BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Sept 2007 | Asl Enna 4The Garante fined Asl Enna 4 EUR 10,000 for processing personal data, including genetic and biometric data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Asl FerraraAsl Ferrara was fined by the Garante for processing genetic, health, and sexual life data without the required notification. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Dec 2021 | ASL LatinaASL Latina was fined for violations of data protection rules. The authority found inadequate measures to prevent data breaches involving health data. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Oct 2013 | ASL n.1 – Avezzano/Sulmona/L'AquilaASL n.1 – Avezzano/Sulmona/L'Aquila was fined EUR 8,000 by the Garante. The authority found a breach consisting of failure to make the notification required under the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 14 Nov 2019 | ASL n. 2 SavoneseASL n. 2 Savonese was fined EUR 8,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data, including failures to comply with lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Feb 2007 | Asl n. 5 CrotoneAsl n. 5 Crotone was fined by the Garante for failing to notify the processing of sensitive personal data, including genetic and health data. The notification requirement was set out in the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Asl n. 8 di Asolo (TV)Asl n. 8 di Asolo was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The notification was required under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Jan 2022 | A.S.L. Napoli 1 CentroA.S.L. Napoli 1 Centro was fined EUR 6,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data in violation of lawfulness, fairness, transparency, and data minimization requirements. | IT | Garante | GDPR | €6,000 | ↗ |
| 20 Nov 2014 | Asl Napoli 2 nordThe Garante imposed a 16,000 EUR fine on Asl Napoli 2 nord for failing to designate data protection officers and for keeping surveillance footage longer than permitted without prior authorization. The case concerned organizational compliance failures and unlawful data retention. | IT | Garante | GDPR | €16,000 | ↗ |
| 13 May 2015 | ASL Napoli 2 NordASL Napoli 2 Nord was fined 20,000 EUR by the Garante for publishing personal data on its website. The disclosed information could reveal individuals' health status, which breached privacy rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 28 Sept 2023 | Asl Napoli 3 SudThe Garante fined Asl Napoli 3 Sud EUR 30,000 for inadequate security measures that led to a data breach. The incident caused limited service disruption. | IT | Garante | GDPR | €30,000 | ↗ |
| 08 Feb 2007 | Asl OristanoAsl Oristano was fined EUR 10,000 by the Garante for failing to notify the processing of personal data concerning health and sexual life. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Feb 2016 | A.S.L. Roma 2A.S.L. Roma 2 was fined EUR 4,000 by the Garante for failing to respond to requests for information concerning the processing of personal data relating to a minor's civil disability. The authority found this to be a breach of Article 164 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Sept 2007 | Asl Salerno 2Asl Salerno 2 was fined EUR 10,000 by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Sept 2007 | Asl San Severo (Foggia 1)Asl San Severo (Foggia 1) was fined by the Garante for processing personal data, including genetic and biometric data, without proper compliance with data protection rules. The case indicates insufficient legal basis and safeguards for the handling of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Asl VercelliAsl Vercelli was fined by the Garante for processing special-category personal data, including genetic and health data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 Feb 2007 | Asl Vibo ValentiaThe health authority Asl Vibo Valentia was fined by Garante for improperly handling sensitive personal data, including genetic and biometric data, without proper authorization. The case concerns a breach of data protection rules and the legal basis required for processing such data. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | a small recruitment bureauA small recruitment bureau in the Netherlands was fined EUR 6,000 by the Autoriteit Persoonsgegevens for failing to respond on time to an ex-candidate’s request to delete personal data. The Raad van State upheld the fine in case ECLI:NL:RVS:2024:2221. | NL | Autoriteit Persoonsgegevens | GDPR | €6,000 | ↗ |
| 01 Jan 2021 | ASM PRATASM PRAT was fined EUR 5,000 by the AEPD for requiring recipients to submit photos of their ID cards without consent. The company also failed to provide information about the data processing, which breached data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 15 Jul 2024 | ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD 200,000 EUR for failing to properly handle a data subject’s request for deletion and for processing personal data without a legal basis. The case concerns breaches of core data protection obligations. | ES | AEPD | GDPR | €200,000 | ↗ |