BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Mar 2008 | Professioni didattiche moderne-P.D.M. s.r.l.P.D.M. s.r.l. was fined for failing to comply with a request to communicate the conformity of personal data processing. The authority found a breach of Article 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 May 2008 | G. & T. Design Comunication s.r.l.G. & T. Design Comunication s.r.l. was fined €4,000 by the Garante for failing to provide the requested information on the acquisition and processing of an email address. The authority treated this as a breach of data protection requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Apr 2015 | avv. Pasquale GiordanoAvv. Pasquale Giordano was fined EUR 4,000 by the Italian data protection authority, Garante. The sanction concerned the disclosure of a client's personal data to the opposing party's lawyer in a divorce proceeding without the client's consent, in breach of Article 23 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Aug 2022 | B.B.B.A lawyer sent personal data without authorization via WhatsApp for professional promotion. The AEPD found a breach of GDPR Articles 6 and 5(1)(f) and imposed a fine of 4,000 EUR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 21 Jan 2016 | Comune di AdriaComune di Adria was fined EUR 4,000 by the Garante for unlawfully disclosing personal data of third parties. The authority sent photographic results to a complainant that contained data relating to other individuals, breaching data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Mar 2026 | ING Bank NV Amsterdam – Sucursala București S.A.The fine was imposed for failing to implement adequate technical and organizational measures to ensure the confidentiality of personal data. As a result, an unauthorized third party received a bank account statement. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 28 Jan 2021 | TRES-F-NETWORK, S.A.UTRES-F-NETWORK, S.A.U was fined by the AEPD 4,000 EUR for sending commercial SMS messages without the recipient's consent and without an existing commercial relationship. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 12 Feb 2026 | Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di MacerataOrdine dei Medici Chirurghi e degli Odontoiatri della Provincia di Macerata was fined EUR 4,000 by the Garante. The authority found breaches of the principles of lawfulness, fairness, transparency, and data minimization. The case indicates non-compliance with core GDPR processing requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Sept 2024 | B.B.B.B.B.B. was fined by the AEPD €4,000 for failing to properly inform individuals about the presence of surveillance cameras. The authority also found the surveillance system disproportionate because it recorded audio and retained images longer than permitted. | ES | AEPD | GDPR | €4,000 | ↗ |
| 03 Mar 2016 | Comune di Ischia di CastroThe Municipality of Comune di Ischia di Castro was fined 4,000 EUR by the Garante for unlawfully publishing personal data of jury members on its online notice board for longer than the legally permitted period. The case concerned a breach of data protection rules and retention limits. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Jun 2015 | Azienda Ospedaliera Ospedale di Circolo Fondazione MacchiAzienda Ospedaliera Ospedale di Circolo Fondazione Macchi was fined by the Garante 4,000 EUR for processing sensitive personal data without obtaining written consent. This breached the Italian Data Protection Code. The case highlights the need for a valid legal basis before processing special-category data. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Jan 2019 | Istituto Statale di Istruzione Superiore “Guglielmo Marconi”Istituto Statale di Istruzione Superiore “Guglielmo Marconi” was fined by the Garante €4,000 for unlawfully processing personal data. The school published teacher rankings on its website that disclosed health information, breaching privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Nov 2024 | UP ROMÂNIA SRLUP ROMÂNIA SRL was fined EUR 4,000 by ANSPDCP for processing employees’ identification and location data during their free time without a legal basis. The authority found breaches of legality, transparency, and data minimization principles. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 25 Feb 2016 | COF Lanzo Hospital SpaCOF Lanzo Hospital Spa was fined by the Garante for failing to respond to an information request concerning the handling of patient medical records. The authority found a breach of Article 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Jan 2021 | CLUB DEPORTIVO RITMO DE ANDALUCÍAThe club was fined by the AEPD 4,000 EUR for failing to adequately inform users about the processing of their personal data. The authority also found that users were not given the opportunity to provide free and voluntary consent for each specific processing purpose. | ES | AEPD | GDPR | €4,000 | ↗ |
| 26 Jul 2017 | Istituto scolastico "A. Mantegna"Istituto scolastico "A. Mantegna" was fined by the Garante for unlawfully publishing students’ personal data, including sensitive information, on its website without a legal basis. The case concerned a breach of lawfulness and data minimization requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Apr 2014 | Comune di CavedineThe Municipality of Cavedine was fined by the Garante 4,000 EUR for publishing personal data online longer than legally permitted. The case concerned a breach of data protection rules and limits on online retention. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Apr 2025 | Comune di Ponte nelle AlpiThe Garante fined Comune di Ponte nelle Alpi 4,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Codice. The case concerned improper personal data processing activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Feb 2020 | Comune di Urago d'OglioComune di Urago d'Oglio was fined EUR 4,000 by the Garante for improper processing and online publication of special-category personal data, including health data. The authority found insufficient legal basis and inadequate transparency toward the data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Aug 2014 | SERVICIOS DE DEPILACION BLOC, S.L.SERVICIOS DE DEPILACION BLOC, S.L. was fined by the AEPD 4,000 EUR for sending unsolicited commercial SMS messages to a former client. The conduct breached Article 21 of the LSSI on marketing communications without prior consent. | ES | AEPD | ePrivacy | €4,000 | ↗ |