ↗ |
| 15 Jun 2020 | Bostadsrättsförening HalmstadBRF Gårdsbjörken was fined by IMY for unlawful video and audio surveillance in common areas. The authority found breaches of GDPR principles, including data minimization and transparency. | SE | IMY | GDPR | €1,898 | ↗ |
| 07 Mar 2023 | SIA "Euronics Latvia"The DVI imposed a fine of EUR 20,000 on SIA "Euronics Latvia". The decision entered into force on 7 March 2023. | LV | DVI | GDPR | €20,000 | ↗ |
| 10 Nov 2011 | Idea Service S.r.l.Idea Service S.r.l. was fined EUR 20,000 by the Garante for failing to provide information about an unwanted switch of telephone service provider. The authority found a breach of Article 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 18 Sept 2008 | Eutelia S.p.A.Eutelia S.p.A. was fined by the Garante EUR 20,000 for using an automated calling system without obtaining prior consent from the individuals concerned. The case concerned a breach of data protection rules and consent requirements for automated communications. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 May 2022 | Hu XiaoyanThe Garante fined Hu Xiaoyan EUR 20,000 for operating a video surveillance system without proper informational signage and required safeguards. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jan 2022 | JEG'S LIFE STYLE, S.L.JEG'S LIFE STYLE, S.L. was fined by the AEPD 20,000 EUR for breaching data protection rules. The company disclosed private information about a former employee to third parties by email without consent. | ES | AEPD | GDPR | €20,000 | ↗ |