BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Dec 2012 | Wire s.r.l.Wire s.r.l. was fined by the Garante in the amount of EUR 32,000 for making pre-recorded electoral propaganda calls without prior, specific, and informed consent from the recipients. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 19 Oct 2017 | Grant Change s.r.l.Grant Change s.r.l. was fined €32,000 by the Italian data protection authority, Garante. The penalty concerned the sending of promotional SMS messages and emails without valid consent from recipients, in breach of data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 04 May 2017 | Easy C@ll s.r.l.Easy C@ll s.r.l. was fined EUR 32,000 by the Garante for making unsolicited promotional calls to individuals listed in the public opt-out register. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 11 Jun 2015 | Banca Nazionale del Lavoro S.p.a.Banca Nazionale del Lavoro S.p.a. was fined by the Garante 32,000 EUR for processing personal data without first informing the data subjects and without obtaining their consent. The case concerns a breach of core notice and consent obligations in personal data processing. | IT | Garante | GDPR | €32,000 | ↗ |
| 31 May 2017 | Unit Contact s.r.l.Unit Contact s.r.l. was fined €32,000 by the Italian authority Garante. The case concerned unsolicited promotional calls made without the required information notice and without obtaining consent, in breach of data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 20 Nov 2014 | Aimon s.r.l.Aimon s.r.l. was fined EUR 32,000 by the Garante for sharing customers’ personal data with various companies without proper notice and consent. The authority found that the conduct breached privacy rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 18 Jan 2018 | Italia Consulenza e Formazione s.r.l.Italia Consulenza e Formazione s.r.l. was fined EUR 32,000 by the Garante for sending promotional emails without proper consent. The case concerns a breach of data protection rules governing direct marketing. | IT | Garante | GDPR | €32,000 | ↗ |
| 01 Dec 2011 | Soprintendenza per i beni architettonici, paesaggistici, storici, artistici e etnoantropologici per Napoli e provinciaThe Garante fined Soprintendenza 32,000 EUR for violations related to the processing of biometric data. The authority found that the processing did not comply with the required legal requirements. | IT | Garante | GDPR | €32,000 | ↗ |
| 08 May 2013 | Agro Informatica di Buracchi GinoAgro Informatica di Buracchi Gino was fined 32,000 EUR by the Garante for sending unsolicited promotional emails without prior explicit consent. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €32,000 | ↗ |
| 21 Mar 2012 | Solar Energy Group s.p.aSolar Energy Group s.p.a was fined by the Garante 32,000 EUR for processing personal data collected through online forms without providing the required information or obtaining consent. The authority found breaches of Articles 13 and 23 of the Italian Privacy Code. | IT | Garante | GDPR | €32,000 | ↗ |
| 12 Apr 2018 | Azienda Ospedaliera Sant’Andrea di RomaAzienda Ospedaliera Sant’Andrea di Roma was fined 32,000 EUR by the Garante for violations related to the processing of personal data in healthcare services. The case concerned deficiencies in consent handling and patient information forms. | IT | Garante | GDPR | €32,000 | ↗ |
| 26 Feb 2026 | Dedalus Italia S.p.A.Dedalus Italia S.p.A. was fined EUR 32,000 by the Garante for inadequate security measures that led to a data breach. The company implemented corrective actions promptly, but prior violations were taken into account when setting the penalty. | IT | Garante | GDPR | €32,000 | ↗ |
| 18 Oct 2012 | Verzeri MaurizioVerzeri Maurizio was fined EUR 32,000 by the Italian data protection authority, Garante. The case concerned the sending of unsolicited promotional faxes without prior recipient consent and without providing the information required under the data protection code. | IT | Garante | GDPR | €32,000 | ↗ |
| 04 Jul 2025 | Niepubliczny Zakład Opieki ZdrowotnejUODO imposed a PLN 32,832 administrative fine on Niepubliczny Zakład Opieki Zdrowotnej for failing to conduct a risk analysis for processing patient data during home visits. The authority also found that appropriate technical and organizational measures to secure the data had not been implemented. | PL | UODO | GDPR | €7,733 | ↗ |
| 28 Oct 2013 | LEGALITAS ASISTENCIA LEGAL, S.L.LEGALITAS ASISTENCIA LEGAL, S.L. was fined by the AEPD 33,000 EUR for sending unsolicited commercial communications. The conduct continued despite requests for data cancellation, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €33,000 | ↗ |
| 01 Jan 2012 | IDEAS CREATIVAS DE OPERACION S.L.IDEAS CREATIVAS DE OPERACION S.L. was fined EUR 33,001 by the AEPD for sending unsolicited commercial emails despite requests for data cancellation. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €33,001 | ↗ |
| 16 Oct 2013 | FRANCE TELECOM ESPAÑA, S.A.FRANCE TELECOM ESPAÑA, S.A. was fined by the AEPD for sending commercial emails to a complainant despite a request not to use personal data for advertising purposes. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €33,001 | ↗ |
| 13 Jul 2012 | NH HOTELES, S.A.NH HOTELES, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant after confirming the cancellation of their personal data. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €33,001 | ↗ |
| 08 Feb 2023 | DKN.5131.50.2021StatusprawomocnaTytuUODO imposed a PLN 33,012 fine on the controller and the processor for failing to implement appropriate technical and organizational measures to secure personal data. The authority also found that the controller did not verify whether the processor provided sufficient guarantees of GDPR compliance and protection of data subjects' rights. | PL | UODO | GDPR | €6,967 | ↗ |
| 21 Jun 2023 | Dane anonimowe (H. Sp. z o.o. z siedzibą w W. przy Al.)UODO imposed a PLN 33,012 fine on H. Sp. z o.o. The penalty was issued because the company failed to provide the President of the Personal Data Protection Office with access to information necessary to perform supervisory duties. | PL | UODO | GDPR | €7,447 | ↗ |