BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Feb 2018 | Comune di FiumicinoComune di Fiumicino was fined by the Garante for failing to notify a data breach within the required timeframe. The authority found a violation of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 20 Feb 2018 | Anonymizováno (ÚOOÚ UOOU-12027/17-24)The entity was fined CZK 20,000 for disclosing sensitive personal data of a witness and a victim in a criminal case during a TV report. The authority found that the processing took place without explicit consent and without a valid legal exception. | CZ | UOOU | GDPR | €790 | ↗ |
| 19 Feb 2018 | AVIS ALQUILE UN COCHE S.A.AVIS ALQUILE UN COCHE S.A. was fined by the AEPD 10,000 EUR for improper handling of personal data. This led to the wrongful publication of an individual's details in the Official State Gazette as the responsible party for a traffic violation they did not commit. | ES | AEPD | GDPR | €10,000 | ↗ |
| 15 Feb 2018 | Innovastem s.r.l.Innovastem s.r.l. was fined by the Garante for processing personal data without providing the required information notice and for handling health-related data without proper consent. The case indicates breaches of transparency obligations and the rules governing the lawful processing of sensitive data. | IT | Garante | GDPR | €22,400 | ↗ |
| 15 Feb 2018 | Casa della legalità e della cultura onlusCasa della legalità e della cultura onlus was fined EUR 20,000 by the Garante. The authority found a data protection breach because the organization failed to respond to requests for information about the publication of personal data on its websites. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Feb 2018 | Nazzareno SalernoNazzareno Salerno was fined for unlawful processing of personal data by sending electoral propaganda emails without proper consent. This breached Garante rules on data handling by political parties. | IT | Garante | GDPR | €12,000 | ↗ |
| 15 Feb 2018 | AUTONOLEGGI 24 S.a.s. DI GIAQUINTO GIOVANNIAUTONOLEGGI 24 S.a.s. was fined by the Garante for processing personal data through a geolocation system without the required notification. The case concerned breaches of notification and supervisory obligations linked to that processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Feb 2018 | Auto Uno s.r.l.Auto Uno s.r.l. was fined EUR 30,000 by the Italian Garante. The case concerned improper management of a video surveillance system, including excessive retention of recorded images. | IT | Garante | GDPR | €30,000 | ↗ |
| 15 Feb 2018 | APS Holding S.p.a.APS Holding S.p.a. was fined by the Garante 40,000 EUR for failing to properly notify the data processing activities linked to the geolocation of vehicles used in its car sharing service. The authority found that the notification obligations under the Italian data protection code were not met. | IT | Garante | GDPR | €40,000 | ↗ |
| 15 Feb 2018 | Genova Car Sharing SrlGenova Car Sharing Srl was fined EUR 46,000 by the Garante. The authority found that customers were not fully informed about vehicle geolocation and that separate consent was not obtained for newsletter communications. | IT | Garante | GDPR | €46,000 | ↗ |
| 12 Feb 2018 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ж-453-05-10-201)The Commission fined an individual for unlawfully processing personal data by including it in a list supporting registration for a referendum campaign without consent. The case concerned a breach of the legal basis requirements for personal data processing. | BG | CPDP | GDPR | €5,113 | ↗ |
| 12 Feb 2018 | Политическа партия „Движение презареди България“The political party Movement Reload Bulgaria was fined 10,000 BGN by the CPDP for processing personal data without consent. The breach occurred during the registration of individuals as election commission members and violated the Bulgarian Personal Data Protection Act. | BG | CPDP | GDPR | €5,113 | ↗ |
| 02 Feb 2018 | Anonymizováno (ÚOOÚ UOOU-06702/17-37)The entity was fined CZK 50,000 by the Czech data protection authority for failing to provide the required cooperation during an ongoing inspection. This breached the duty to create conditions for the inspection and to allow the inspector to exercise their powers. | CZ | UOOU | GDPR | €1,985 | ↗ |
| 01 Feb 2018 | Car2Go Italia s.r.l.Car2Go Italia s.r.l. was fined EUR 20,000 by the Garante. The authority found a breach of data protection rules for failing to designate employees as data processors in connection with geolocation data processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Feb 2018 | Provincia di BeneventoProvincia di Benevento was fined by the Garante for unlawfully publishing special-category personal data on its website, including health information and tax codes. The authority found a breach of data protection rules. | IT | Garante | GDPR | €60,000 | ↗ |
| 01 Feb 2018 | Car City Club s.r.l.Car City Club s.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to designate data processors among its employees, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Feb 2018 | Transpe S.p.A.Transpe S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to notify the installation of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Feb 2018 | Iqbal QuasimIqbal Quasim was fined EUR 30,000 by the Garante. The case concerned registering phone SIM cards to third parties without their consent, which breached data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 25 Jan 2018 | Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined by the Garante 60,000 EUR for publishing special-category personal data, including health information, on its institutional website. The disclosure breached data protection rules and triggered supervisory enforcement. | IT | Garante | GDPR | €60,000 | ↗ |
| 25 Jan 2018 | Avis Budget Italia s.p.a.Avis Budget Italia s.p.a. was fined EUR 60,000 by the Garante for improper installation and notification of geolocation devices on its vehicle fleet. The authority found that the company did not comply with data protection requirements. | IT | Garante | GDPR | €60,000 | ↗ |