BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Jul 2017 | Crea Futuro s.r.l.Crea Futuro s.r.l. was fined by the Garante 64,000 EUR for processing personal data without providing adequate information and obtaining consent. The breach affected about 2 million people, indicating a broad compliance impact. | IT | Garante | GDPR | €64,000 | ↗ |
| 20 Jul 2017 | S.I.T. s.r.l.S.I.T. s.r.l. was fined by the Garante in the amount of EUR 6,400 for unauthorized access to surveillance images and for processing customer data without proper notice to data subjects. The authority found that these actions breached data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 20 Jul 2017 | InvalsiInvalsi was fined EUR 40,000 by the Italian Garante for unlawful processing of personal data. The case concerned the online publication of files containing disaggregated student personal data, including sensitive information. | IT | Garante | GDPR | €40,000 | ↗ |
| 20 Jul 2017 | Centro Laser s.r.l.Centro Laser s.r.l. was fined EUR 20,400 by the Garante for using inadequate password procedures and failing to provide required information on data processing to users. The case concerns breaches of data protection rules. | IT | Garante | GDPR | €20,400 | ↗ |
| 20 Jul 2017 | Aria S.p.a.Aria S.p.a. was fined 20,000 EUR by the Garante. The authority found a data protection breach for failing to designate employees as data processors. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Jul 2017 | BARCLAYS BANK PLC Sucursal en EspañaBARCLAYS BANK PLC Sucursal en España was fined by the AEPD 5,000 EUR for sending commercial emails without meeting the requirements of Article 21 of the LSSI. The breach occurred despite the recipient's request to cancel their personal data. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 05 Jul 2017 | Istituto Auxologico ItalianoIstituto Auxologico Italiano was fined EUR 10,000 by the Garante for failing to implement adequate technical and organizational measures to protect sensitive personal data. The breach concerned the control and security of personal data contained in medical records, in violation of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Jul 2017 | Klik s.r.l.Klik s.r.l. was fined EUR 30,000 by the Garante for retaining telephone traffic data for more than 24 months. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 05 Jul 2017 | Compagnia Generale Trattori S.p.A.Compagnia Generale Trattori S.p.A. was fined by the Garante EUR 20,000 for using a GPS/GPRS system to monitor employee activities without proper notification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Jul 2017 | Vodafone Omnitel N.V.Vodafone Omnitel N.V. was fined by the Italian data protection authority, Garante, in the amount of 40,000 EUR. The sanction concerned the use of a group authentication credential to access personal data, which breached the security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 26 Jun 2017 | LEAD CONVERSION S.L.LEAD CONVERSION S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails without prior recipient consent. The conduct breached electronic communications rules and marketing consent requirements. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 22 Jun 2017 | Bolos & SynergatesThe law firm Bolos & Synergates was fined EUR 1,000 by the HDPA for unlawfully collecting and using personal data for direct marketing. The violation involved unsolicited electronic communications sent without prior consent from the data subjects. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 22 Jun 2017 | Adsalsa Italia Publicidad SucursalAdsalsa Italia Publicidad Sucursal was fined EUR 20,000 by the Garante. The authority found that personal data were processed without obtaining separate consent for each purpose, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Jun 2017 | Bookingshow s.p.a.Bookingshow s.p.a. was fined EUR 62,000 by the Garante for unlawfully processing personal data. The company required mandatory consent for promotional purposes during online ticket purchases, which breached data processing rules. | IT | Garante | GDPR | €62,000 | ↗ |
| 22 Jun 2017 | Vodafone-PanafonVodafone-Panafon was fined EUR 10,000 by the HDPA for a significant delay in responding to a data subject access request. The authority found a breach of Article 12 of Law L.2472/1997. | GR | HDPA | GDPR | €10,000 | ↗ |
| 15 Jun 2017 | F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante 16,000 EUR for making unsolicited promotional calls. The authority found that the required privacy notice was not provided and consent was not obtained, in breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 15 Jun 2017 | Azienda Policlinico Umberto IAzienda Policlinico Umberto I was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate data processing officers and provide them with the necessary instructions, breaching minimum security measures under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Jun 2017 | F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante in the amount of 10,000 EUR for making unsolicited promotional calls to a number listed in the public opposition registry. The conduct breached data protection rules and the right to object to direct marketing. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Jun 2017 | DALMORRIS, S.L.DALMORRIS, S.L. was fined by the AEPD in the amount of 600 EUR for sending an unsolicited commercial email. The conduct breached Article 21.1 of the LSSI, which prohibits unwanted marketing communications. | ES | AEPD | ePrivacy | €600 | ↗ |
| 12 Jun 2017 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 3,300 EUR for sending commercial communications to a former customer after a request for data cancellation. The authority also noted an allegation of sharing personal data with third parties without consent. | ES | AEPD | ePrivacy | €3,300 | ↗ |