Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Apr 2021Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante in the amount of 4,000 EUR for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization because personal data remained accessible online for an extended period.ITGaranteGDPR€4,000
30 Jan 2025SOCIETE DE COURTAGE EN ENERGIE (procédure simplifiée)The CNIL used a simplified procedure against SOCIETE DE COURTAGE EN ENERGIE and ordered 4,000 EUR in connection with the liquidation of an astreinte. The case concerns failure to comply with a prior obligation subject to a coercive penalty.FRCNILGDPR€4,000
12 Sept 2024Ordine delle Professioni Infermieristiche di TriesteThe Garante fined the Ordine delle Professioni Infermieristiche di Trieste EUR 4,000 for breaches of data protection rules. The case involved improper disclosure of data to third parties and a failure to provide adequate information to data subjects.ITGaranteGDPR€4,000
16 May 2019SOGIMA S.r.l.SOGIMA S.r.l. was fined by the Garante for allowing unauthorized access to personal data on its website. The breach involved names, email addresses, and bank details without the consent of the data subjects.ITGaranteGDPR€4,000
29 Oct 2020Borgo Fonte Scura s.r.l.Borgo Fonte Scura s.r.l. was fined by the Garante 4,000 EUR for failing to provide proper data protection information to individuals, including employees, about the use of a video surveillance system at its premises. The authority found that the required privacy notice obligations were not met.ITGaranteGDPR€4,000
07 Aug 2024EXPANSION CONSULTING 2020, S.L.EXPANSION CONSULTING 2020, S.L. was fined by the AEPD in the amount of €4,000 for failing to provide access to personal data and the information requested by the data protection authority. The case concerned non-compliance with Article 58(1) GDPR.ESAEPDGDPR€4,000
07 Apr 2016Comune di LizzanoComune di Lizzano was fined by the Garante for publishing personal data, including health information about a minor, on its online notice board. The authority found this to be a breach of data protection rules.ITGaranteGDPR€4,000
18 Nov 201524 Media s.r.l.24 Media s.r.l. was fined EUR 4,000 by the Garante. The authority found that the company required mandatory consent for purposes beyond the original data collection intent, including promotional communications and sharing data with third parties.ITGaranteGDPR€4,000
23 Jun 2025Vodafone Romania S.A.Vodafone Romania S.A. was fined EUR 4,000 by ANSPDCP for GDPR violations. The investigation was completed in May 2025.ROANSPDCPGDPR€4,000
10 Nov 2022Comune di Villafranca di VeronaThe Comune di Villafranca di Verona was fined 4,000 EUR by the Garante for breaching data protection principles. The authority found that personal data linked to a sensitive private matter was improperly disclosed online.ITGaranteGDPR€4,000
14 Apr 2021Avalos Consultores, S.L.Avalos Consultores, S.L. was fined by the AEPD 4,000 EUR for transferring personal data to another company without the data subject's consent. The authority found this breached Article 6 of the GDPR.ESAEPDGDPR€4,000
02 Jul 2020Regione CampaniaRegione Campania was fined EUR 4,000 by the Garante. The authority found a breach of the data minimization principle after personal data was published online without a proper legal basis.ITGaranteGDPR€4,000
03 Feb 2025CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe labor union CSI-CSIF was fined EUR 4,000 by the AEPD for failing to adequately protect personal data during a voting process. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality.ESAEPDGDPR€4,000
02 Apr 2015Regione CampaniaThe Garante fined Regione Campania EUR 4,000 for failing to provide requested information related to a disciplinary procedure. The authority found a breach of data protection rules.ITGaranteGDPR€4,000
04 Jun 2015Centrex srlCentrex srl was fined by the Garante for conducting telemarketing activities without prior informed consent from individuals. The case involved promotional calls to numbers listed in the public opposition registry.ITGaranteGDPR€4,000
20 Nov 2008XYThe entity was fined by the Garante in the amount of 4,000 EUR for failing to respond to a request for information concerning unsolicited promotional emails. The case concerned non-compliance with data protection obligations.ITGaranteGDPR€4,000
31 Jan 2019Istituto Scolastico Superiore “Andrea Mantegna”Istituto Scolastico Superiore “Andrea Mantegna” was fined by the Garante €4,000 for unlawfully publishing personal data on its institutional website. The disclosure included health information about teaching staff, which is sensitive personal data.ITGaranteGDPR€4,000
17 Jul 2023HSSERVICE LIZCON SOLUTIONS, S.L.HSSERVICE LIZCON SOLUTIONS, S.L. was fined by the AEPD EUR 4,000 for failing to provide information about personal data processing when a customer brought in a TV for repair. The authority also found that the company’s website lacked the required data protection information.ESAEPDGDPR€4,000
24 Jul 2014Intermatica Holding s.r.l.Intermatica Holding s.r.l. was fined by the Italian Garante for failing to adopt minimum security measures. The company used passwords of seven characters instead of the required eight, breaching Article 33 of the Italian Data Protection Code.ITGaranteGDPR€4,000
26 Sept 2024CI & DI Food s.r.l.CI & DI Food s.r.l. was fined by the Garante 4,000 EUR for failing to respond to an employee’s request to access personal data related to employment. The request included work attendance records.ITGaranteGDPR€4,000