Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
18 Dec 2025LTL S.p.A.LTL S.p.A. was fined 40,000 EUR by the Garante for unlawfully maintaining access to an ex-employee’s email account after termination. The authority found this to be a breach of data protection rules.ITGaranteGDPR€40,000
23 Mar 2023La Risorsa Umana.it s.r.l.La Risorsa Umana.it s.r.l. was fined EUR 40,000 by the Garante for monitoring employee email communications without providing proper information to employees. The authority found that this conduct breached GDPR requirements on transparency of processing and data security.ITGaranteGDPR€40,000
27 Jan 2022T.S.M. s.r.l.T.S.M. s.r.l. was fined EUR 40,000 by the Italian supervisory authority, the Garante. The sanction concerned the failure to respond to information requests, which breached GDPR obligations related to data subject rights.ITGaranteGDPR€40,000
19 Dec 2024SOCIETE EXERCANT UNE ACTIVITE D'AGENCE IMMOBILIERECNIL imposed an administrative fine of EUR 40,000 on SOCIETE EXERCANT UNE ACTIVITE D'AGENCE IMMOBILIERE. The case concerns a breach of rules supervised by CNIL.FRCNILGDPR€40,000
12 Mar 2026La7 S.p.A.La7 S.p.A. was fined 40,000 EUR by the Garante for broadcasting personal data, including phone numbers and names, during a news segment. The authority found a breach of GDPR Article 5 on data processing principles.ITGaranteGDPR€40,000
19 Jun 2020IBERDROLA CLIENTES, SAUThe AEPD fined IBERDROLA CLIENTES, SAU EUR 40,000 for emailing a customer's electricity bill, which contained sensitive personal data, to an unrelated third party. The incident indicates a breach of confidentiality and personal data protection obligations.ESAEPDGDPR€40,000
15 Sept 2022FCA Italy S.p.A.FCA Italy S.p.A. was fined by the Garante for failing to respond to a data subject's request for access to personal data related to employment. The authority found a breach of GDPR Article 15.ITGaranteGDPR€40,000
01 Feb 2025Orange RomaniaThe Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) fined Orange Romania EUR 40,000 for GDPR violations. The authority found improper handling of personal data deletion requests and excessive collection of identity document copies.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€40,000
29 Nov 2018Istituto Nazionale Previdenza Sociale (INPS)INPS was fined for processing the personal data of 12.6 million private workers using automated software without prior verification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€40,000
13 Nov 2024Istituto Nazionale della Previdenza SocialeThe Italian Data Protection Authority fined Istituto Nazionale della Previdenza Sociale (INPS) EUR 40,000 for violations related to the processing of personal data for official statistics. The authority found that the processing did not comply with core data protection principles.ITGaranteGDPR€40,000
22 May 2014Eismann s.r.l.Eismann s.r.l. was fined by the Garante 40,000 EUR for making promotional phone calls without prior express consent from recipients. The company also concealed the caller's identity, which breached Italian data protection rules.ITGaranteGDPR€40,000
26 Jul 2017Cloud Europa s.r.l.Cloud Europa s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unsolicited promotional phone calls, in breach of data protection rules.ITGaranteGDPR€40,000
01 Jan 2024EXCEL HOTELS & RESORTS, S.A.EXCEL HOTELS & RESORTS, S.A. was fined by the AEPD 40,000 EUR for leaving property owners’ personal data unattended, including ID and passport numbers. The authority found that this created unauthorized access to sensitive personal information and breached data protection principles.ESAEPDGDPR€40,000
20 Oct 2022Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined by the Garante €40,000 for failing to provide a data subject with access to personal data relating to derivative transactions. The authority found a breach of the principles of lawful, fair, and transparent processing.ITGaranteGDPR€40,000
05 Jul 2017Vodafone Omnitel N.V.Vodafone Omnitel N.V. was fined by the Italian data protection authority, Garante, in the amount of 40,000 EUR. The sanction concerned the use of a group authentication credential to access personal data, which breached the security measures required under the Italian Data Protection Code.ITGaranteGDPR€40,000
22 May 2014Colligo s.r.lColligo s.r.l was fined EUR 40,000 by the Garante for making promotional phone calls while disguising or hiding the caller's identity. The authority found this conduct breached the Italian Data Protection Code.ITGaranteGDPR€40,000
12 Nov 2024Uptime-IT ApSUptime-IT ApS was fined by Datatilsynet 40,000 DKK for failing to implement adequate security measures as a data processor. This led to a ransomware attack that encrypted sensitive personal data, including health information and CPR numbers, which could not be restored.DKDatatilsynetGDPR€5,362
13 Jun 2024Samodzielny Publiczny Zespół Opieki Zdrowotnej z siedzibą w P., za naruszenie art. 5 ust. 1 lit. f) i ust. 2, art. 25 ust. 1, art. 32 ust. 1 i 2 oraz art. 34 ust. 1 rozporządzenia 2016/679The Polish DPA (UODO) imposed an administrative fine of PLN 40,000 on the Samodzielny Publiczny Zespół Opieki Zdrowotnej based in P. The decision concerns breaches of Article 5(1)(f) and (2), Article 25(1), Article 32(1) and (2), and Article 34(1) of Regulation (EU) 2016/679.PLUODOGDPR€9,201
25 Jul 2019SOCIEDAD ESTATAL CORREOS Y TELEGRAFOS. S.A.The entity delivered correspondence to the wrong recipient, which constitutes a breach of the data protection principles in Article 5 of the GDPR. AEPD imposed a fine of EUR 40,000.ESAEPDGDPR€40,000
21 Apr 2021Azienda provinciale per i servizi sanitari di TrentoAzienda provinciale per i servizi sanitari di Trento was fined by the Garante EUR 40,000 for violations related to the processing of health data. The authority found omissions in implementing technical and organizational measures for access to the health dossier.ITGaranteGDPR€40,000