BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 18 Dec 2025 | LTL S.p.A.LTL S.p.A. was fined 40,000 EUR by the Garante for unlawfully maintaining access to an ex-employee’s email account after termination. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 23 Mar 2023 | La Risorsa Umana.it s.r.l.La Risorsa Umana.it s.r.l. was fined EUR 40,000 by the Garante for monitoring employee email communications without providing proper information to employees. The authority found that this conduct breached GDPR requirements on transparency of processing and data security. | IT | Garante | GDPR | €40,000 | ↗ |
| 27 Jan 2022 | T.S.M. s.r.l.T.S.M. s.r.l. was fined EUR 40,000 by the Italian supervisory authority, the Garante. The sanction concerned the failure to respond to information requests, which breached GDPR obligations related to data subject rights. | IT | Garante | GDPR | €40,000 | ↗ |
| 19 Dec 2024 | SOCIETE EXERCANT UNE ACTIVITE D'AGENCE IMMOBILIERECNIL imposed an administrative fine of EUR 40,000 on SOCIETE EXERCANT UNE ACTIVITE D'AGENCE IMMOBILIERE. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €40,000 | ↗ |
| 12 Mar 2026 | La7 S.p.A.La7 S.p.A. was fined 40,000 EUR by the Garante for broadcasting personal data, including phone numbers and names, during a news segment. The authority found a breach of GDPR Article 5 on data processing principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 19 Jun 2020 | IBERDROLA CLIENTES, SAUThe AEPD fined IBERDROLA CLIENTES, SAU EUR 40,000 for emailing a customer's electricity bill, which contained sensitive personal data, to an unrelated third party. The incident indicates a breach of confidentiality and personal data protection obligations. | ES | AEPD | GDPR | €40,000 | ↗ |
| 15 Sept 2022 | FCA Italy S.p.A.FCA Italy S.p.A. was fined by the Garante for failing to respond to a data subject's request for access to personal data related to employment. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €40,000 | ↗ |
| 01 Feb 2025 | Orange RomaniaThe Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) fined Orange Romania EUR 40,000 for GDPR violations. The authority found improper handling of personal data deletion requests and excessive collection of identity document copies. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €40,000 | ↗ |
| 29 Nov 2018 | Istituto Nazionale Previdenza Sociale (INPS)INPS was fined for processing the personal data of 12.6 million private workers using automated software without prior verification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 13 Nov 2024 | Istituto Nazionale della Previdenza SocialeThe Italian Data Protection Authority fined Istituto Nazionale della Previdenza Sociale (INPS) EUR 40,000 for violations related to the processing of personal data for official statistics. The authority found that the processing did not comply with core data protection principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 22 May 2014 | Eismann s.r.l.Eismann s.r.l. was fined by the Garante 40,000 EUR for making promotional phone calls without prior express consent from recipients. The company also concealed the caller's identity, which breached Italian data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 26 Jul 2017 | Cloud Europa s.r.l.Cloud Europa s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unsolicited promotional phone calls, in breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 01 Jan 2024 | EXCEL HOTELS & RESORTS, S.A.EXCEL HOTELS & RESORTS, S.A. was fined by the AEPD 40,000 EUR for leaving property owners’ personal data unattended, including ID and passport numbers. The authority found that this created unauthorized access to sensitive personal information and breached data protection principles. | ES | AEPD | GDPR | €40,000 | ↗ |
| 20 Oct 2022 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined by the Garante €40,000 for failing to provide a data subject with access to personal data relating to derivative transactions. The authority found a breach of the principles of lawful, fair, and transparent processing. | IT | Garante | GDPR | €40,000 | ↗ |
| 05 Jul 2017 | Vodafone Omnitel N.V.Vodafone Omnitel N.V. was fined by the Italian data protection authority, Garante, in the amount of 40,000 EUR. The sanction concerned the use of a group authentication credential to access personal data, which breached the security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 22 May 2014 | Colligo s.r.lColligo s.r.l was fined EUR 40,000 by the Garante for making promotional phone calls while disguising or hiding the caller's identity. The authority found this conduct breached the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Nov 2024 | Uptime-IT ApSUptime-IT ApS was fined by Datatilsynet 40,000 DKK for failing to implement adequate security measures as a data processor. This led to a ransomware attack that encrypted sensitive personal data, including health information and CPR numbers, which could not be restored. | DK | Datatilsynet | GDPR | €5,362 | ↗ |
| 13 Jun 2024 | Samodzielny Publiczny Zespół Opieki Zdrowotnej z siedzibą w P., za naruszenie art. 5 ust. 1 lit. f) i ust. 2, art. 25 ust. 1, art. 32 ust. 1 i 2 oraz art. 34 ust. 1 rozporządzenia 2016/679The Polish DPA (UODO) imposed an administrative fine of PLN 40,000 on the Samodzielny Publiczny Zespół Opieki Zdrowotnej based in P. The decision concerns breaches of Article 5(1)(f) and (2), Article 25(1), Article 32(1) and (2), and Article 34(1) of Regulation (EU) 2016/679. | PL | UODO | GDPR | €9,201 | ↗ |
| 25 Jul 2019 | SOCIEDAD ESTATAL CORREOS Y TELEGRAFOS. S.A.The entity delivered correspondence to the wrong recipient, which constitutes a breach of the data protection principles in Article 5 of the GDPR. AEPD imposed a fine of EUR 40,000. | ES | AEPD | GDPR | €40,000 | ↗ |
| 21 Apr 2021 | Azienda provinciale per i servizi sanitari di TrentoAzienda provinciale per i servizi sanitari di Trento was fined by the Garante EUR 40,000 for violations related to the processing of health data. The authority found omissions in implementing technical and organizational measures for access to the health dossier. | IT | Garante | GDPR | €40,000 | ↗ |