BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2022 | MUXERS CONCEPT, S.L.MUXERS CONCEPT, S.L. was fined EUR 20,000 by the AEPD for installing an unauthorized audio recording system in employee areas. The authority found this conduct to be in breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 30 Oct 2014 | Planetcall s.r.l.Planetcall s.r.l. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned promotional phone calls made without the individuals’ prior consent, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Jul 2022 | Acqua Novara.VCO S.p.a.Acqua Novara.VCO S.p.a. was fined EUR 20,000 by the Garante for breaches related to the processing of personal data. The case concerned confidentiality and the risks arising from handling sensitive data in a workplace context. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Jul 2017 | Aria S.p.a.Aria S.p.a. was fined 20,000 EUR by the Garante. The authority found a data protection breach for failing to designate employees as data processors. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jun 2023 | AUSL Toscana Sud EstThe Garante fined AUSL Toscana Sud Est 20,000 EUR for the unlawful dissemination of a patient's health data. The authority found a breach of data protection principles. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Nov 2024 | Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 20,000 EUR for publishing employees’ personal data without a legal basis. The disclosure included details on additional payments, sickness absences, and union rights, breaching the GDPR and the national privacy code. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Nov 2025 | GROUPEMENT D'INTERET ECONOMIQUE (GIE) EXERCANT UNE ACTIVITE D'ORGANISATION, DE DEVELOPPEMENT ET DE PROMOTION DE CENTRES COMMERCIAUX (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on a GIE engaged in the organization, development, and promotion of shopping centers. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 08 Mar 2018 | Tekne Progetti s.r.l.Tekne Progetti s.r.l. was fined for failing to respond to an information request from the Garante concerning its data processing activities. The conduct was found to violate Article 164 of the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 11 Apr 2024 | Istituto Nazionale Previdenza Sociale - INPSThe Italian Data Protection Authority fined INPS EUR 20,000 for violating data protection principles. The case concerned the improper handling of candidates’ personal data in a public competition. | IT | Garante | GDPR | €20,000 | ↗ |
| 03 May 2018 | Ordinanza ingiunzione - 3 maggio 2018 [9023941]A fine of EUR 20,000 was imposed for failing to notify the Garante about the processing of geolocation data collected through GPS devices. The case concerns a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Feb 2021 | SERVICIOS LOGÍSTICOS MARTORELL SIGLO XXI, S.L.The company was fined by the AEPD for deploying a biometric fingerprint system for employee attendance control without carrying out a data protection impact assessment. The authority found this to be a breach of Article 35 GDPR because the processing involved biometric data requiring prior risk assessment. | ES | AEPD | GDPR | €20,000 | ↗ |
| 16 May 2018 | Conafi Prestitò s.p.a.Conafi Prestitò s.p.a. was fined by the Garante for failing to notify certain data processing activities related to loan management. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 25 Sept 2025 | Azienda Ospedaliero Universitaria di FerraraAzienda Ospedaliero Universitaria di Ferrara was fined EUR 20,000 by the Garante for irregularities in the handling of personal data in its health dossier system. The authority found that the organization failed to implement adequate measures to protect data privacy. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Nov 2022 | ING Bank NV Amsterdam Sucursala BucureștiANSPDCP completed an investigation into ING Bank NV Amsterdam Bucharest Branch and found a breach of GDPR provisions. The case was opened following a data breach notification submitted by the controller. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 14 Sept 2023 | Shardana Working Soc. Coop. a r.l.Shardana Working Soc. Coop. a r.l. was fined by the Garante 20,000 EUR for failing to fully comply with data access requests. The authority found a breach of Article 15 GDPR. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Feb 2017 | Sisal S.p.A.Sisal S.p.A. was fined by the Garante in the amount of EUR 20,000 for installing a geolocation system on smartphones provided to employees without proper compliance with data protection rules. The case concerned the processing of location data in an employment context and insufficient legal safeguards. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Apr 2025 | Anonymised (IDPC 0476_001)The IDPC imposed a EUR 20,000 fine on Anonymised (IDPC 0476_001) for breaches of several GDPR provisions. The case concerned lawfulness, fairness and transparency, purpose limitation, information duties, the right to rectification, and the appointment of a data protection officer. | MT | IDPC | GDPR | €20,000 | ↗ |
| 06 Oct 2023 | SOCIETE DE CONSEILS EN SYSTEMES ET LOGICIELS INFORMATIQUES (procédure simplifiée)CNIL imposed a fine of EUR 20,000 on SOCIETE DE CONSEILS EN SYSTEMES ET LOGICIELS INFORMATIQUES under a simplified procedure. The decision concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €20,000 | ↗ |
| 21 Mar 2018 | Azienda Sanitaria Locale Napoli 2 NordAzienda Sanitaria Locale Napoli 2 Nord was fined by the Garante for allowing personal data of registered users to be accessed and modified by anyone through its institutional website. The case concerned inadequate protection of personal data and non-compliance with data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jan 2020 | RADIOTELEVISIÓN DEL PRINCIPADO DE ASTURIASRADIOTELEVISIÓN DEL PRINCIPADO DE ASTURIAS was fined by the AEPD 20,000 EUR for retaining and processing images without a proper legal basis. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €20,000 | ↗ |