BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 May 2015 | Comune di BagnoregioComune di Bagnoregio was fined by the Garante for unlawfully publishing personal data on its website. The conduct breached the conditions set out in the Italian data protection code. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Jul 2025 | HAMMERHOJ DESIGN, S.L.HAMMERHOJ DESIGN, S.L. was fined EUR 4,000 by the AEPD for publishing images of minors on Facebook without consent. The authority found this conduct to be in breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 29 Feb 2024 | CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on CHIRURGIEN DENTISTE under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision. | FR | CNIL | GDPR | €4,000 | ↗ |
| 09 Oct 2014 | Comune di Lamezia TermeThe Municipality of Lamezia Terme was fined 4,000 EUR by the Garante. The authority found that personal data, including names, tax codes, and IBANs, had been published on its website without a legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Apr 2026 | Istituto “Ancelle della Compagnia della Regina dei Gigli”The Garante fined the school EUR 4,000 for processing students’ personal data without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jul 2021 | Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5)Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5) was fined EUR 4,000 by the Garante for violations related to the processing of personal data, including health data, during the COVID-19 pandemic. The case concerned improper handling of sensitive data in the context of pandemic-related activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 19 Sept 2013 | dott. Luigi Ventronedott. Luigi Ventrone was fined for failing to respond to requests for information concerning the processing of personal data in connection with a complaint by Ms. Ilaria Corsale. The authority found a breach of Article 157 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 08 Apr 2021 | Anonymisé (CNPD decision-11-fr-2021)The company breached the GDPR by failing to respect data retention limits, by not adequately informing employees about data processing, and by applying insufficient security measures. The CNPD decision of 8 April 2021 resulted in a fine of 4,000 EUR. | LU | CNPD | GDPR | €4,000 | ↗ |
| 28 Apr 2026 | SIPHONE 2020, S.L.SIPHONE 2020, S.L. was fined by the AEPD 4,000 EUR for operating a video surveillance system that also recorded audio. Employees were not informed and did not consent, which breached privacy and data protection rules. | ES | AEPD | GDPR | €4,000 | ↗ |
| 04 Feb 2020 | BAZAR SUSANABAZAR SUSANA was fined EUR 4,000 by the AEPD for improperly obtaining and disseminating personal images from a video surveillance system. The case concerns a breach of data protection rules and the unlawful processing of CCTV footage. | ES | AEPD | GDPR | €4,000 | ↗ |
| 27 Mar 2025 | Istituto di Istruzione Superiore “P. 96012510796The Garante imposed a fine on an educational institution for breaches of GDPR Articles 5, 6, and 9 in connection with data processing activities. The case concerned deficiencies in the lawful basis and principles of processing, including special-category data. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 Apr 2016 | CityFan s.r.l.CityFan s.r.l. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned the failure to formally designate employees and collaborators as data processors under Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Mar 2023 | Ministero dell’InternoMinistero dell’Interno was fined EUR 4,000 by the Garante for unlawfully communicating personal data, including health information, to the police without proper justification. The case concerned a breach of lawfulness and purpose limitation requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Mar 2014 | Paolo ZaniniPaolo Zanini was fined EUR 4,000 by the Garante for sending unsolicited promotional faxes. The conduct breached data protection rules and the requirement for prior consent for marketing communications. | IT | Garante | GDPR | €4,000 | ↗ |
| 11 Oct 2024 | ORTHOPHONISTE (procédure simplifiée)The CNIL imposed a 4,000 EUR penalty on ORTHOPHONISTE (procédure simplifiée) in connection with the liquidation of an astreinte. The case concerns compliance with a prior obligation under the data protection authority’s supervision. | FR | CNIL | GDPR | €4,000 | ↗ |
| 04 Jul 2013 | Comune di CiampinoThe Municipality of Ciampino was fined EUR 4,000 by the Garante for publishing on its website a list containing personal data of individuals eligible to serve as polling station scrutineers. The publication was made without an appropriate legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Apr 2023 | Università degli studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined EUR 4,000 by the Garante for improperly disclosing a complainant’s personal data to all Italian universities. The disclosure also included data relating to criminal offenses, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 20 Dec 2024 | English Home SRLEnglish Home SRL was fined €4,000 by ANSPDCP for violating Article 21 of the GDPR. The case concerned failure to respect the data subject’s right to object to processing. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 09 Jun 2016 | Comune di LevantoThe Municipality of Levanto was fined EUR 4,000 by the Garante for publishing on its website a list of candidates for regional contributions. The disclosure of personal data lacked sufficient legal basis and breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 03 May 2022 | Megareduceri TV S.R.L.Megareduceri TV S.R.L. was fined by ANSPDCP in the amount of EUR 4,000 for failing to provide requested information to the supervisory authority. The breach concerned obligations under the GDPR. | RO | ANSPDCP | GDPR | €4,000 | ↗ |