Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Sept 2024COMMUNE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on COMMUNE (procédure simplifiée) and issued an injunction. The decision concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€20,000
10 Jun 2021aiComply S.r.l.aiComply S.r.l. was fined by the Garante in the amount of EUR 20,000 for failing to implement adequate security measures. In particular, it did not use a secure network protocol, which created a risk to the confidentiality and integrity of personal data.ITGaranteGDPR€20,000
05 Oct 2017Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante for publishing a regional council resolution on its website that contained personal evaluations and information about an employee. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
14 Mar 2023Dane anonimowe (Prokuraturę Rejonową w G. z siedzibą w G. przy ul.)UODO imposed an administrative fine of PLN 20,000 on the District Prosecutor's Office in G. The authority found that the entity failed to notify the supervisory authority of a personal data breach without undue delay and did not inform the affected individuals without undue delay.PLUODOGDPR€4,266
22 Jun 2017Adsalsa Italia Publicidad SucursalAdsalsa Italia Publicidad Sucursal was fined EUR 20,000 by the Garante. The authority found that personal data were processed without obtaining separate consent for each purpose, in breach of data protection rules.ITGaranteGDPR€20,000
14 Dec 2017SEMS – Servizi per la mobilità sostenibile S.r.l.SEMS – Servizi per la mobilità sostenibile S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to meet notification obligations linked to the installation of satellite tracking devices in its vehicle fleet, in breach of data protection rules.ITGaranteGDPR€20,000
20 Nov 2024Raiffeisen Bank S.A.Raiffeisen Bank S.A. was fined EUR 20,000 by ANSPDCP for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€20,000
21 Jan 2010Casa di cura privata Di Lorenzo s.p.a.The private clinic Casa di cura privata Di Lorenzo s.p.a. was fined by the Garante for breaching data protection rules. The authority found that it failed to comply with notification obligations under the Italian Privacy Code.ITGaranteGDPR€20,000
01 Oct 2020Università Campus Bio-medico di RomaThe Garante fined Università Campus Bio-medico di Roma 20,000 EUR for a data protection breach. Online medical reports were accessible to other patients, resulting in unauthorized disclosure of sensitive information.ITGaranteGDPR€20,000
13 May 2015ASL Napoli 2 NordASL Napoli 2 Nord was fined 20,000 EUR by the Garante for publishing personal data on its website. The disclosed information could reveal individuals' health status, which breached privacy rules.ITGaranteGDPR€20,000
16 Feb 2017Crabion s.r.l.Crabion s.r.l. was fined by the Garante in the amount of EUR 20,000 for processing genetic data without the required authorization. The case concerns breaches of the rules governing the lawful processing of sensitive personal data.ITGaranteGDPR€20,000
28 Apr 2022Istituto Nazionale Assicurazione Infortuni sul LavoroIstituto Nazionale Assicurazione Infortuni sul Lavoro was fined by the Garante EUR 20,000. The authority found that inadequate technical and organizational measures led to a data breach.ITGaranteGDPR€20,000
01 Feb 2018Transpe S.p.A.Transpe S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to notify the installation of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations.ITGaranteGDPR€20,000
19 Sept 2024ARMURERIE VENDANT SES ARTICLES EN LIGNE ET EN MAGASIN (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ARMURERIE VENDANT SES ARTICLES EN LIGNE ET EN MAGASIN. The case was handled under a simplified procedure.FRCNILGDPR€20,000
24 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONAL was fined by the AEPD EUR 20,000 for sending unsolicited commercial communications by email. The conduct breached Article 21.1 of the LSSI and constituted unlawful marketing communication.ESAEPDePrivacy€20,000
04 Aug 2025Azienda Ospedaliero Universitaria CareggiAzienda Ospedaliero Universitaria Careggi was fined by the Garante EUR 20,000 for violations related to the management of electronic health records. The authority found non-compliance with data protection requirements.ITGaranteGDPR€20,000
13 May 2021ATS di Bergamo, Agenzia di Tutela della saluteATS di Bergamo was fined by the Garante 20,000 EUR for violations involving the improper handling of sensitive health data. The case concerned the use of email to transmit data, which did not provide an adequate level of protection.ITGaranteGDPR€20,000
01 Apr 2025EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.The AEPD fined EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A. 20,000 EUR for publishing unnecessary personal data in a news article. A video in the article revealed the identity of a minor, which was considered disproportionate and unnecessary for the informational purpose.ESAEPDGDPR€20,000
08 Mar 2018Riacetech S.r.l.Riacetech S.r.l. was fined for failing to notify the Garante about the installation of a biometric data processing system for employees. The case concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€20,000
03 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD EUR 20,000 for continuing to send marketing emails to a user who had repeatedly requested to unsubscribe. The authority found this to be a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€20,000