BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Dec 2025 | KomendantaUODO imposed an administrative fine of PLN 40,000 on Komendanta for unlawful processing of personal data, including special category data, by publishing it on a website without a legal basis. The authority also found that appropriate technical and organizational measures were not implemented and ordered the processing operations to be brought into compliance with GDPR requirements. | PL | UODO | GDPR | €9,457 | ↗ |
| 11 Apr 2013 | Diners Club Italia s.r.l.Diners Club Italia s.r.l. was fined €40,000 by the Garante for breaches of data protection rules. The authority found that the company failed to designate data processing officers and did not update the security program document. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Apr 2022 | Azienda ospedaliera di PerugiaAzienda ospedaliera di Perugia was fined by the Garante EUR 40,000 for breaches related to the protection of whistleblower identities. The authority found that adequate personal data protection measures were not in place. | IT | Garante | GDPR | €40,000 | ↗ |
| 26 Sept 2023 | RESTART ENERGY ONE S.A.RESTART ENERGY ONE S.A. was fined by ANSPDCP in the amount of RON 40,000 for additional GDPR violations. The authority also imposed corrective measures to improve data protection processes. | RO | ANSPDCP | GDPR | €8,048 | ↗ |
| 18 Sept 2014 | Meridi s.r.l.Meridi s.r.l. was fined by the Garante 40,000 EUR for failing to provide adequate information about video surveillance and for not appointing data processing officers. The authority found a breach of data security measures. | IT | Garante | GDPR | €40,000 | ↗ |
| 17 May 2023 | Volkswagen Leasing GmbHVolkswagen Leasing GmbH was fined EUR 40,000 by the Garante for failing to adequately respond to a data access request. The authority found a breach of GDPR provisions on data subject rights. | IT | Garante | GDPR | €40,000 | ↗ |
| 13 Dec 2018 | Anonymizováno (ÚOOÚ UOOU-08001/18-14)The entity was fined 40,000 CZK by the UOOU for insufficient security measures in the processing of personal data. The authority cited inadequate audit logs and a lack of regular access checks to electronic health records. | CZ | UOOU | GDPR | €1,549 | ↗ |
| 28 Apr 2022 | Il Sole 24 Ore S.p.a.Il Sole 24 Ore S.p.a. was fined by the Garante EUR 40,000 for publishing a court order containing the personal data of an adopted minor. The authority also found an incomplete and delayed response to a data access request. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Dec 2025 | Anticimex s.r.l.Anticimex s.r.l. was fined EUR 40,000 by the Garante for breaching data protection rules. The company failed to provide an employee with access to personal data, including work-related emails and CRM access logs, despite a request under Article 15 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 23 Sept 2010 | Regione PugliaRegione Puglia was fined EUR 40,000 by the Italian data protection authority, Garante. The case concerned the online publication of sensitive health data relating to disabled individuals, in breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Apr 2022 | ISWEB S.p.A.ISWEB S.p.A. was fined EUR 40,000 by the Italian supervisory authority, Garante. The authority found that the company failed to properly regulate its relationship with the hosting service provider in relation to data processing for Azienda ospedaliera di Perugia, in breach of Article 28 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 24 May 2017 | Call Solution s.r.l.Call Solution s.r.l. was fined EUR 40,000 by the Garante for making unsolicited promotional calls to numbers listed in the public opt-out registry. The conduct breached data protection rules and the requirements governing telephone marketing. | IT | Garante | GDPR | €40,000 | ↗ |
| 09 Feb 2023 | Anonymizováno (ÚOOÚ UOOU-04020/22-13)The entity was fined for repeatedly sending unsolicited commercial communications by electronic means without recipients' consent. The authority found a breach of Czech rules on information society services. | CZ | UOOU | ePrivacy | €1,688 | ↗ |
| 18 Dec 2018 | ORGANIZACION NACIONAL DE CIEGOS (ONCE)ONCE was fined EUR 40,000 by the AEPD for sending more than 200 unsolicited commercial emails without prior consent. The authority found this to be a breach of Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €40,000 | ↗ |
| 03 Feb 2021 | NBQ TECHNOLOGY, S.A.U.NBQ TECHNOLOGY, S.A.U. was fined by the AEPD 40,000 EUR for processing personal data without a legal basis. The case was linked to a denied financial operation following an identity theft incident. | ES | AEPD | GDPR | €40,000 | ↗ |
| 21 Oct 2019 | Anonymizováno (ÚOOÚ UOOU-02928/19-13)The entity was fined for publishing personal data related to criminal proceedings on its website. The authority found a breach of GDPR rules on the processing and disclosure of personal data. | CZ | UOOU | GDPR | €1,561 | ↗ |
| 13 Mar 2025 | Interflora Italia S.p.A.Interflora Italia S.p.A. was fined EUR 40,000 by the Garante for sending promotional SMS messages without providing an opt-out option. The case indicates a breach of GDPR requirements for marketing communications and data subject rights. | IT | Garante | GDPR | €40,000 | ↗ |
| 11 Apr 2013 | Casa di cura La Quiete srlCasa di cura La Quiete srl was fined by the Garante for failing to notify data processing activities related to patients’ laboratory tests. The data could reveal infectious diseases, which required notification under the Italian data protection code. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 Sept 2011 | Agenzia per le erogazioni in agricoltura (AGEA)The Italian Data Protection Authority fined Agenzia per le erogazioni in agricoltura (AGEA) EUR 40,000 for violations related to the processing of personal data within the National Agricultural Information System (Sian). The case concerned compliance of the processing activities with personal data protection requirements. | IT | Garante | GDPR | €40,000 | ↗ |
| 22 Nov 2012 | Synergo s.r.l.Synergo s.r.l. was fined by the Italian Garante for failing to notify the processing of sensitive health data. The case involved information on HIV status and infectious diseases, which should have been notified under the Italian data protection code. | IT | Garante | GDPR | €40,000 | ↗ |