BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Jan 2016 | Comune di AdriaComune di Adria was fined EUR 4,000 by the Garante for unlawfully disclosing personal data of third parties. The authority sent photographic results to a complainant that contained data relating to other individuals, breaching data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Apr 2023 | Comune di AdelfiaThe Garante fined Comune di Adelfia EUR 8,000 for violations related to the publication of personal data on its institutional website. The data were later removed. | IT | Garante | GDPR | €8,000 | ↗ |
| 05 Mar 2015 | Comune di Acquarica del CapoThe Municipality of Acquarica del Capo was fined 10,000 EUR by the Garante for unlawfully publishing personal data revealing health information on its website. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Oct 2013 | Comune di AcirealeComune di Acireale was fined for failing to adopt minimum security measures and for not appointing data processing officers, as required by the Italian Data Protection Code. The case concerned basic organizational and security compliance failures. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Apr 2015 | Comune di AccianoComune di Acciano was fined 4,000 EUR by the Garante for unlawfully processing personal data by keeping a council resolution online beyond the legally permitted period. The case concerned non-compliance with data protection rules on retention and publication limits. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Mar 2015 | Comune di AcateComune di Acate was fined by the Garante for unlawfully publishing personal data revealing health information on its institutional website. The case concerned a breach of data protection rules and the confidentiality of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Oct 2023 | ComuneThe Italian data protection authority fined a municipality EUR 12,000 for unlawfully publishing personal data online in access request registers. Documents in the transparency section of the municipal website exposed names, protocol numbers, and other sensitive details of hundreds of citizens. | IT | Garante per la protezione dei dati personali | GDPR | €12,000 | ↗ |
| 17 Oct 2024 | ComuneThe Garante fined Comune EUR 8,000 for breaches of GDPR Articles 5, 6 and 9, and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data in the context of public employment and administrative transparency. | IT | Garante | GDPR | €8,000 | ↗ |
| 21 Mar 2013 | Compu & Games srlCompu & Games srl was fined EUR 54,000 by the Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information. | IT | Garante | GDPR | €54,000 | ↗ |
| 11 Oct 2023 | COM. PROP. ***COMUNIDAD.1The entity installed surveillance cameras oriented toward public roads without prior administrative authorization. This breached data protection rules and resulted in a fine by the AEPD. | ES | AEPD | GDPR | €1,000 | ↗ |
| 06 Dec 2011 | Composad s.r.l.Composad s.r.l. was fined by the Garante €26,000 for processing personal data collected through its website without properly appointing a data processor. The case concerned a breach of data protection rules and related organizational obligations. | IT | Garante | GDPR | €26,000 | ↗ |
| 09 Nov 2023 | Complete Marketing Services LtdBetween 8 June 2021 and 4 February 2022, Complete Marketing Services Ltd instigated 242,497 unsolicited direct marketing calls in breach of PECR. The ICO became aware of the matter after complaints about live marketing calls relating to road traffic accidents and personal injury claims were reported via the TPS. | GB | ICO | ePrivacy | €172,000 | ↗ |
| 08 Aug 2014 | Compass ExpoCompass Expo was fined EUR 10,000 by the HDPA for sending unsolicited electronic communications without recipients' consent. The authority found a breach of Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €10,000 | ↗ |
| 18 Jul 2023 | Compara Facile S.r.l.Compara Facile S.r.l. was fined EUR 40,000 by the Garante for making unsolicited marketing calls to a number listed in the Public Register of Oppositions without prior informed consent. The authority also found that the company failed to respond to data subject rights requests, indicating non-compliance with data protection obligations. | IT | Garante | GDPR | €40,000 | ↗ |
| 16 May 2023 | Compania Națională Poșta Română S.A.Compania Națională Poșta Română S.A. was fined EUR 5,000 by ANSPDCP for GDPR violations related to the completion of Form 230. The case arose from complaints, and the authority instructed the company to ensure personal data processing complies with processing principles. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 07 Nov 2022 | Compania Națională Poșta Română SAIn October 2022, ANSPDCP completed an investigation into Compania Națională Poșta Română SA and found a breach of GDPR provisions. The company was fined EUR 2,000 following a data security incident reported by a data operator. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 12 Jun 2026 | Compania Națională Poșta RomânăCompania Națională Poșta Română was fined by ANSPDCP in the amount of EUR 5,000 for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 08 Dec 2025 | Compania de Apă Oltenia S.A.The company was fined EUR 1,000 by ANSPDCP after an employee disclosed personal data on a social network. The case was initiated following a complaint from the data subject. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 05 Jul 2017 | Compagnia Generale Trattori S.p.A.Compagnia Generale Trattori S.p.A. was fined by the Garante EUR 20,000 for using a GPS/GPRS system to monitor employee activities without proper notification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Apr 2015 | Compagnia dei Telefoni s.r.l.Compagnia dei Telefoni s.r.l. was fined by the Garante 80,000 EUR for conducting telemarketing through automated calls without prior informed consent. The company also made promotional calls while concealing the caller's identity. | IT | Garante | GDPR | €80,000 | ↗ |