BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Dec 2012 | Assicurazioni Generali s.p.a.Assicurazioni Generali s.p.a. was fined 40,000 EUR by the Garante for making an unsolicited promotional phone call. The call was placed despite the recipient's prior objection to the processing of personal data for marketing purposes. | IT | Garante | GDPR | €40,000 | ↗ |
| 10 Nov 2022 | Doctolib SrlDoctolib Srl was fined EUR 40,000 by the Italian Garante for violations linked to insufficient transparency in the online information provided to patients. The case concerned, in particular, how consent for processing health data was obtained. | IT | Garante | GDPR | €40,000 | ↗ |
| 21 Sept 2017 | AMI S.p.A.AMI S.p.A. was fined by the Garante for installing electronic monitoring and localization devices on public transport vehicles without proper notification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 16 Nov 2023 | Amazon Italia Transport s.r.l.Amazon Italia Transport s.r.l. was fined €40,000 by the Garante for failing to respond to a former employee’s request for access to personal data. The authority found a breach of Article 15 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 05 Mar 2020 | CoolblueCoolblue was fined 40,000 EUR by the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, for unlawfully collecting personal data through cookies without active consent. The violation occurred in 2020, and the company updated its cookie banner after the authority’s investigation. | NL | Autoriteit Persoonsgegevens | GDPR | €40,000 | ↗ |
| 22 Nov 2024 | Maynooth UniversityThe Irish DPC imposed a fine of EUR 40,000 on Maynooth University in inquiry IN-19-9-3. The penalty has been collected. | IE | DPC | GDPR | €40,000 | ↗ |
| 04 Oct 2012 | American Express Services Europe LimitedAmerican Express Services Europe Limited was fined by the Garante EUR 40,000 for making promotional calls without the data subject's consent. The case concerns a breach of privacy rules governing telephone marketing. | IT | Garante | GDPR | €40,000 | ↗ |
| 03 Jul 2020 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALIberia was fined by the AEPD 40,000 EUR for failing to provide the complainant access to their personal data, including telephone recordings. The authority found a breach of the right of access to personal data. | ES | AEPD | GDPR | €40,000 | ↗ |
| 20 Jul 2017 | InvalsiInvalsi was fined EUR 40,000 by the Italian Garante for unlawful processing of personal data. The case concerned the online publication of files containing disaggregated student personal data, including sensitive information. | IT | Garante | GDPR | €40,000 | ↗ |
| 25 Jan 2018 | Trivenet s.r.l.Trivenet s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company retained call data longer than permitted under data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 10 Dec 2015 | Aruba s.p.a.Aruba s.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 40,000. The case concerned the sending of promotional emails without obtaining the required consent, in breach of articles 23 and 130 of the Italian data protection code. | IT | Garante | GDPR | €40,000 | ↗ |
| 15 Feb 2018 | APS Holding S.p.a.APS Holding S.p.a. was fined by the Garante 40,000 EUR for failing to properly notify the data processing activities linked to the geolocation of vehicles used in its car sharing service. The authority found that the notification obligations under the Italian data protection code were not met. | IT | Garante | GDPR | €40,000 | ↗ |
| 22 Sept 2011 | C.T.M. s.p.a.C.T.M. s.p.a. was fined 40,000 EUR by the Italian data protection authority, Garante. The case concerned the failure to formally designate data processors and a breach of minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 14 Nov 2024 | Provvedimento del 14 novembre 2024 [10104860]Garante imposed a EUR 40,000 fine on a healthcare company for failing to update its security assessments in response to increased cyberattacks. The authority found a breach of GDPR Article 32 because technical and organizational measures were not adjusted to the changed risk level. | IT | Garante | GDPR | €40,000 | ↗ |
| 11 Feb 2021 | Bonatti S.p.ABonatti S.p.A was fined EUR 40,000 by the Garante for violating data protection rules. The company improperly shared an employee's medical data with a third party. | IT | Garante | GDPR | €40,000 | ↗ |
| 27 Apr 2023 | Geico S.p.A.Geico S.p.A. was fined 40,000 EUR by the Garante for keeping former employees' email accounts active after the employment relationship ended. The authority found that the company accessed the contents of those accounts in breach of GDPR requirements. | IT | Garante | GDPR | €40,000 | ↗ |
| 21 Dec 2018 | Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act. | NL | AP | GDPR | €40,000 | ↗ |
| 19 Nov 2021 | Working Capital Management España, S.L.Working Capital Management España, S.L. was fined by the AEPD 40,000 EUR for unlawfully processing personal data. The company included an individual's data in a credit information system without a valid contract, in connection with an identity theft case. | ES | AEPD | GDPR | €40,000 | ↗ |
| 21 May 2020 | TuslaThe Irish DPC imposed a fine of EUR 40,000 on Tusla in case IN-19-12-8. The fine was collected. | IE | DPC | GDPR | €40,000 | ↗ |
| 13 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined 40,000 EUR by the AEPD for charging a customer's phone bill without consent. The authority found a breach of Article 6(1) GDPR due to the lack of a lawful basis for processing. | ES | AEPD | GDPR | €40,000 | ↗ |