BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2019 | AVON COSMETICS SAUAVON COSMETICS SAU was fined by the AEPD 60,000 EUR for improper processing of personal data. The company included an individual in a creditworthiness file without first verifying the person’s identity. | ES | AEPD | GDPR | €60,000 | ↗ |
| 31 Mar 2016 | avv. Gioacchino GenchiAvv. Gioacchino Genchi was fined by the Italian Garante for creating a database containing personal data, including phone traffic data. The database was accessible to his collaborators, which breached data protection rules. | IT | Garante | GDPR | €192,000 | ↗ |
| 19 Mar 2015 | avv. Luciana Candriella CadettoThe lawyer transmitted a legal document containing excessive personal and sensitive data, including data relating to a minor, without proper consent. The authority found a breach of data protection rules and imposed a 4,000 EUR fine. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Apr 2015 | avv. Pasquale GiordanoAvv. Pasquale Giordano was fined EUR 4,000 by the Italian data protection authority, Garante. The sanction concerned the disclosure of a client's personal data to the opposing party's lawyer in a divorce proceeding without the client's consent, in breach of Article 23 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Feb 2017 | Avv. Silvana VassalliAvv. Silvana Vassalli was fined by the Garante for unlawful processing of personal data. The breach involved transmitting an email containing personal data without proper authorization. | IT | Garante | GDPR | €8,000 | ↗ |
| 07 Jun 2024 | AXA REAL ESTATE INVESTMENT MANAGERS IBERICA S.A.AXA Real Estate Investment Managers Iberica S.A. was fined by the AEPD for failing to implement adequate security measures. The deficiency resulted in a data breach involving personal data stored on an encrypted USB drive. | ES | AEPD | GDPR | €100,000 | ↗ |
| 22 Oct 2025 | AXARNET COMUNICACIONES, S.L.AXARNET COMUNICACIONES, S.L. suffered a data breach caused by a vulnerability in a third-party program. The incident exposed personal data of 50,250 clients, including names, email addresses, and bank account details, leading to a fine by the AEPD. | ES | AEPD | GDPR | €20,000 | ↗ |
| 15 Nov 2024 | AXARQUIA VELEZ DENTAL, S.L.AXARQUIA VELEZ DENTAL, S.L. was fined by the AEPD 5,000 EUR for failing to properly signpost the video surveillance system inside its premises. The authority found a breach of GDPR transparency requirements. | ES | AEPD | GDPR | €5,000 | ↗ |
| 28 Nov 2013 | Axa società cooperativa a responsabilità limitataAxa società cooperativa a responsabilità limitata was fined by the Garante 46,000 EUR for using biometric systems to monitor employee attendance and working hours. The authority found that the processing took place without proper consent and required notifications, in breach of data protection rules. | IT | Garante | GDPR | €46,000 | ↗ |
| 11 Jan 2023 | AXEL SPRINGER ESPAÑA S.AAXEL SPRINGER ESPAÑA S.A was fined 5,000 EUR by the AEPD for non-compliance with data protection rules in its cookie policy. The website required users to disable providers individually and did not offer an option to disable all cookies at once. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 25 Jul 2013 | Axis Strategic Vision srlAxis Strategic Vision srl was fined by the Garante in the amount of 4,800 EUR for providing inadequate privacy notices on its websites. The authority found that the notices did not meet data protection requirements. | IT | Garante | GDPR | €4,800 | ↗ |
| 28 Sept 2023 | Axpo Italia S.p.A.Axpo Italia S.p.A. was fined by the Garante 10,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the conclusion of unsolicited contracts for electricity and gas supply. | IT | Garante | GDPR | €10,000,000 | ↗ |
| 08 Jun 2023 | AziendaThe company was fined for failing to process personal data in a lawful, fair, and transparent manner. The authority also found breaches of data minimization and inadequate security measures. | IT | Garante | GDPR | €5,000 | ↗ |
| 17 Oct 2024 | AziendaThe company was fined for failing to implement adequate security measures, which led to a data breach affecting a large number of individuals. The case indicates insufficient protection of personal data and elevated risk to data subjects. | IT | Garante | GDPR | €25,000 | ↗ |
| 23 Mar 2023 | Azienda 1 di SassariThe Garante imposed a fine of 4,000 EUR on Azienda 1 di Sassari for violations related to the processing of personal data, including health data. The authority found that adequate security measures were not in place for this processing. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Jun 2015 | Azienda di Servizi per la persona "Carlo Pezzani" di VogheraThe company published the personal data of five guests on its website without a legal basis. This breached privacy rules and led to a fine imposed by the Garante. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Jun 2011 | Azienda mobilità trasporti di Bari s.p.a.Azienda mobilità trasporti di Bari s.p.a. was fined by the Garante for processing employees' biometric data without proper notice, consent, or adequate information. The authority found violations of several provisions of the Italian data protection code. | IT | Garante | GDPR | €34,000 | ↗ |
| 15 Jun 2011 | Azienda Multiservizi e Igiene Urbana S.p.A.Azienda Multiservizi e Igiene Urbana S.p.A. was fined for collecting personal data through a web form without providing users with the required privacy notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 07 Dec 2023 | Azienda OspedalieraAzienda Ospedaliera was fined EUR 8,000 by the Garante for breaches of data protection rules. The case concerned data processing principles and insufficient security measures. | IT | Garante | GDPR | €8,000 | ↗ |
| 12 Mar 2015 | Azienda Ospedaliera Bolognini di SeriateAzienda Ospedaliera Bolognini di Seriate was fined by the Garante for sending medical reports to an incorrect address without the patient's consent. The case involved a breach of data protection rules and the confidentiality of medical information. | IT | Garante | GDPR | €4,000 | ↗ |