BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Jun 2026 | Artmark Holding SRLArtmark Holding SRL was fined by ANSPDCP 10,000 RON for sending unsolicited commercial emails without obtaining prior explicit consent from recipients. The case concerns a breach of rules on electronic marketing communications and consent requirements. | RO | ANSPDCP | ePrivacy | €1,908 | ↗ |
| 26 Mar 2015 | Artsana s.p.a.Artsana s.p.a. was fined by the Garante for failing to provide adequate simplified information about its video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 23 Jul 2015 | Art Sposa s.r.l.Art Sposa s.r.l. was fined by the Garante in the amount of EUR 2,400 for failing to provide the required privacy notice to users submitting personal data through its website contact form. The conduct breached Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 10 Dec 2015 | Aruba s.p.a.Aruba s.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 40,000. The case concerned the sending of promotional emails without obtaining the required consent, in breach of articles 23 and 130 of the Italian data protection code. | IT | Garante | GDPR | €40,000 | ↗ |
| 27 Jul 2011 | ASCENDIA REINGENIERIA&CONSULTING S.L.U.ASCENDIA REINGENIERIA&CONSULTING S.L.U. was fined by the AEPD €600 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €600 | ↗ |
| 12 Nov 2015 | A.S.D. Associazione di promozione culturale e sociale Social ClubA.S.D. Associazione di promozione culturale e sociale Social Club was fined EUR 2,400 by the Garante for publishing an inadequate privacy notice on its website. The authority found this to be a breach of Article 161 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 01 Jan 2025 | ASESORAMOS TU FORMACIÓN CON CALIDAD S.L.ASESORAMOS TU FORMACIÓN CON CALIDAD S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case also involved the improper inclusion of individuals in credit information systems. | ES | AEPD | GDPR | €10,000 | ↗ |
| 03 Feb 2021 | ASESORÍA MUNIZ SOLÁN, S.L.ASESORÍA MUNIZ SOLÁN, S.L. was fined by the AEPD 2,000 EUR for breaching confidentiality after sending a debt certificate relating to a third party instead of the correct document. The authority also noted inadequate security measures under GDPR Article 32. | ES | AEPD | GDPR | €2,000 | ↗ |
| 07 Dec 2023 | ASESORÍA Y PROGRAMACIÓN PROFESIONAL, S.L.The entity was fined for continuing to send advertising emails despite the recipient's attempts to unsubscribe. This conduct breached Article 21 of the LSSI and resulted in a EUR 5,000 penalty. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 13 Jan 2011 | Ashley s.r.l.Ashley s.r.l. was fined 6,000 EUR by the Garante for failing to provide adequate information to data subjects about its video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 22 Jan 2024 | ASILO DE ANCIANOS SANTO DOMINGO Y SANTA ELOISAThe organization was fined for repeatedly sending emails with visible recipient addresses. The case involved a breach of data protection principles and a failure to implement adequate security measures. | ES | AEPD | GDPR | €1,000 | ↗ |
| 10 Jul 2025 | Asilo nido “La Combricola Dei Birichini Di Betty”The Garante imposed a 10,000 EUR fine on the nursery for failing to provide parents with the required information about the processing of children's images. It also found that no data protection impact assessment had been carried out for the surveillance system. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Asl 21 di Casale MonferratoThe Garante fined Asl 21 di Casale Monferrato 10,000 EUR for processing genetic and health data without the required notification. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl Alto MoliseAsl Alto Molise was fined 10,000 EUR by the Garante for failing to notify data processing activities related to health diagnosis, treatment, and prevention within the required timeframe. The breach violated the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl Basso MoliseAsl Basso Molise was fined by the Garante for failing to notify its data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Sept 2007 | Asl Benevento 1The Garante fined Asl Benevento 1 10,000 EUR for failing to notify data processing activities within the required timeframe. The breach concerned Article 163 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Apr 2007 | Asl Brindisi 1The Garante fined Asl Brindisi 1 for failing to notify the processing of personal data under the Italian Data Protection Code. Article 37 was violated, and the fine amounted to EUR 20,000. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Feb 2007 | Asl Centro MoliseAsl Centro Molise was fined by the Garante for processing personal data, including genetic and biometric data, without the required notification. The breach concerned obligations under the Italian data protection code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl di Maglie (Lecce)Asl di Maglie (Lecce) was fined by the Garante for failing to notify personal data processing activities within the required timeframe. This constituted a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Jun 2013 | ASL di SalernoASL di Salerno was fined EUR 18,000 by the Garante for failing to implement minimum security measures. The authority cited, among other issues, the absence of designated data processing managers and the use of common, outdated passwords for electronic systems. | IT | Garante | GDPR | €18,000 | ↗ |