BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Feb 2016 | Asociación de Empresarios de Tecnologías de la Información y Comunicaciones de Andalucía (ETICOM)ETICOM was fined €3,400 by the AEPD for sending unsolicited commercial emails without prior consent from recipients. The authority also found that the messages did not include a simple opt-out mechanism, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,400 | ↗ |
| 18 Feb 2016 | Banco dell'oro Operatori professionali in oro srlBanco dell'oro Operatori professionali in oro srl was fined by the Garante EUR 2,400 for operating a video surveillance system without the required data protection notice. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 18 Feb 2016 | Europa Investigazioni s.r.lEuropa Investigazioni s.r.l was fined EUR 8,000 by the Garante. The authority found that the company failed to notify the processing of data indicating the geographical position of individuals or objects via an electronic communications network. | IT | Garante | GDPR | €8,000 | ↗ |
| 16 Feb 2016 | ROCK INTERNET, S.L.ROCK INTERNET, S.L. was fined EUR 30,000 by the AEPD for sending unsolicited commercial emails despite the recipient’s repeated requests to unsubscribe. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 11 Feb 2016 | Anteprima Group srlAnteprima Group srl was fined EUR 6,400 by the Garante. The case concerned an unsolicited promotional call made without prior information to the recipient and without obtaining consent. | IT | Garante | GDPR | €6,400 | ↗ |
| 11 Feb 2016 | E-Via s.p.a.E-Via s.p.a. was fined 10,000 EUR by the Garante for failing to implement minimum security measures in the processing of telematic traffic data. The authority found a breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Feb 2016 | Vito Roma s.r.l.Vito Roma s.r.l. was fined by the Garante for operating a video surveillance system without providing the required data protection notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 11 Feb 2016 | Circolo ricreativo D.D. PeckerCircolo ricreativo D.D. Pecker was fined by the Garante for providing inadequate information to data subjects about the processing of their personal data. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Feb 2016 | Fondazione IRCCS Cà Granda, Ospedale Maggiore PoliclinicoFondazione IRCCS Cà Granda, Ospedale Maggiore Policlinico was fined by the Garante €10,000 for unlawful processing of personal data. The breach involved the incorrect delivery of documents containing health information of third parties. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Feb 2016 | A.S.L. Roma 2A.S.L. Roma 2 was fined EUR 4,000 by the Garante for failing to respond to requests for information concerning the processing of personal data relating to a minor's civil disability. The authority found this to be a breach of Article 164 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Feb 2016 | Istituto Tecnico Industriale Ettore MajoranaIstituto Tecnico Industriale Ettore Majorana was fined for processing biometric data for attendance tracking without the required notification to the Garante. This breached the Italian Privacy Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 04 Feb 2016 | DIVULGACION DINAMICA, S.L.DIVULGACION DINAMICA, S.L. was fined by the AEPD EUR 600 for sending commercial emails without prior consent from recipients. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 04 Feb 2016 | Hans Christoph Josef DietrichHans Christoph Josef Dietrich was fined EUR 4,000 by the Garante. The case concerned the public display of a list of patients who had not paid for medical services, which amounted to unauthorized disclosure of personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Jan 2016 | Planetcall s.r.l.Planetcall s.r.l. was fined €20,000 by the Garante for failing to designate data processors and for using inadequate authentication credentials. The case concerned breaches of the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Jan 2016 | Agenzia di promozione economica della ToscanaAgenzia di promozione economica della Toscana was fined 10,000 EUR by the Garante for publishing lists of disabled candidates admitted to competitive exams on its institutional websites. The authority found that this disclosure breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2016 | Punto Fermo s.r.l.Punto Fermo s.r.l. was fined by the Garante EUR 12,000 for retaining surveillance footage for 25 days. This exceeded the one-week limit set by the general rules on video surveillance. | IT | Garante | GDPR | €12,000 | ↗ |
| 21 Jan 2016 | Federico FabiFederico Fabi was fined by the Garante for failing to provide the required information to data subjects when collecting personal data through forms on the company’s website. The case concerns a breach of transparency and notice obligations under data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 21 Jan 2016 | Alfonso EspositoAlfonso Esposito, a gynecologist, was fined by the Garante for processing clients’ personal data for medical purposes without obtaining their consent. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jan 2016 | Comune di AdriaComune di Adria was fined EUR 4,000 by the Garante for unlawfully disclosing personal data of third parties. The authority sent photographic results to a complainant that contained data relating to other individuals, breaching data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Jan 2016 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 10,500 for sending unsolicited advertising SMS messages without prior recipient consent. The authority also found that no opt-out mechanism was provided, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €10,500 | ↗ |