BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 May 2024 | Azienda USL della RomagnaThe Garante imposed a fine of EUR 8,400 on Azienda USL della Romagna for violations related to data processing operations. The processes were largely manual and dependent on operator diligence, which led to a data breach. | IT | Garante | GDPR | €8,400 | ↗ |
| 21 Apr 2011 | Azienda USL della Valle D'AostaAzienda USL della Valle D'Aosta was fined for processing personal data during phone bookings without providing the required information notice and for failing to update the security program document. The authority found these actions breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Apr 2021 | Azienda Usl di BolognaThe Garante fined Azienda Usl di Bologna EUR 30,000 for violations related to the processing of personal data in the electronic health record. The case resulted in a data breach, indicating deficiencies in the protection or handling of patient data. | IT | Garante | GDPR | €30,000 | ↗ |
| 14 Jan 2021 | Azienda Usl di BolognaAzienda Usl di Bologna was fined by the Garante 18,000 EUR for violations related to personal data protection in the healthcare sector. The case concerned irregularities in the processing of patient data, which breached data protection requirements. | IT | Garante | GDPR | €18,000 | ↗ |
| 02 Dec 2021 | Azienda USL di ParmaAzienda USL di Parma was fined by the Garante for a data breach involving the unauthorized disclosure of health data. The incident affected one individual and did not result in significant harm, but it was still treated as a GDPR violation. | IT | Garante | GDPR | €5,000 | ↗ |
| 17 Apr 2026 | Azienda USL ModenaAzienda USL Modena was fined by the Garante in the amount of 10,000 EUR for a data breach caused by a ransomware attack. The authority found a breach of GDPR data security obligations. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Jun 2024 | Azienda Usl RomagnaThe Garante fined Azienda Usl Romagna EUR 24,000 for data protection violations related to the management of health data. The case concerned irregularities in the processing of sensitive data, which requires heightened safeguards and GDPR compliance. | IT | Garante | GDPR | €24,000 | ↗ |
| 28 Sept 2023 | Azienda Usl Toscana centroThe Garante imposed a fine of EUR 50,000 on Azienda Usl Toscana centro for data protection violations related to the former Sanatorio Guido Banti premises. The case concerned irregularities in the processing of personal data in that context. | IT | Garante | GDPR | €50,000 | ↗ |
| 22 Feb 2024 | Azienda Usl Valle d’AostaThe Garante imposed a EUR 75,000 fine on Azienda Usl Valle d’Aosta for unauthorized access to patient health records. Healthcare professionals who were not involved in the patients’ care accessed the data, breaching GDPR data protection requirements. | IT | Garante | GDPR | €75,000 | ↗ |
| 10 Nov 2022 | Azienda Usl Valle d’AostaAzienda Usl Valle d’Aosta was fined EUR 40,000 by the Garante for unlawful access to a patient's health dossier. The access was made by a healthcare professional not involved in the patient's care, breaching GDPR data processing principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Sept 2013 | Azienda USL ViterboAzienda USL Viterbo was fined for failing to implement minimum security measures and for not appointing data processing officers. The authority also noted that the security program document was not updated between 2006 and 2010. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Oct 2025 | Azzurra Sport s.r.l.Azzurra Sport s.r.l. was fined EUR 4,000 by the Garante for unlawful processing of personal data through a video surveillance system. The breach concerned the absence of appropriate informational signage for individuals subject to the monitoring. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 May 2024 | Azzurro Club Hotels S.r.l.Azzurro Club Hotels S.r.l. was fined by the Garante 10,000 EUR for sending promotional emails without consent. The company also failed to respond to a data subject’s request for information under Article 15 GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2025 | B3C CONSULTORÍA DE SERVICIOS 2010 S.L.B3C CONSULTORÍA DE SERVICIOS 2010 S.L. was fined by the AEPD EUR 800 for subcontracting TELCO without authorization from the data controller, AIRE NETWORKS. The company also failed to impose the required contractual obligations on TELCO, breaching GDPR Articles 28.2 and 28.4. | ES | AEPD | GDPR | €800 | ↗ |
| 16 Dec 2020 | Babaváró kölcsönnel összefüggésben végzett adatkezelés – várandósgondozási könyvekről való másolatkészítés jogszerűségeThe supervisory authority found that the entity processed personal and health data from maternity care records without a legal basis in connection with Babaváró loan applications. It also failed to provide clear and transparent information about the processing, breaching GDPR principles. | HU | NAIH | GDPR | €98,350 | ↗ |
| 22 Oct 2015 | Bagni Miramare srlBagni Miramare srl was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned collecting email addresses through its website without providing the required privacy notice, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 17 Jan 2013 | Bagno sport 70 s.a.s.Bagno sport 70 s.a.s. was fined 8,000 EUR by the Garante for processing customers' biometric data for payments. The company failed to notify the supervisory authority, which breached the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 12 Mar 2026 | Bakeca s.r.l.Bakeca s.r.l. was fined €5,000 by the Italian data protection authority, Garante. The case concerned the publication of online ads without the required consent, which breached data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 24 Oct 2013 | Balangero SerenaBalangero Serena was fined by the Garante in the amount of 4,000 EUR for non-compliance with data protection rules in the use of surveillance cameras at Murphy's Bar. The authority found that privacy notices for individuals under surveillance were inadequate. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Oct 2010 | Baldomero **** y Jesús ***** CBBaldomero **** y Jesús ***** CB was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent from recipients. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |