BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Apr 2021 | Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante in the amount of 4,000 EUR for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization because personal data remained accessible online for an extended period. | IT | Garante | GDPR | €4,000 | ↗ |
| 30 Jan 2025 | SOCIETE DE COURTAGE EN ENERGIE (procédure simplifiée)The CNIL used a simplified procedure against SOCIETE DE COURTAGE EN ENERGIE and ordered 4,000 EUR in connection with the liquidation of an astreinte. The case concerns failure to comply with a prior obligation subject to a coercive penalty. | FR | CNIL | GDPR | €4,000 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di TriesteThe Garante fined the Ordine delle Professioni Infermieristiche di Trieste EUR 4,000 for breaches of data protection rules. The case involved improper disclosure of data to third parties and a failure to provide adequate information to data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 May 2019 | SOGIMA S.r.l.SOGIMA S.r.l. was fined by the Garante for allowing unauthorized access to personal data on its website. The breach involved names, email addresses, and bank details without the consent of the data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Oct 2020 | Borgo Fonte Scura s.r.l.Borgo Fonte Scura s.r.l. was fined by the Garante 4,000 EUR for failing to provide proper data protection information to individuals, including employees, about the use of a video surveillance system at its premises. The authority found that the required privacy notice obligations were not met. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 Aug 2024 | EXPANSION CONSULTING 2020, S.L.EXPANSION CONSULTING 2020, S.L. was fined by the AEPD in the amount of €4,000 for failing to provide access to personal data and the information requested by the data protection authority. The case concerned non-compliance with Article 58(1) GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 07 Apr 2016 | Comune di LizzanoComune di Lizzano was fined by the Garante for publishing personal data, including health information about a minor, on its online notice board. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Nov 2015 | 24 Media s.r.l.24 Media s.r.l. was fined EUR 4,000 by the Garante. The authority found that the company required mandatory consent for purposes beyond the original data collection intent, including promotional communications and sharing data with third parties. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Jun 2025 | Vodafone Romania S.A.Vodafone Romania S.A. was fined EUR 4,000 by ANSPDCP for GDPR violations. The investigation was completed in May 2025. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 10 Nov 2022 | Comune di Villafranca di VeronaThe Comune di Villafranca di Verona was fined 4,000 EUR by the Garante for breaching data protection principles. The authority found that personal data linked to a sensitive private matter was improperly disclosed online. | IT | Garante | GDPR | €4,000 | ↗ |
| 14 Apr 2021 | Avalos Consultores, S.L.Avalos Consultores, S.L. was fined by the AEPD 4,000 EUR for transferring personal data to another company without the data subject's consent. The authority found this breached Article 6 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 02 Jul 2020 | Regione CampaniaRegione Campania was fined EUR 4,000 by the Garante. The authority found a breach of the data minimization principle after personal data was published online without a proper legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 03 Feb 2025 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe labor union CSI-CSIF was fined EUR 4,000 by the AEPD for failing to adequately protect personal data during a voting process. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality. | ES | AEPD | GDPR | €4,000 | ↗ |
| 02 Apr 2015 | Regione CampaniaThe Garante fined Regione Campania EUR 4,000 for failing to provide requested information related to a disciplinary procedure. The authority found a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Jun 2015 | Centrex srlCentrex srl was fined by the Garante for conducting telemarketing activities without prior informed consent from individuals. The case involved promotional calls to numbers listed in the public opposition registry. | IT | Garante | GDPR | €4,000 | ↗ |
| 20 Nov 2008 | XYThe entity was fined by the Garante in the amount of 4,000 EUR for failing to respond to a request for information concerning unsolicited promotional emails. The case concerned non-compliance with data protection obligations. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Jan 2019 | Istituto Scolastico Superiore “Andrea Mantegna”Istituto Scolastico Superiore “Andrea Mantegna” was fined by the Garante €4,000 for unlawfully publishing personal data on its institutional website. The disclosure included health information about teaching staff, which is sensitive personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Jul 2023 | HSSERVICE LIZCON SOLUTIONS, S.L.HSSERVICE LIZCON SOLUTIONS, S.L. was fined by the AEPD EUR 4,000 for failing to provide information about personal data processing when a customer brought in a TV for repair. The authority also found that the company’s website lacked the required data protection information. | ES | AEPD | GDPR | €4,000 | ↗ |
| 24 Jul 2014 | Intermatica Holding s.r.l.Intermatica Holding s.r.l. was fined by the Italian Garante for failing to adopt minimum security measures. The company used passwords of seven characters instead of the required eight, breaching Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 26 Sept 2024 | CI & DI Food s.r.l.CI & DI Food s.r.l. was fined by the Garante 4,000 EUR for failing to respond to an employee’s request to access personal data related to employment. The request included work attendance records. | IT | Garante | GDPR | €4,000 | ↗ |