BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Apr 2022 | Anonymisé (CNPD decision-10-fr-2022)The public transport organization breached GDPR requirements on storage limitation, data minimization, and providing adequate information to data subjects. CNPD imposed a fine of EUR 4,000. | LU | CNPD | GDPR | €4,000 | ↗ |
| 10 Mar 2021 | B.B.B.The entity was fined by the AEPD in the amount of 4,000 EUR for installing a video surveillance system aimed at public areas. The authority also found that images were captured without justified cause and retained longer than permitted by law. | ES | AEPD | GDPR | €4,000 | ↗ |
| 12 May 2016 | Leonardo SestaLeonardo Sesta, a lawyer, was fined by the Italian data protection authority, Garante. The violation concerned transmitting personal data by email instead of registered mail, contrary to data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jan 2015 | Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined EUR 4,000 by the Garante. The authority found that personal data had been unlawfully published on its website for longer than the legally permitted fifteen days. | IT | Garante | GDPR | €4,000 | ↗ |
| 03 Jun 2020 | MALAGATROM, S.L.U.MALAGATROM, S.L.U. was fined by the AEPD 4,000 EUR for processing and disclosing personal data on Amazon without consent. The authority found this conduct to be contrary to Article 6 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 13 Jul 2016 | Italian Lab s.r.l.Italian Lab s.r.l. was fined EUR 4,000 by the Garante. The case concerned the processing of personal data for a mailing list and newsletter without obtaining user consent. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Nov 2023 | LOS NIÑOS DE MONTESSORI, S.L.The company was fined by the AEPD for failing to publish a privacy policy on its website and for installing non-exempt cookies without informing users or obtaining consent. The case reflects deficiencies in basic transparency and consent requirements under data protection rules. | ES | AEPD | GDPR | €4,000 | ↗ |
| 28 Mar 2019 | Vestas s.r.l.Vestas s.r.l. was fined by the Garante 4,000 EUR for obtaining a single mandatory consent covering different processing purposes. This approach breached data protection rules because consent was not separated by purpose. | IT | Garante | GDPR | €4,000 | ↗ |
| 03 Sept 2014 | Anonymised (HDPA 119/2014)A fine was imposed for the unlawful collection and processing of personal data, including email addresses, and for sending unsolicited marketing emails without subscriber consent. The case concerns breaches of lawful processing requirements and the need for prior consent for marketing communications. | GR | HDPA | ePrivacy | €4,000 | ↗ |
| 02 Jul 2021 | PODEMOS PARTIDO POLÍTICOPODEMOS PARTIDO POLÍTICO was fined by the AEPD for irregularities in its video surveillance system. The cameras excessively captured public space without justification, and proper signage was missing. | ES | AEPD | GDPR | €4,000 | ↗ |
| 23 Oct 2024 | SNOW INK SIERRA NEVADA, S.L.SNOW INK SIERRA NEVADA, S.L. was fined by the AEPD 4,000 EUR for using surveillance cameras that captured public areas, which breached data protection principles. Privacy masks were implemented during the sanctioning process. | ES | AEPD | GDPR | €4,000 | ↗ |
| 01 Feb 2024 | HOGAR LUZ Y GAS S.L.HOGAR LUZ Y GAS S.L. was fined EUR 4,000 by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information, which breaches Article 58.1 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 20 Jun 2024 | Provvedimento del 20 giugno 2024 [10037411]The Garante imposed a fine on a healthcare entity for delays in providing preoperative photographs. The delay affected the complainant's legal position in ongoing proceedings. | IT | Garante | GDPR | €4,000 | ↗ |
| 02 Apr 2015 | Comune di MontefrancoComune di Montefranco was fined EUR 4,000 by the Garante. The authority found that the role of Mercurio service s.r.l. was not properly regulated, although it processed personal data relating to traffic violations without proper authorization. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Jan 2022 | FUNDACIÓN CIPRI GÓMESFUNDACIÓN CIPRI GÓMES was fined EUR 4,000 by the AEPD for failing to provide information on personal data processing to athletes or their guardians. The authority also found unlawful processing of a minor's personal data after the parents had withdrawn him from the gym. | ES | AEPD | GDPR | €4,000 | ↗ |
| 27 May 2021 | Società Cavourese S.p.A.Società Cavourese S.p.A. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned improper handling of personal data related to employee disciplinary proceedings, in breach of the GDPR and national privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 26 Mar 2015 | Comune di Santa NinfaComune di Santa Ninfa was fined EUR 4,000 by the Garante for unlawfully publishing personal data on its institutional website. The data remained available for longer than the legally permitted 15 days, constituting a data protection breach. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Oct 2024 | ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES (procédure simplifiée)CNIL imposed a EUR 4,000 penalty on ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES under a simplified procedure. The case concerns liquidation of an astreinte, indicating that a prior obligation was not fulfilled on time. | FR | CNIL | GDPR | €4,000 | ↗ |
| 30 Jan 2020 | Liceo Nobel di Torre del GrecoLiceo Nobel di Torre del Greco was fined EUR 4,000 by the Garante for publishing a teacher ranking list on its website. The conduct breached GDPR principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Jan 2021 | Istituto Comprensivo Villanova D’AstiIstituto Comprensivo Villanova D’Asti was fined EUR 4,000 by the Garante for publishing personal data online. The disclosed information could reveal health status and economic-social conditions, breaching data minimization and transparency principles. | IT | Garante | GDPR | €4,000 | ↗ |