BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Nov 2015 | Giuseppina GhezziGiuseppina Ghezzi was fined by the Garante 26,000 EUR for registering 100 phone cards to an unaware third party. The required data protection information was not provided and consent was not obtained, constituting a breach of data protection law. | IT | Garante | GDPR | €26,000 | ↗ |
| 18 Mar 2018 | Cristiano PanepintoCristiano Panepinto was fined €26,000 by the Garante for sending promotional emails without obtaining users’ free and specific consent. The conduct breached Article 130 of the Italian Privacy Code. | IT | Garante | GDPR | €26,000 | ↗ |
| 26 Jul 2018 | Associazione MEVALAUTE ONLUSThe association was fined by the Garante for sending unsolicited PEC communications. The authority found that personal data were processed without consent, in breach of data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |
| 26 Jul 2018 | MEVALUATE ITALIA S.R.L.MEVALUATE ITALIA S.R.L. was fined by the Garante 26,000 EUR for sending promotional emails without obtaining specific consent. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |
| 24 Oct 2013 | Claudio ContiClaudio Conti was fined EUR 26,000 by the Garante for activating 100 phone cards in the name of an unaware third party. Required information was not provided and consent was not obtained, constituting a data protection breach. | IT | Garante | GDPR | €26,000 | ↗ |
| 30 Dec 2022 | Dane anonimowe (K. S.A. z siedzibą w K. ul.)The President of UODO imposed an administrative fine of PLN 27,418 on the company. The sanction concerned failure to provide access to information necessary for the authority to perform its duties. | PL | UODO | GDPR | €5,858 | ↗ |
| 04 Oct 2012 | Abbanoa s.p.a.Abbanoa s.p.a. was fined EUR 28,000 by the Garante for failing to provide the required privacy notice in its video surveillance systems. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €28,000 | ↗ |
| 22 May 2018 | C.R.M. S.r.l.C.R.M. S.r.l. was fined EUR 28,000 for using a biometric system to record employee attendance without prior notification to the Garante. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €28,000 | ↗ |
| 01 Apr 2025 | Dane anonimowe (G. M. prowadzącą działalność gospodarczą pod firmą)UODO imposed an administrative fine of PLN 29,043 on the business operator. The authority found that appropriate technical and organizational measures proportionate to the risk of personal data processing were not implemented, and that their effectiveness was not regularly tested, measured, and assessed. | PL | UODO | GDPR | €6,938 | ↗ |
| 13 Nov 2024 | Sligo County CouncilThe Irish DPC imposed a fine of EUR 29,500 on Sligo County Council in inquiry 07/SIU/2018. The case status is listed as not confirmed. | IE | DPC | GDPR | €29,500 | ↗ |
| 26 Nov 2024 | Dane anonimowe (X. ul.)UODO imposed an administrative fine of PLN 29,684.04 on Dane anonimowe (X. ul.) for breaching Article 33(1) and Article 34(1) and (2) of the GDPR. The authority also ordered the controller to notify the affected data subject about the personal data breach. | PL | UODO | GDPR | €6,886 | ↗ |
| 19 Jan 2023 | Sąd Rejonowy Szczecin-Centrum z siedzibą w Szczecinie przy ul.The UODO imposed an administrative fine of PLN 30,000 on the Szczecin-Centrum District Court. The authority found that appropriate technical and organizational measures were not implemented to match the risk of processing data using portable storage devices. | PL | UODO | GDPR | €6,374 | ↗ |
| 16 May 2023 | Dane anonimowe (Burmistrza Miasta Z.)UODO imposed an administrative fine of PLN 30,000 on the Mayor of City Z. and ordered the processing operations to be brought into compliance with the GDPR. The authority required appropriate technical and organizational measures, including regular testing, measuring, and evaluating their effectiveness to ensure processing security. | PL | UODO | GDPR | €6,687 | ↗ |
| 01 Jan 2023 | THE RED KIWI, S.L.THE RED KIWI, S.L. was fined 30,000 EUR by the AEPD. The breach involved adding clients’ phone numbers to a WhatsApp group without consent, which enabled unauthorized access to personal data. | ES | AEPD | GDPR | €30,000 | ↗ |
| 18 Apr 2022 | SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.The company changed the electricity and gas supplier without the customer's consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD. | ES | AEPD | GDPR | €30,000 | ↗ |
| 09 Sept 2022 | MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD for processing personal data without a lawful basis. The company failed to respond properly to a data access request and incorrectly linked an individual to insurance policies and claims. | ES | AEPD | GDPR | €30,000 | ↗ |
| 25 Oct 2021 | Anonymizováno (ÚOOÚ UOOU-00288/20-21)The entity was fined by the UOOU for sending unsolicited commercial communications by email without prior recipient consent. The conduct breached Czech rules on information society services. | CZ | UOOU | ePrivacy | €1,166 | ↗ |
| 18 Apr 2018 | Consorzio “Marte Euroservice”Consorzio “Marte Euroservice” was fined EUR 30,000 by the Garante for sending promotional emails without recipients’ consent. The company also exposed email addresses to multiple recipients, creating an additional data protection breach. | IT | Garante | GDPR | €30,000 | ↗ |
| 12 Feb 2026 | Sportitalia Società Sportiva Dilettantistica a.r.l.Sportitalia Società Sportiva Dilettantistica a.r.l. was fined EUR 30,000 by the Garante for violations related to the processing of personal data in promotional emails. The authority found that the company did not comply with GDPR requirements in connection with these marketing communications. | IT | Garante | GDPR | €30,000 | ↗ |
| 16 Feb 2012 | Amiat s.p.a.Amiat s.p.a. was fined EUR 30,000 by the Garante for failing to designate Allsystems s.p.a. as a data processor and for not providing the necessary instructions. The authority found that the company did not adopt the minimum security measures required for data processing. | IT | Garante | GDPR | €30,000 | ↗ |