BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 May 2011 | Idrablu SpaIdrablu Spa was fined by the Garante in the amount of EUR 20,000 for failing to respond to requests for information about the transfer of personal data to another company. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Feb 2018 | Technical Hunter s.r.l.Technical Hunter s.r.l. was fined by the Garante 20,000 EUR for processing job applicants’ personal data without proper compliance with data protection rules. The data was collected and used through the company website, job portals, and social networks. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Apr 2018 | Raffaele FrancescoRaffaele Francesco was fined by the Garante for processing the personal data of five patients without the required consent during dental services. The conduct breached the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Dec 2024 | SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 06 Sept 2012 | One Italia S.p.A.One Italia S.p.A. was fined €20,000 by the Garante for sending promotional MMS messages without obtaining prior consent from recipients. The conduct breached Articles 23 and 130 of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 31 Dec 2025 | UNIVERSITE (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on UNIVERSITE (procédure simplifiée). The case concerned a confirmed breach of rules supervised by CNIL. | FR | CNIL | GDPR | €20,000 | ↗ |
| 27 Sept 2022 | ALBERO FORTE COMPOSITE, S.L.The company used employees’ facial images for clocking in and out without proper notice about biometric data processing. AEPD found this to be a breach of data protection rules and imposed a 20,000 EUR fine. | ES | AEPD | GDPR | €20,000 | ↗ |
| 15 Apr 2025 | COLPER BUSINESS 2020 S.L.COLPER BUSINESS 2020 S.L. was fined by the AEPD EUR 20,000 for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 02 Dec 2021 | La Duomo S.r.l.s.La Duomo S.r.l.s. was fined EUR 20,000 by the Garante for sending unsolicited promotional SMS messages without valid consent. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 02 Nov 2021 | MYHERITAGE, LTDMYHERITAGE, LTD was fined EUR 20,000 by the AEPD for international data transfers without adequate safeguards and for unclear legal grounds for processing. The authority also found insufficient information provided to data subjects and improper handling of genetic data. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 27 Jan 2021 | Powerplay S.r.l.Powerplay S.r.l. was fined by the Garante for making unsolicited promotional calls despite the recipient's clear request not to receive further communications. The company failed to place the number on a blacklist, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Mar 2024 | Centro Riparazioni Piacentino S.p.A.Centro Riparazioni Piacentino S.p.A. was fined by the Garante for continuing to operate individual company accounts months after employment ended and for accessing messages without proper deletion. The authority also found inadequate information and insufficient access rights for former employees. | IT | Garante | GDPR | €20,000 | ↗ |
| 04 Oct 2017 | PRENATAL SAPRENATAL SA was fined by the AEPD EUR 20,000 for sending commercial SMS messages without providing recipients with an opt-out mechanism. The case concerns a breach of electronic communications rules and marketing consent requirements. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 13 Sept 2024 | DIGITAL PHOTO IMAGE, S.A.DIGITAL PHOTO IMAGE, S.A. was fined EUR 20,000 by the AEPD for breaching the LSSI. The company sent emails without providing recipients with a valid means to exercise their right to stop receiving such communications. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 11 May 2017 | Laboratorio Villafranca sncLaboratorio Villafranca snc was fined EUR 20,000 by the Italian data protection authority, Garante. The case concerned a failure to properly notify data processing activities under the Italian data protection code. | IT | Garante | GDPR | €20,000 | ↗ |
| 02 Nov 2022 | QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the AEPD for processing personal data without a valid legal basis and for failing to comply with data deletion requests. The violations concerned Articles 6 and 17 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 16 Nov 2017 | S.T.E.A.T. S.p.a.S.T.E.A.T. S.p.a. was fined by the Garante for failing to properly notify the installation of electronic monitoring and localization devices on public transport buses. The authority found a breach of data protection notification obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Mar 2018 | Fin Solution Italia S.p.a.Fin Solution Italia S.p.a. was fined EUR 20,000 by the Garante for inadequate security measures in the processing of personal data. The authority found that weak passwords were used on company PCs, increasing the risk of unauthorized access. | IT | Garante | GDPR | €20,000 | ↗ |
| 02 Jun 2016 | TELEFONICA MOVILES ESPAÑA, S.A.U.Telefónica Móviles España was fined €20,000 by the AEPD for using “supercookies” without properly informing users or obtaining their consent. The authority found this conduct to be in breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 17 Oct 2024 | SOCIETE AYANT POUR ACTIVITE LA FOURNITURE DE PRESTATIONS DE SERVICE (GESTION APPELS TELEPHONIQUES) (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE AYANT POUR ACTIVITE LA FOURNITURE DE PRESTATIONS DE SERVICE (GESTION APPELS TELEPHONIQUES). The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |