BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2018 | CANARY ISLANDS CAR S.L.CANARY ISLANDS CAR S.L. was fined by the AEPD 45,000 EUR for inaccurate processing of personal data. As a result, a traffic violation was incorrectly attributed to a person who had not rented the vehicle. | ES | AEPD | GDPR | €45,000 | ↗ |
| 18 Sept 2008 | Suzuki Italia S.p.A.Suzuki Italia S.p.A. was fined for failing to provide the required privacy notice to individuals whose personal data was obtained from a third party. The breach was found under the Italian Data Protection Code. | IT | Garante | GDPR | €45,000 | ↗ |
| 09 Jan 2024 | 20 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined 45,000 EUR by the AEPD for publicly exposing the image of a victim of an alleged crime. The authority found that this constituted a breach of data protection rules. | ES | AEPD | GDPR | €45,000 | ↗ |
| 18 Jul 2023 | Comune di ModicaThe Garante fined Comune di Modica EUR 45,000 for inadequate data protection measures linked to video surveillance in public areas. The issues affected a large number of individuals over an extended period, and those recorded were not properly informed. | IT | Garante | GDPR | €45,000 | ↗ |
| 07 May 2015 | Nappo Nicola JolandaNappo Nicola Jolanda was fined EUR 45,000 by the Garante for activating 37 phone cards in the names of 15 individuals without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €45,000 | ↗ |
| 29 Apr 2021 | Comune di TriesteComune di Trieste was fined for the unauthorized disclosure of personal data relating to individuals involved in accidents, including names, damage details, and compensation amounts. The data was improperly accessible, constituting a breach of GDPR requirements. | IT | Garante | GDPR | €45,000 | ↗ |
| 10 Apr 2025 | Stefanelli FedericaThe Garante imposed a 45,000 EUR fine on Stefanelli Federica for processing personal data without proper consent in unauthorized call-center operations. The case also involved sensitive data, including payment method information, which could have led to unauthorized contract activations. | IT | Garante | GDPR | €45,000 | ↗ |
| 04 Jun 2025 | Noi Compriamo Auto.it S.r.l.The Italian Supervisory Authority fined Noi Compriamo Auto.it S.r.l. 45,000 EUR for sending unsolicited promotional emails without proper consent documentation. The case indicates a breach of GDPR requirements for lawful direct marketing. | IT | Garante | GDPR | €45,000 | ↗ |
| 30 Nov 2022 | Dane anonimowe (N. B. oraz T. M., wspólników spółki cywilnej Kancelaria)UODO imposed an administrative fine on N. B. and T. M., partners in the civil-law partnership Kancelaria. The authority found that they processed personal data of clients and prospective clients without a legal basis. | PL | UODO | GDPR | €9,799 | ↗ |
| 26 May 2022 | Azienda Sanitaria Locale Roma 1The Garante fined Azienda Sanitaria Locale Roma 1 EUR 46,000 for the unauthorized publication of health-related personal data on its institutional website. The case concerned a breach of data protection rules through the disclosure of sensitive information without a lawful basis. | IT | Garante | GDPR | €46,000 | ↗ |
| 28 Nov 2013 | Axa società cooperativa a responsabilità limitataAxa società cooperativa a responsabilità limitata was fined by the Garante 46,000 EUR for using biometric systems to monitor employee attendance and working hours. The authority found that the processing took place without proper consent and required notifications, in breach of data protection rules. | IT | Garante | GDPR | €46,000 | ↗ |
| 22 Feb 2018 | Bar La Piazzetta s.a.s.Bar La Piazzetta s.a.s. was fined EUR 46,000 by the Italian Garante. The authority found that surveillance footage was kept longer than permitted, access was not password-protected, and the required privacy notices were not provided. | IT | Garante | GDPR | €46,000 | ↗ |
| 15 Feb 2018 | Genova Car Sharing SrlGenova Car Sharing Srl was fined EUR 46,000 by the Garante. The authority found that customers were not fully informed about vehicle geolocation and that separate consent was not obtained for newsletter communications. | IT | Garante | GDPR | €46,000 | ↗ |
| 13 Sept 2012 | YVES ROCHER ESPAÑA, S.A.YVES ROCHER ESPAÑA, S.A. was fined EUR 47,001 by the AEPD for continuing to send advertising emails to an individual who had requested data deletion and confirmation of that deletion. The authority found that marketing communications continued despite the request. | ES | AEPD | ePrivacy | €47,001 | ↗ |
| 31 May 2023 | Dane anonimowe (P. Sp. z o.o. z siedzibą w W. przy ul.)UODO imposed a PLN 47,160 fine on the anonymous company for failing to implement appropriate technical and organizational measures to secure personal data processing in IT systems. The authority also found a lack of regular testing, measuring, and evaluation of the effectiveness of those measures, as well as failure to report the personal data breach without undue delay. In addition, the company did not notify affected individuals without undue delay despite a high risk to their rights and freedoms. | PL | UODO | GDPR | €10,395 | ↗ |
| 09 Aug 2018 | InsingerGilissen Bankiers N.V.Theodoor Gilissen Bankiers N.V. failed to provide a complete overview of personal data processing upon request, which breached data protection rules. Its successor, InsingerGilissen Bankiers N.V., was fined EUR 48,000. | NL | AP | GDPR | €48,000 | ↗ |
| 02 Mar 2017 | Trilogy s.r.l.Trilogy s.r.l. was fined EUR 48,000 by the Garante for making unsolicited marketing calls. The authority found that the company failed to provide the required information and did not obtain consent, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €48,000 | ↗ |
| 25 Mar 2021 | Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules. | IT | Garante | GDPR | €50,000 | ↗ |
| 24 Apr 2025 | Darian Bishop trading as ECO4UBetween 9 January 2023 and 9 October 2023, 194,110 unsolicited direct marketing calls were made to subscribers registered with the TPS who had not indicated consent to receive such calls. The conduct generated 21 complaints to the Commissioner and the TPS, leading to an ICO fine. | GB | ICO | GDPR | €58,480 | ↗ |
| 05 Jun 2020 | EDP Energía, S.A.U.EDP Energía, S.A.U. was fined €50,000 by the AEPD for processing personal data without consent. The authority found this conduct to be in breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |