BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Dec 2024 | Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined by the Garante in the amount of EUR 40,000 for violations related to data processing. The case concerned non-compliance with Art. 2-ter of the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 Apr 2025 | Comune di BolognaThe Garante imposed a fine of 40,000 EUR on Comune di Bologna for breaches of data protection principles. The case concerned non-compliance with requirements on lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €40,000 | ↗ |
| 19 Jul 2018 | Go Internet S.p.AGo Internet S.p.A was fined by the Garante in the amount of 40,000 EUR for processing and retaining telephone and internet traffic data beyond the permitted period. The authority found this conduct contrary to the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 21 Dec 2018 | Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act. | NL | AP | GDPR | €40,000 | ↗ |
| 08 Aug 2022 | CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. (CASER)CASER was fined 40,000 EUR by the AEPD for modifying insurance policy data without the policyholder’s consent. The authority found that this breached GDPR data processing principles. | ES | AEPD | GDPR | €40,000 | ↗ |
| 01 Dec 2024 | Orange România SAThe Romanian data protection authority completed an investigation in December 2024 into Orange România SA and found a breach of Article 12(3) GDPR. The case concerned failure to meet the deadline for responding to a data subject access request, resulting in a EUR 40,000 fine. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €40,000 | ↗ |
| 20 Apr 2017 | Linea Com s.r.l.Linea Com s.r.l. was fined by the Garante EUR 40,000 for retaining customers' telephone and telematic traffic data beyond the legal retention periods. The authority found that the storage periods exceeded the limits set by data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Dec 2023 | Azienda socio sanitaria territoriale nord MilanoAzienda socio sanitaria territoriale nord Milano was fined by the Garante EUR 40,000 for allowing unrestricted access to patient data across hospital departments. The authority found breaches of data minimization and purpose limitation principles during the COVID-19 emergency. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 Aug 2025 | FIATC MUTUA DE SEGUROS Y REASEGUROSFIATC Mutua de Seguros y Reaseguros was fined €40,000 by the AEPD after unauthorized access to its systems. The incident may have exposed personal data, including DNI/CIF, and the authority found inadequate security measures and a breach of Article 5(1)(f) GDPR. | ES | AEPD | GDPR | €40,000 | ↗ |
| 26 Mar 2015 | Okcom S.p.a.Okcom S.p.a. was fined EUR 40,000 by the Italian Garante. The authority found non-compliance with strong authentication requirements and a failure to notify the Garante about compliance with data protection measures. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Mar 2026 | INPS – Istituto nazionale previdenza socialeThe Italian Data Protection Authority fined INPS EUR 40,000 for improperly displaying personal data of individuals residing in a care facility during an ISEE precompilation request. The authority found a breach of data protection principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 20 Jan 2021 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 40,000 by the AEPD for failing to respond to a data access request. The case concerns non-compliance with GDPR obligations relating to data subject rights. | ES | AEPD | GDPR | €40,000 | ↗ |
| 08 Sept 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD €40,000 for processing personal data without a legal basis. The case involved fraudulent contracts created in individuals’ names without their consent, breaching the principle of lawful processing. | ES | AEPD | GDPR | €40,000 | ↗ |
| 15 Mar 2018 | Lombardia Informatica S.p.A.Lombardia Informatica S.p.A. was fined EUR 40,000 by the Garante for allowing unauthorized access to personal data through its portal. The case concerned a breach of data protection rules and indicated insufficient access controls. | IT | Garante | GDPR | €40,000 | ↗ |
| 27 Nov 2025 | InfobelThe Belgian Data Protection Authority (APD) imposed a EUR 40,000 fine on Infobel on 2025-11-27. The authority found that the company resold telecom-derived personal data for marketing purposes without valid consent and ordered it to inform its business customers of the decision. | BE | Autorité de protection des données (APD) | GDPR | €40,000 | ↗ |
| 05 Oct 2017 | Start S.p.A.Start S.p.A. was fined by the Garante 40,000 EUR for operating a geolocation system on its buses without full compliance with data protection rules. The case concerned location data processing without the required legal basis and safeguards. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Jul 2023 | Compara Facile S.r.l.Compara Facile S.r.l. was fined EUR 40,000 by the Garante for making unsolicited marketing calls to a number listed in the Public Register of Oppositions without prior informed consent. The authority also found that the company failed to respond to data subject rights requests, indicating non-compliance with data protection obligations. | IT | Garante | GDPR | €40,000 | ↗ |
| 31 Oct 2022 | FACTOR ENERGÍA, S.A.FACTOR ENERGÍA, S.A. was fined by the AEPD EUR 40,000 for sending personalized marketing messages using personal data without a legal basis. The authority found a breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €40,000 | ↗ |
| 08 Apr 2022 | AVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCAAVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCA was fined by the AEPD for failing to implement robust access controls. The weakness enabled attackers to encrypt files and demand a ransom, indicating significant gaps in technical and organizational safeguards. | ES | AEPD | GDPR | €40,000 | ↗ |
| 10 Nov 2022 | Azienda Usl Valle d’AostaAzienda Usl Valle d’Aosta was fined EUR 40,000 by the Garante for unlawful access to a patient's health dossier. The access was made by a healthcare professional not involved in the patient's care, breaching GDPR data processing principles. | IT | Garante | GDPR | €40,000 | ↗ |