BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2013 | SEARCH TASK S.L.U.SEARCH TASK S.L.U. was fined EUR 40,000 by the AEPD for sending commercial communications without the required consent. The case concerned a breach of Article 21 of the LSSI and unlawful use of personal data for marketing purposes. | ES | AEPD | ePrivacy | €40,000 | ↗ |
| 10 Jun 2021 | Aeroporto Guglielmo Marconi di Bologna S.p.a.Aeroporto Guglielmo Marconi di Bologna S.p.a. was fined by the Garante EUR 40,000 for violations related to the protection of whistleblower identities. The case indicates insufficient personal data safeguards in the handling of reports. | IT | Garante | GDPR | €40,000 | ↗ |
| 17 Dec 2020 | Miropass S.r.l.Miropass S.r.l. was fined EUR 40,000 by the Italian supervisory authority Garante. The case concerned violations related to data processing activities. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Oct 2019 | Dane anonimowe (Burmistrza G. karę pieniężną w kwocie 40.000 zł)UODO found a breach of the principles of lawful processing and confidentiality. A fine of PLN 40,000 was imposed, together with an order to bring processing operations into compliance with data protection rules. | PL | UODO | GDPR | €9,336 | ↗ |
| 01 Jan 2022 | INMOBILIARIA MESLLOC, S.L.INMOBILIARIA MESLLOC, S.L. was fined by the AEPD for unlawfully sharing tenants’ personal data with third-party companies without authorization. The authority found this conduct violated Article 6(1) of the GDPR. | ES | AEPD | GDPR | €40,000 | ↗ |
| 21 Mar 2018 | Ditta individuale Smile di Remmert OriettaThe company was fined for processing the personal data of 36 individuals without consent in connection with training enrollments. It also submitted false documents to the Province of Turin to account for courses that were never conducted. | IT | Garante | GDPR | €40,000 | ↗ |
| 30 Mar 2023 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to respond to a data subject access request concerning recorded calls. The authority also found that the company did not notify a personal data breach to the regulator. | GR | HDPA | GDPR | €40,000 | ↗ |
| 28 Oct 2015 | MUTUA MADRILEÑA AUTOMOVILISTA SOCIEDAD DE SEGUROS A PRIMA FIJAMutua Madrileña was fined 40,001 EUR by the AEPD for sending unsolicited commercial emails despite the recipient’s objection. The case concerns a breach of data protection and direct marketing rules. | ES | AEPD | ePrivacy | €40,001 | ↗ |
| 15 Oct 2025 | Dane anonimowe (B. Sp. z o.o. z siedzibą w M. za naruszenie przepisu art. 33 ust. 1 rozporządzenia 2016/679)UODO imposed an administrative fine on B. Sp. z o.o. for failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay and, at the latest, within 72 hours of becoming aware of it. The case concerns the reporting obligation under Article 33(1) GDPR. | PL | UODO | GDPR | €9,519 | ↗ |
| 08 Jun 2023 | RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined EUR 40,660 by the Italian Garante. The case concerned the publication of unauthorized photographs of a private individual taken inside her home, which infringed her privacy rights. | IT | Garante | GDPR | €40,660 | ↗ |
| 16 Jan 2014 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 41,000 EUR for sending commercial communications by email and SMS without the recipients’ consent. The conduct breached Article 21.1 of the LSSI, which requires prior consent for such messages. | ES | AEPD | ePrivacy | €41,000 | ↗ |
| 29 Nov 2012 | Enterprise Work s.r.l.Enterprise Work s.r.l. was fined by the Garante in the amount of 41,600 EUR. The case concerned the sending of unsolicited promotional faxes without valid recipient consent. | IT | Garante | GDPR | €41,600 | ↗ |
| 09 May 2018 | Telefonika s.r.l.sTelefonika s.r.l.s was fined by the Italian data protection authority, Garante, in the amount of EUR 42,000. The sanction concerned numerous unsolicited promotional phone calls made without proper consent. | IT | Garante | GDPR | €42,000 | ↗ |
| 14 Sept 2023 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined 42,000 EUR by the Garante for failing to provide timely access to personal data requested by a parent under GDPR Article 15. The authority said the delay resulted from an operational error that prevented timely handling of the request. | IT | Garante | GDPR | €42,000 | ↗ |
| 22 Jan 2015 | Istituto Nazionale Previdenza SocialeIstituto Nazionale Previdenza Sociale was fined EUR 44,000 by the Garante. The authority found that the required privacy notice was not provided to users, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €44,000 | ↗ |
| 01 Jan 2012 | VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined by the AEPD in the amount of EUR 44,001 for sending unsolicited commercial communications to a non-customer. The authority found this conduct to be in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €44,001 | ↗ |
| 07 Jul 2022 | Senseonics Inc.Senseonics Inc. was fined EUR 45,000 by the Garante for violations related to the processing of personal data. The authority cited issues with data integrity and confidentiality, including health data. | IT | Garante | GDPR | €45,000 | ↗ |
| 12 Mar 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 45,000 EUR by the AEPD for sending continuous SMS messages to a complainant despite a prior request to cancel personal data. The authority found this conduct to be a breach of data protection principles. | ES | AEPD | GDPR | €45,000 | ↗ |
| 11 Feb 2021 | Istituti ospedalieri bergamaschiThe Garante fined Istituti ospedalieri bergamaschi EUR 45,000 for a data protection breach. Online medical reports were accessible to other patients, exposing sensitive personal data. | IT | Garante | GDPR | €45,000 | ↗ |
| 28 Nov 2017 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 45,000 EUR by the AEPD for sending commercial emails without providing a valid electronic address for exercising the right to object. The authority found this to be a breach of LSSI rules on commercial communications. | ES | AEPD | ePrivacy | €45,000 | ↗ |