Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 May 2024Azienda USL della RomagnaThe Garante imposed a fine of EUR 8,400 on Azienda USL della Romagna for violations related to data processing operations. The processes were largely manual and dependent on operator diligence, which led to a data breach.ITGaranteGDPR€8,400
21 Apr 2011Azienda USL della Valle D'AostaAzienda USL della Valle D'Aosta was fined for processing personal data during phone bookings without providing the required information notice and for failing to update the security program document. The authority found these actions breached data protection rules.ITGaranteGDPR€20,000
29 Apr 2021Azienda Usl di BolognaThe Garante fined Azienda Usl di Bologna EUR 30,000 for violations related to the processing of personal data in the electronic health record. The case resulted in a data breach, indicating deficiencies in the protection or handling of patient data.ITGaranteGDPR€30,000
14 Jan 2021Azienda Usl di BolognaAzienda Usl di Bologna was fined by the Garante 18,000 EUR for violations related to personal data protection in the healthcare sector. The case concerned irregularities in the processing of patient data, which breached data protection requirements.ITGaranteGDPR€18,000
02 Dec 2021Azienda USL di ParmaAzienda USL di Parma was fined by the Garante for a data breach involving the unauthorized disclosure of health data. The incident affected one individual and did not result in significant harm, but it was still treated as a GDPR violation.ITGaranteGDPR€5,000
17 Apr 2026Azienda USL ModenaAzienda USL Modena was fined by the Garante in the amount of 10,000 EUR for a data breach caused by a ransomware attack. The authority found a breach of GDPR data security obligations.ITGaranteGDPR€10,000
06 Jun 2024Azienda Usl RomagnaThe Garante fined Azienda Usl Romagna EUR 24,000 for data protection violations related to the management of health data. The case concerned irregularities in the processing of sensitive data, which requires heightened safeguards and GDPR compliance.ITGaranteGDPR€24,000
28 Sept 2023Azienda Usl Toscana centroThe Garante imposed a fine of EUR 50,000 on Azienda Usl Toscana centro for data protection violations related to the former Sanatorio Guido Banti premises. The case concerned irregularities in the processing of personal data in that context.ITGaranteGDPR€50,000
22 Feb 2024Azienda Usl Valle d’AostaThe Garante imposed a EUR 75,000 fine on Azienda Usl Valle d’Aosta for unauthorized access to patient health records. Healthcare professionals who were not involved in the patients’ care accessed the data, breaching GDPR data protection requirements.ITGaranteGDPR€75,000
10 Nov 2022Azienda Usl Valle d’AostaAzienda Usl Valle d’Aosta was fined EUR 40,000 by the Garante for unlawful access to a patient's health dossier. The access was made by a healthcare professional not involved in the patient's care, breaching GDPR data processing principles.ITGaranteGDPR€40,000
12 Sept 2013Azienda USL ViterboAzienda USL Viterbo was fined for failing to implement minimum security measures and for not appointing data processing officers. The authority also noted that the security program document was not updated between 2006 and 2010.ITGaranteGDPR€10,000
23 Oct 2025Azzurra Sport s.r.l.Azzurra Sport s.r.l. was fined EUR 4,000 by the Garante for unlawful processing of personal data through a video surveillance system. The breach concerned the absence of appropriate informational signage for individuals subject to the monitoring.ITGaranteGDPR€4,000
09 May 2024Azzurro Club Hotels S.r.l.Azzurro Club Hotels S.r.l. was fined by the Garante 10,000 EUR for sending promotional emails without consent. The company also failed to respond to a data subject’s request for information under Article 15 GDPR.ITGaranteGDPR€10,000
01 Jan 2025B3C CONSULTORÍA DE SERVICIOS 2010 S.L.B3C CONSULTORÍA DE SERVICIOS 2010 S.L. was fined by the AEPD EUR 800 for subcontracting TELCO without authorization from the data controller, AIRE NETWORKS. The company also failed to impose the required contractual obligations on TELCO, breaching GDPR Articles 28.2 and 28.4.ESAEPDGDPR€800
16 Dec 2020Babaváró kölcsönnel összefüggésben végzett adatkezelés – várandósgondozási könyvekről való másolatkészítés jogszerűségeThe supervisory authority found that the entity processed personal and health data from maternity care records without a legal basis in connection with Babaváró loan applications. It also failed to provide clear and transparent information about the processing, breaching GDPR principles.HUNAIHGDPR€98,350
22 Oct 2015Bagni Miramare srlBagni Miramare srl was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned collecting email addresses through its website without providing the required privacy notice, in breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
17 Jan 2013Bagno sport 70 s.a.s.Bagno sport 70 s.a.s. was fined 8,000 EUR by the Garante for processing customers' biometric data for payments. The company failed to notify the supervisory authority, which breached the Italian Data Protection Code.ITGaranteGDPR€8,000
12 Mar 2026Bakeca s.r.l.Bakeca s.r.l. was fined €5,000 by the Italian data protection authority, Garante. The case concerned the publication of online ads without the required consent, which breached data protection rules.ITGaranteGDPR€5,000
24 Oct 2013Balangero SerenaBalangero Serena was fined by the Garante in the amount of 4,000 EUR for non-compliance with data protection rules in the use of surveillance cameras at Murphy's Bar. The authority found that privacy notices for individuals under surveillance were inadequate.ITGaranteGDPR€4,000
21 Oct 2010Baldomero **** y Jesús ***** CBBaldomero **** y Jesús ***** CB was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent from recipients. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,001