Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Jun 2026Artmark Holding SRLArtmark Holding SRL was fined by ANSPDCP 10,000 RON for sending unsolicited commercial emails without obtaining prior explicit consent from recipients. The case concerns a breach of rules on electronic marketing communications and consent requirements.ROANSPDCPePrivacy€1,908
26 Mar 2015Artsana s.p.a.Artsana s.p.a. was fined by the Garante for failing to provide adequate simplified information about its video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
23 Jul 2015Art Sposa s.r.l.Art Sposa s.r.l. was fined by the Garante in the amount of EUR 2,400 for failing to provide the required privacy notice to users submitting personal data through its website contact form. The conduct breached Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
10 Dec 2015Aruba s.p.a.Aruba s.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 40,000. The case concerned the sending of promotional emails without obtaining the required consent, in breach of articles 23 and 130 of the Italian data protection code.ITGaranteGDPR€40,000
27 Jul 2011ASCENDIA REINGENIERIA&CONSULTING S.L.U.ASCENDIA REINGENIERIA&CONSULTING S.L.U. was fined by the AEPD €600 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€600
12 Nov 2015A.S.D. Associazione di promozione culturale e sociale Social ClubA.S.D. Associazione di promozione culturale e sociale Social Club was fined EUR 2,400 by the Garante for publishing an inadequate privacy notice on its website. The authority found this to be a breach of Article 161 of the Italian Data Protection Code.ITGaranteGDPR€2,400
01 Jan 2025ASESORAMOS TU FORMACIÓN CON CALIDAD S.L.ASESORAMOS TU FORMACIÓN CON CALIDAD S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case also involved the improper inclusion of individuals in credit information systems.ESAEPDGDPR€10,000
03 Feb 2021ASESORÍA MUNIZ SOLÁN, S.L.ASESORÍA MUNIZ SOLÁN, S.L. was fined by the AEPD 2,000 EUR for breaching confidentiality after sending a debt certificate relating to a third party instead of the correct document. The authority also noted inadequate security measures under GDPR Article 32.ESAEPDGDPR€2,000
07 Dec 2023ASESORÍA Y PROGRAMACIÓN PROFESIONAL, S.L.The entity was fined for continuing to send advertising emails despite the recipient's attempts to unsubscribe. This conduct breached Article 21 of the LSSI and resulted in a EUR 5,000 penalty.ESAEPDePrivacy€5,000
13 Jan 2011Ashley s.r.l.Ashley s.r.l. was fined 6,000 EUR by the Garante for failing to provide adequate information to data subjects about its video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
22 Jan 2024ASILO DE ANCIANOS SANTO DOMINGO Y SANTA ELOISAThe organization was fined for repeatedly sending emails with visible recipient addresses. The case involved a breach of data protection principles and a failure to implement adequate security measures.ESAEPDGDPR€1,000
10 Jul 2025Asilo nido “La Combricola Dei Birichini Di Betty”The Garante imposed a 10,000 EUR fine on the nursery for failing to provide parents with the required information about the processing of children's images. It also found that no data protection impact assessment had been carried out for the surveillance system.ITGaranteGDPR€10,000
14 Sept 2006Asl 21 di Casale MonferratoThe Garante fined Asl 21 di Casale Monferrato 10,000 EUR for processing genetic and health data without the required notification. The authority found a breach of the Italian Privacy Code.ITGaranteGDPR€10,000
13 Feb 2007Asl Alto MoliseAsl Alto Molise was fined 10,000 EUR by the Garante for failing to notify data processing activities related to health diagnosis, treatment, and prevention within the required timeframe. The breach violated the Italian Data Protection Code.ITGaranteGDPR€10,000
13 Feb 2007Asl Basso MoliseAsl Basso Molise was fined by the Garante for failing to notify its data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code.ITGaranteGDPR€10,000
13 Sept 2007Asl Benevento 1The Garante fined Asl Benevento 1 10,000 EUR for failing to notify data processing activities within the required timeframe. The breach concerned Article 163 of the Italian Data Protection Code.ITGaranteGDPR€10,000
04 Apr 2007Asl Brindisi 1The Garante fined Asl Brindisi 1 for failing to notify the processing of personal data under the Italian Data Protection Code. Article 37 was violated, and the fine amounted to EUR 20,000.ITGaranteGDPR€20,000
13 Feb 2007Asl Centro MoliseAsl Centro Molise was fined by the Garante for processing personal data, including genetic and biometric data, without the required notification. The breach concerned obligations under the Italian data protection code.ITGaranteGDPR€10,000
13 Feb 2007Asl di Maglie (Lecce)Asl di Maglie (Lecce) was fined by the Garante for failing to notify personal data processing activities within the required timeframe. This constituted a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
20 Jun 2013ASL di SalernoASL di Salerno was fined EUR 18,000 by the Garante for failing to implement minimum security measures. The authority cited, among other issues, the absence of designated data processing managers and the use of common, outdated passwords for electronic systems.ITGaranteGDPR€18,000