Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Apr 2026Poste Italiane S.p.a. e PostePay S.p.a.Poste Italiane S.p.a. and PostePay S.p.a. were sanctioned for unlawful processing of personal data in their Bancoposta and PostePay apps on Android devices. The apps required users to authorize access to data to detect malicious software, which breached GDPR principles.ITGaranteGDPR€6,624,000
17 Apr 2026Comune di VeneziaThe Municipality of Venice was fined €3,000 by the Garante for failing to ensure the required transparency in data processing. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€3,000
17 Apr 2026Pak StorePak Store was fined EUR 2,000 by the Garante for using a CCTV camera without the required signage and without the necessary authorization from the Labour Inspectorate. The authority found a breach of the information obligations under GDPR Article 13.ITGaranteGDPR€2,000
17 Apr 2026The European House - Ambrosetti S.p.A.The European House - Ambrosetti S.p.A. was fined by Garante 85,000 EUR for a data breach. The incident involved unauthorized access and exfiltration of personal and authentication data affecting an unspecified number of individuals.ITGaranteGDPR€85,000
17 Apr 2026Comune di CogoletoComune di Cogoleto was fined EUR 4,000 by the Garante for failing to ensure transparency in data processing. The authority also found that no data protection impact assessment had been carried out, breaching the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
17 Apr 2026Io e te s.r.l.s.Io e te s.r.l.s. was fined EUR 2,000 by the Italian Garante. The case concerned improper use of a surveillance camera that enabled remote viewing through a mobile application without proper authorization.ITGaranteGDPR€2,000
17 Apr 2026Carlo Maria Antonio ParisiThe Garante fined Carlo Maria Antonio Parisi, owner of the online newspaper “giornalistitalia.it”, EUR 2,500. The authority found inadequate technical and organizational measures to support data subject rights and delays in handling requests without undue delay.ITGaranteGDPR€2,500
17 Apr 2026Ausl ModenaAusl Modena was fined by the Garante in the amount of 3,500 EUR for creating duplicate patient records. The case involved processing health data without proper transparency and compliance with data protection rules.ITGaranteGDPR€3,500
17 Apr 2026Comune di Mazara del ValloThe Garante fined Comune di Mazara del Vallo 6,000 EUR for violations related to the online publication of personal data. The case concerned the improper disclosure of personal information through online publication.ITGaranteGDPR€6,000
17 Apr 2026Azienda USL ModenaAzienda USL Modena was fined by the Garante in the amount of 10,000 EUR for a data breach caused by a ransomware attack. The authority found a breach of GDPR data security obligations.ITGaranteGDPR€10,000
17 Apr 2026Provvedimento del 17 aprile 2026 [10254325]The supervisory authority found that a video surveillance system with 25 cameras operated without the required informational signage. The breach concerned GDPR information obligations.ITGaranteGDPR€3,000
17 Apr 2026Associazione Movimento Cinque Stelle SiciliaThe Garante fined Associazione Movimento Cinque Stelle Sicilia 5,000 EUR for failing to adopt adequate technical and organizational measures to facilitate the exercise of data protection rights. The authority also found that requests were not addressed without undue delay.ITGaranteGDPR€5,000
17 Apr 2026Sicra PressThe Garante imposed a 2,000 EUR fine on Sicra Press for using non-anonymized data in articles related to judicial matters. The authority found a breach of data protection rules.ITGaranteGDPR€2,000
17 Apr 2026Istituto “Ancelle della Compagnia della Regina dei Gigli”The Garante fined the school EUR 4,000 for processing students’ personal data without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
28 Apr 2026RESIDENCIAL ETXE-LAN, S.L.RESIDENCIAL ETXE-LAN, S.L. was fined by the AEPD for failing to provide the required information to the supervisory authority. The breach concerned Article 58(1) GDPR and hindered the authority’s supervisory powers.ESAEPDGDPR€3,000
28 Apr 2026Fondation YThe APD Litigation Chamber fined Fondation Y EUR 1,000 for failing to respond to a data erasure request. The authority also found negligent cooperation with the data protection authority, constituting a breach of Article 31 GDPR.BEAPDGDPR€1,000
28 Apr 2026CROWD ENTERTAINMENT LIMITEDCROWD ENTERTAINMENT LIMITED was fined EUR 15,000 by ANSPDCP for GDPR violations. The case concerned non-compliant processing of personal data.ROANSPDCPGDPR€15,000
28 Apr 2026vzwDecision on the merits No. 94/2026 of 28 April 2026 was issued by the Belgian Gegevensbeschermingsautoriteit. A Belgian vzw was fined EUR 1,000 for failing to respond to registered letters and failing to appear at the hearing, which was treated as a breach of the GDPR cooperation duty.BEGegevensbeschermingsautoriteit (GBA)GDPR€1,000
28 Apr 2026CROWD ENTERTAINMENT LIMITEDCROWD ENTERTAINMENT LIMITED was fined EUR 20,000 by the Romanian authority ANSPDCP. The sanction concerned violations of GDPR requirements.ROANSPDCPGDPR€20,000
28 Apr 2026SIPHONE 2020, S.L.SIPHONE 2020, S.L. was fined by the AEPD 4,000 EUR for operating a video surveillance system that also recorded audio. Employees were not informed and did not consent, which breached privacy and data protection rules.ESAEPDGDPR€4,000