BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Sept 2024 | COMMUNE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on COMMUNE (procédure simplifiée) and issued an injunction. The decision concerns a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €20,000 | ↗ |
| 10 Jun 2021 | aiComply S.r.l.aiComply S.r.l. was fined by the Garante in the amount of EUR 20,000 for failing to implement adequate security measures. In particular, it did not use a secure network protocol, which created a risk to the confidentiality and integrity of personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Oct 2017 | Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante for publishing a regional council resolution on its website that contained personal evaluations and information about an employee. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Mar 2023 | Dane anonimowe (Prokuraturę Rejonową w G. z siedzibą w G. przy ul.)UODO imposed an administrative fine of PLN 20,000 on the District Prosecutor's Office in G. The authority found that the entity failed to notify the supervisory authority of a personal data breach without undue delay and did not inform the affected individuals without undue delay. | PL | UODO | GDPR | €4,266 | ↗ |
| 22 Jun 2017 | Adsalsa Italia Publicidad SucursalAdsalsa Italia Publicidad Sucursal was fined EUR 20,000 by the Garante. The authority found that personal data were processed without obtaining separate consent for each purpose, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Dec 2017 | SEMS – Servizi per la mobilità sostenibile S.r.l.SEMS – Servizi per la mobilità sostenibile S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to meet notification obligations linked to the installation of satellite tracking devices in its vehicle fleet, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Nov 2024 | Raiffeisen Bank S.A.Raiffeisen Bank S.A. was fined EUR 20,000 by ANSPDCP for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 21 Jan 2010 | Casa di cura privata Di Lorenzo s.p.a.The private clinic Casa di cura privata Di Lorenzo s.p.a. was fined by the Garante for breaching data protection rules. The authority found that it failed to comply with notification obligations under the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Oct 2020 | Università Campus Bio-medico di RomaThe Garante fined Università Campus Bio-medico di Roma 20,000 EUR for a data protection breach. Online medical reports were accessible to other patients, resulting in unauthorized disclosure of sensitive information. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 May 2015 | ASL Napoli 2 NordASL Napoli 2 Nord was fined 20,000 EUR by the Garante for publishing personal data on its website. The disclosed information could reveal individuals' health status, which breached privacy rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Feb 2017 | Crabion s.r.l.Crabion s.r.l. was fined by the Garante in the amount of EUR 20,000 for processing genetic data without the required authorization. The case concerns breaches of the rules governing the lawful processing of sensitive personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 28 Apr 2022 | Istituto Nazionale Assicurazione Infortuni sul LavoroIstituto Nazionale Assicurazione Infortuni sul Lavoro was fined by the Garante EUR 20,000. The authority found that inadequate technical and organizational measures led to a data breach. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Feb 2018 | Transpe S.p.A.Transpe S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to notify the installation of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Sept 2024 | ARMURERIE VENDANT SES ARTICLES EN LIGNE ET EN MAGASIN (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ARMURERIE VENDANT SES ARTICLES EN LIGNE ET EN MAGASIN. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 24 Nov 2015 | VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONAL was fined by the AEPD EUR 20,000 for sending unsolicited commercial communications by email. The conduct breached Article 21.1 of the LSSI and constituted unlawful marketing communication. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 04 Aug 2025 | Azienda Ospedaliero Universitaria CareggiAzienda Ospedaliero Universitaria Careggi was fined by the Garante EUR 20,000 for violations related to the management of electronic health records. The authority found non-compliance with data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 May 2021 | ATS di Bergamo, Agenzia di Tutela della saluteATS di Bergamo was fined by the Garante 20,000 EUR for violations involving the improper handling of sensitive health data. The case concerned the use of email to transmit data, which did not provide an adequate level of protection. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Apr 2025 | EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.The AEPD fined EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A. 20,000 EUR for publishing unnecessary personal data in a news article. A video in the article revealed the identity of a minor, which was considered disproportionate and unnecessary for the informational purpose. | ES | AEPD | GDPR | €20,000 | ↗ |
| 08 Mar 2018 | Riacetech S.r.l.Riacetech S.r.l. was fined for failing to notify the Garante about the installation of a biometric data processing system for employees. The case concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 03 Nov 2015 | VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD EUR 20,000 for continuing to send marketing emails to a user who had repeatedly requested to unsubscribe. The authority found this to be a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |