BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Mar 2015 | Liceo Statale "Farnesina"Liceo Statale Farnesina was fined EUR 4,000 by the Garante for unlawfully publishing lists of student names on its institutional website without a legal basis. The conduct breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Sept 2024 | GESTIÓN DE VENTAS IBERIA S.L.GESTIÓN DE VENTAS IBERIA S.L. was fined 4,000 EUR by the AEPD for failing to provide access as required under Article 58.1 of the GDPR. The case concerns non-compliance with a supervisory authority request. | ES | AEPD | GDPR | €4,000 | ↗ |
| 15 May 2013 | You & Me di Borille FabrizoYou & Me di Borille Fabrizo was fined EUR 4,000 by the Italian Garante. The sanction concerned the failure to respond to requests for information about surveillance cameras, which breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Nov 2025 | SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL ET AIDE A LA GESTION AUPRES DE CLUBS DE SPORTS SUBAQUATIQUES (procédure simplifiée)CNIL imposed an administrative fine of 4,000 EUR on SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL ET AIDE A LA GESTION AUPRES DE CLUBS DE SPORTS SUBAQUATIQUES under a simplified procedure. The decision concerns a regulatory breach handled in administrative proceedings. | FR | CNIL | GDPR | €4,000 | ↗ |
| 20 Mar 2008 | MO.MA. s.r.l.MO.MA. s.r.l. was fined by the Garante for failing to comply with a request to confirm the conformity of personal data processing. The authority found a breach of Article 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 02 Feb 2019 | XX S.r.l.The company was fined EUR 4,000 by the Garante. The authority found that it processed personal data for promotional purposes without obtaining valid consent from the data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Feb 2020 | Liceo Artistico Statale di NapoliLiceo Artistico Statale di Napoli was fined EUR 4,000 by the Garante for publishing an outdated teacher ranking on its institutional website. The authority found this breached GDPR principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Jul 2016 | Sorec s.r.l.Sorec s.r.l. was fined EUR 4,000 by the Garante for inadequate password security in its data processing systems. The case concerned non-compliance with data protection requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Feb 2014 | Genesis Consulting s.r.l.Genesis Consulting s.r.l. was fined EUR 4,000 by the Garante. The authority found that personal data collected through a website form were used for marketing purposes without adequate notice and without specific consent. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Jan 2021 | STOCKHUNTERS, S.L.STOCKHUNTERS, S.L. was fined EUR 4,000 by the AEPD for failing to comply with GDPR Article 13. The authority found that the website privacy policy did not meet the required information standards. | ES | AEPD | GDPR | €4,000 | ↗ |
| 13 Dec 2018 | Ministero dell’Istruzione, dell’Università e della Ricerca – Ufficio Scolastico Regionale per la Lombardia – Ufficio III – Ambito territoriale di BergamoThe Ministry of Education’s regional office in Bergamo was fined for unlawfully publishing personal data related to disciplinary proceedings on its website. The authority found a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Apr 2015 | Comune di CastelplanioComune di Castelplanio was fined by the Garante for publishing personal data, including names, on its online notice board. This conduct breached privacy regulations. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Oct 2019 | Partito Democratico, Coordinamento Metropolitano di FirenzePartito Democratico, Coordinamento Metropolitano di Firenze was fined by the Garante €4,000 for a data protection breach. The incident resulted from a cyber attack on its website that exposed personal data of party members. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Jun 2014 | Ministero della GiustiziaThe Ministry of Justice was fined for unlawfully publishing personal data on its institutional website without a legal basis. The disclosure included names, dates of birth, and tax codes, in breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 08 Oct 2015 | Amministrazione provinciale di PordenoneAmministrazione provinciale di Pordenone was fined 4,000 EUR by the Garante. The authority found that the annual Security Programmatic Document was not updated by the required deadline, breaching data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 May 2015 | Comune di GenovaThe Municipality of Genoa was fined by the Garante for unlawfully keeping personal and judicial data on its institutional website beyond the legally permitted period. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 May 2024 | SOCIETE AYANT POUR ACTIVITE LE COMMERCE DE DETAIL OPTIQUE (procédure simplifiée)The CNIL ordered liquidation of a penalty payment of EUR 4,000 against SOCIETE AYANT POUR ACTIVITE LE COMMERCE DE DETAIL OPTIQUE. The measure relates to non-compliance with a prior obligation in simplified proceedings. | FR | CNIL | GDPR | €4,000 | ↗ |
| 12 May 2023 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union sent an email containing personal data of election officials and representatives without their consent. AEPD found this to be a breach of data protection rules and imposed a 4,000 EUR fine. | ES | AEPD | GDPR | €4,000 | ↗ |
| 28 Jul 2016 | Comune di San Lorenzo NuovoComune di San Lorenzo Nuovo was fined EUR 4,000 by the Garante for unlawfully publishing the list of court jurors online for longer than legally permitted. This resulted in unauthorized disclosure of personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 May 2022 | Concordia Capital IFN S.A.The company was fined for installing audio-video cameras in employee offices. The authority found that this monitoring violated data protection rules. | RO | ANSPDCP | GDPR | €4,000 | ↗ |