Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Nov 2024Uptime-IT ApSUptime-IT ApS was fined by Datatilsynet 40,000 DKK for failing to implement adequate security measures as a data processor. This led to a ransomware attack that encrypted sensitive personal data, including health information and CPR numbers, which could not be restored.DKDatatilsynetGDPR€5,362
13 Nov 2024Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 8,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data. The decision indicates non-compliance with core rules on lawful and proper processing.ITGaranteGDPR€8,000
13 Nov 2024Sligo County CouncilThe Irish DPC imposed a fine of EUR 29,500 on Sligo County Council in inquiry 07/SIU/2018. The case status is listed as not confirmed.IEDPCGDPR€29,500
13 Nov 2024FederprivacyFederprivacy was fined EUR 6,000 by the Garante after a data breach caused by a cyberattack. The attack compromised the website, email accounts, and social media, indicating inadequate technical and organizational measures.ITGaranteGDPR€6,000
13 Nov 2024Montini Group S.r.l.Montini Group S.r.l. was fined EUR 6,000 by the Garante. The case concerned contacting an employee’s general practitioner without consent, which breached GDPR rules on processing health data.ITGaranteGDPR€6,000
13 Nov 2024Illumia S.p.A.Illumia S.p.A. was fined by the Italian data protection authority, Garante, for violations related to the processing of personal data for telemarketing purposes. The authority cited inadequate contractual arrangements with sub-processors and insufficient oversight of commercial partners.ITGaranteGDPR€678,000
13 Nov 2024Spinacqua S.r.l.Spinacqua S.r.l. was fined by the Garante €10,000 for making unsolicited promotional calls to a number listed in the Public Opposition Register. The company did not obtain consent and failed to verify the number’s registration status before contacting it.ITGaranteGDPR€10,000
13 Nov 2024Thermogen S.r.l.Thermogen S.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The conduct breached the GDPR and national privacy laws.ITGaranteGDPR€10,000
13 Nov 2024UP ROMÂNIA SRLUP ROMÂNIA SRL was fined EUR 4,000 by ANSPDCP for processing employees’ identification and location data during their free time without a legal basis. The authority found breaches of legality, transparency, and data minimization principles.ROANSPDCPGDPR€4,000
13 Nov 2024Istituto Nazionale della Previdenza SocialeThe Italian Data Protection Authority fined Istituto Nazionale della Previdenza Sociale (INPS) EUR 40,000 for violations related to the processing of personal data for official statistics. The authority found that the processing did not comply with core data protection principles.ITGaranteGDPR€40,000
13 Nov 2024Comune di UgentoThe Garante fined Comune di Ugento 2,400 EUR for publishing data on its website that could reveal individuals' health status. The case involved the improper disclosure of sensitive information in a public online setting.ITGaranteGDPR€2,400
14 Nov 2024Comune di MaddaloniThe Garante fined Comune di Maddaloni EUR 2,000 for failing to communicate the Data Protection Officer’s contact details to the Authority. This constituted a breach of Article 37(7) GDPR.ITGaranteGDPR€2,000
14 Nov 2024Comune di Borgo Val di TaroComune di Borgo Val di Taro was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€8,000
14 Nov 2024Mario IonàMario Ionà was fined EUR 2,000 by the Garante for sending unsolicited emails and SMS promoting a tutoring service. The website lezioniprivate.eu did not provide information about the data controller, which added an information-duty breach.ITGaranteGDPR€2,000
14 Nov 2024OPERATEUR DE TELECOMMUNICATIONSOPERATEUR DE TELECOMMUNICATIONS was issued an administrative fine of EUR 50 million and an injunction. The case concerns a CNIL decision dated 2024-11-14.FRCNILGDPR€50,000,000
14 Nov 2024D’Anna Assicurazioni S.r.l.D’Anna Assicurazioni S.r.l. was fined by the Garante 5,000 EUR for sending unsolicited promotional emails despite the recipient’s objection. The authority found this breached GDPR rules on data subject rights and transparency.ITGaranteGDPR€5,000
14 Nov 2024Provvedimento del 14 novembre 2024 [10104860]Garante imposed a EUR 40,000 fine on a healthcare company for failing to update its security assessments in response to increased cyberattacks. The authority found a breach of GDPR Article 32 because technical and organizational measures were not adjusted to the changed risk level.ITGaranteGDPR€40,000
14 Nov 2024Comune di Torre AnnunziataThe Garante imposed a EUR 2,000 fine on Comune di Torre Annunziata for failing to communicate the contact details of its Data Protection Officer. This obligation arises under Article 37(7) GDPR and is intended to ensure the supervisory authority can reach the DPO.ITGaranteGDPR€2,000
15 Nov 2024AXARQUIA VELEZ DENTAL, S.L.AXARQUIA VELEZ DENTAL, S.L. was fined by the AEPD 5,000 EUR for failing to properly signpost the video surveillance system inside its premises. The authority found a breach of GDPR transparency requirements.ESAEPDGDPR€5,000
18 Nov 2024Altex România S.A.ANSPDCP completed an investigation in October 2024 at Altex România S.A. and found violations of GDPR provisions. As a result, the company was fined EUR 20,000.ROANSPDCPGDPR€20,000