BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Dec 2014 | Itala s.p.aItala s.p.a was fined EUR 4,000 by the Garante for processing personal data related to job applications without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Mar 2021 | ALAVA NORTE, S.L.ALAVA NORTE, S.L. was fined by the AEPD in the amount of 4,000 EUR for installing surveillance cameras without sufficient justification. The cameras captured both public and private spaces, which breached data protection principles. | ES | AEPD | GDPR | €4,000 | ↗ |
| 17 Mar 2016 | Università degli studi di FoggiaUniversità degli studi di Foggia was fined 4,000 EUR by the Garante for unlawfully disclosing health-related data to third parties. The authority found that the disclosure lacked an appropriate legal basis and breached privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Sept 2025 | Comune di PazzanoThe Garante imposed a fine of 3,960 EUR on Comune di Pazzano for failing to meet data protection obligations. The case concerned, among other issues, the improper provision of the Data Protection Officer’s contact details and other GDPR requirements. | IT | Garante | GDPR | €3,960 | ↗ |
| 28 May 2026 | Action Fit di MilanoThe Garante fined Action Fit di Milano EUR 3,930 for sending unsolicited commercial emails to a customer without consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €3,930 | ↗ |
| 13 Jan 2015 | LEROY MERLIN ESPAÑA S.L.U.LEROY MERLIN ESPAÑA S.L.U. was fined by the AEPD EUR 3,900 for sending unsolicited commercial SMS messages without recipient consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,900 | ↗ |
| 13 Jun 2022 | SOCIETE D'ENTRETIEN ET REPARATION DE VEHICULESCNIL imposed a liquidation of the penalty payment against SOCIETE D'ENTRETIEN ET REPARATION DE VEHICULES in the amount of EUR 3,900. The measure relates to failure to comply with a prior obligation within the required deadline. | FR | CNIL | GDPR | €3,900 | ↗ |
| 10 Oct 2016 | ROCK INTERNET S.L.ROCK INTERNET S.L. was fined 3,800 EUR by the AEPD. The case concerned sending unsolicited commercial emails without recipient consent, in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €3,800 | ↗ |
| 13 Dec 2022 | Anonymisé (CNPD decision-21-fr-2022)The company was fined EUR 3,700 by the CNPD for breaching the transparency obligations under Article 12(1) of the GDPR. The authority found that information was not sufficiently accessible to users. | LU | CNPD | GDPR | €3,700 | ↗ |
| 13 Dec 2022 | Anonymisé (CNPD decision-24-fr-2022)The entity failed to meet GDPR transparency obligations, particularly regarding the accessibility and comprehensibility of information provided to data subjects. CNPD imposed a fine of EUR 3,700. | LU | CNPD | GDPR | €3,700 | ↗ |
| 27 Mar 2025 | Comune di MilazzoThe Garante fined the Comune di Milazzo €3,600 for failing to provide adequate data protection information on its website. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €3,600 | ↗ |
| 15 Jul 2021 | Anonymisé (CNPD decision-27-fr-2021)The company did not meet GDPR requirements to inform individuals about data processing, especially in relation to video surveillance and employee notices. CNPD treated this as a breach of the information obligations owed to data subjects. | LU | CNPD | GDPR | €3,500 | ↗ |
| 19 Feb 2015 | VUELING AIRLINES S.A.VUELING AIRLINES S.A. was fined by the AEPD EUR 3,500 for sending unsolicited commercial emails to the complainant. The conduct breached Article 21.1 of the LSSI on marketing communications without prior consent. | ES | AEPD | ePrivacy | €3,500 | ↗ |
| 23 May 2024 | Ordine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di MateraOrdine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di Matera was fined 3,500 EUR by the Garante. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization, in the handling of personal data. | IT | Garante | GDPR | €3,500 | ↗ |
| 03 Sept 2019 | ЧСИThe CPDP fined a private bailiff (ЧСИ) for failing to provide a data subject with access to personal data collected through video surveillance. The authority found a breach of Article 12 GDPR. | BG | CPDP | GDPR | €1,790 | ↗ |
| 17 Apr 2026 | Ausl ModenaAusl Modena was fined by the Garante in the amount of 3,500 EUR for creating duplicate patient records. The case involved processing health data without proper transparency and compliance with data protection rules. | IT | Garante | GDPR | €3,500 | ↗ |
| 01 Jan 2024 | MAD COOL FESTIVAL, S.L.MAD COOL FESTIVAL, S.L. was fined 3,500 EUR by the AEPD for a data breach on its website. The incident exposed users’ personal data, indicating non-compliance with GDPR Articles 5(1)(f) and 32. | ES | AEPD | GDPR | €3,500 | ↗ |
| 10 Mar 2022 | Anonymisé (CNPD decision-07-fr-2022)The CNPD found that Société A breached the GDPR by failing to comply with data minimization, retention limitation, and information provision requirements. The case concerned improper personal data processing in relation to compliance obligations. | LU | CNPD | GDPR | €3,500 | ↗ |
| 01 Jan 2016 | HAPPY SOCIAL MEDIA, LTDHAPPY SOCIAL MEDIA, LTD was fined by the AEPD EUR 3,400 for sending unsolicited marketing emails. The authority found that the messages did not include a simple opt-out mechanism, which breached the LSSI. | ES | AEPD | ePrivacy | €3,400 | ↗ |
| 19 Feb 2016 | Asociación de Empresarios de Tecnologías de la Información y Comunicaciones de Andalucía (ETICOM)ETICOM was fined €3,400 by the AEPD for sending unsolicited commercial emails without prior consent from recipients. The authority also found that the messages did not include a simple opt-out mechanism, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,400 | ↗ |