BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Oct 2013 | Stadek sncStadek snc was fined EUR 4,000 by the Garante for non-compliant video surveillance signage. The case concerns a breach of data protection requirements related to informing individuals about surveillance. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Mar 2015 | Azienda Ospedaliera Bolognini di SeriateAzienda Ospedaliera Bolognini di Seriate was fined by the Garante for sending medical reports to an incorrect address without the patient's consent. The case involved a breach of data protection rules and the confidentiality of medical information. | IT | Garante | GDPR | €4,000 | ↗ |
| 28 Feb 2019 | Comune di MisterbiancoComune di Misterbianco was fined by the Garante 4,000 EUR for unlawful processing of personal data. The breach involved publishing personal information on its website beyond the legally permitted period. | IT | Garante | GDPR | €4,000 | ↗ |
| 14 Dec 2017 | Rotondi AndreaAndrea Rotondi was fined for the improper handling of banking documents that were found by a private citizen. Banca Nazionale del Lavoro was held jointly liable for the violation. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Nov 2017 | Ricciotti CorradoRicciotti Corrado was fined by the Garante 4,000 EUR for violations related to personal data protection. The case involved improper handling of banking documentation. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Oct 2025 | Azzurra Sport s.r.l.Azzurra Sport s.r.l. was fined EUR 4,000 by the Garante for unlawful processing of personal data through a video surveillance system. The breach concerned the absence of appropriate informational signage for individuals subject to the monitoring. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jul 2025 | KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD in the amount of EUR 4,000 for sending unsolicited messages and processing personal data without a legal basis. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 12 Sept 2023 | LEADDESK, S.L.LEADDESK, S.L. was fined by the AEPD for failing to provide access to information required under Article 58(1) of the GDPR. The conduct was treated as an obstruction of the data protection authority’s investigative functions. | ES | AEPD | GDPR | €4,000 | ↗ |
| 15 Mar 2023 | Partidul Uniunea Salvați RomâniaThe fine was imposed for a data security breach involving the loss of confidentiality and integrity of data stored on a server. The incident resulted from a phishing attack that compromised the system. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 27 Oct 2021 | VENTANAS MAKE YOURSELF, S.L.The company was fined by the AEPD EUR 4,000 for not having a privacy policy and a cookie policy on its website. The breach concerned GDPR and LSSI requirements on information provided to users. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 24 Nov 2022 | Società Lombarda Sport s.r.l.Società Lombarda Sport s.r.l. was fined by the Garante 4,000 EUR for processing personal data without an adequate legal basis. The authority also found failures to ensure data integrity and confidentiality in connection with the issuance of medical certificates for non-competitive sports activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Feb 2026 | Comune di Mazara del ValloComune di Mazara del Vallo was fined EUR 4,000 by the Garante for breaches of data protection principles. The authority found that the municipality failed to provide adequate information to data subjects and did not carry out a data protection impact assessment for its video surveillance system. | IT | Garante | GDPR | €4,000 | ↗ |
| 20 Mar 2008 | Marco TardelliMarco Tardelli was fined by the Garante for failing to provide a complete response to a personal data access request. The authority found a breach of the Italian data protection code. | IT | Garante | GDPR | €4,000 | ↗ |
| 14 May 2020 | Anonymizováno (ÚOOÚ spr-563809-118)The entity was fined for operating a camera system without meeting the information obligations required under Czech data protection law. The case concerns a breach of transparency duties toward individuals subject to surveillance. | CZ | UOOU | GDPR | €145 | ↗ |
| 13 Sept 2012 | Ruzzo Reti S.p.a.Ruzzo Reti S.p.a. was fined EUR 4,000 by the Italian Garante. The authority found that the company failed to designate data processors, meaning it did not adopt the minimum security measures required by the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Nov 2015 | Comune di RecaleComune di Recale was fined EUR 4,000 by the Garante for publishing an individual's personal data on its institutional website without proper legal basis. The case concerned violations of privacy and personal data processing rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Jan 2022 | Medicina & Lavoro s.r.l.Medicina & Lavoro s.r.l. was fined by the Garante 4,000 EUR for failing to provide an adequate response to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Nov 2016 | Comune di Sant'AgnelloComune di Sant'Agnello was fined EUR 4,000 by the Garante. The authority found that personal data of children had been published on the municipality's website, in breach of privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Jul 2016 | M2G Solution s.r.l.M2G Solution s.r.l. was fined 4,000 EUR by the Garante for making promotional calls to a number listed in the public opposition register. The authority found this to be a breach of the right to object to direct marketing. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Jan 2019 | Istituto Comprensivo Paolo StefanelliIstituto Comprensivo Paolo Stefanelli was fined by the Garante 4,000 EUR for publishing personal data on its website that revealed individuals' health status. The case involved a breach of privacy rules and the protection of sensitive data. | IT | Garante | GDPR | €4,000 | ↗ |