BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Jun 2014 | Sudmetal s.r.l.Sudmetal s.r.l. was fined for using an integrated video surveillance system that allowed images from workplaces to be viewed without the required safeguards. The authority found this to be a breach of privacy regulations. | IT | Garante | GDPR | €12,000 | ↗ |
| 13 Apr 2023 | Suditaly Imprese Meridionali Soc. coop.The Garante imposed a 2,500 EUR fine on Suditaly Imprese Meridionali Soc. coop. for publishing detailed health data without the data subjects' consent. The case concerned Article 9 of the GDPR, which restricts processing of special categories of personal data. | IT | Garante | GDPR | €2,500 | ↗ |
| 15 Mar 2018 | Studio Silver Consulting S.r.l.s.Studio Silver Consulting S.r.l.s. was fined EUR 30,000 by the Garante for violations related to the processing of personal data in its debt management activities. The case concerned improper handling of personal data in the context of debt collection operations. | IT | Garante | GDPR | €30,000 | ↗ |
| 19 Dec 2024 | Studio Riabilitazione Creditizia s.r.l.s.The Garante fined Studio Riabilitazione Creditizia s.r.l.s. €70,000 for improperly accessing financial data from the Central Credit Register without proper authorization. The authority found this conduct breached data protection principles. | IT | Garante | GDPR | €70,000 | ↗ |
| 27 Oct 2016 | Studio Medico Odontoiatrico Associato Gimmelli B. & G.Studio Medico Odontoiatrico Associato Gimmelli B. & G. was fined by the Garante for unlawfully processing personal data by disclosing it to Ina Assitalia s.p.a. without obtaining the required informed consent from the data subject. The case reflects a breach of core lawful-processing requirements. | IT | Garante | GDPR | €6,400 | ↗ |
| 13 Dec 2012 | Studio Immobiliare Conca D'Oro s.r.l.Studio Immobiliare Conca D'Oro s.r.l. was fined by the Garante 6,400 EUR for making promotional phone calls without providing the required information notice and without obtaining consent. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €6,400 | ↗ |
| 24 Nov 2022 | STS Di Prisinzano s.r.l.STS Di Prisinzano s.r.l. was fined EUR 1,000 by the Garante for failing to provide a data subject with an adequate privacy notice during roadside assistance. The authority found a breach of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |
| 01 Jan 2025 | STRATESYS TECHNOLOGY SOLUTIONS, S.L.STRATESYS TECHNOLOGY SOLUTIONS, S.L. was fined EUR 100,000 by the AEPD for breaching Article 5(1)(f) of the GDPR. The case concerned a failure to protect the integrity and confidentiality of personal data. | ES | AEPD | GDPR | €100,000 | ↗ |
| 12 May 2017 | Strategy MentorThe fine was imposed for sending unsolicited marketing emails to a large number of recipients without prior consent. This conduct breached ePrivacy rules governing electronic marketing communications. | GR | HDPA | ePrivacy | €75,000 | ↗ |
| 10 Jan 2025 | Stowarzyszenie „Maraton” z GorlicThe President of the Personal Data Protection Office imposed an administrative fine of PLN 916.71 on Stowarzyszenie „Maraton” z Gorlic. The penalty concerned failure to notify a personal data breach within the required 72-hour deadline, together with related compliance shortcomings. | PL | Prezes Urzędu Ochrony Danych Osobowych | GDPR | €215 | ↗ |
| 24 Jan 2022 | Stortingets administrasjonThe Norwegian DPA notified the Storting's administration of a NOK 2,000,000 fine for failing to implement adequate technical and organizational measures, including two-factor authentication. The deficiency led to a data breach affecting email accounts of representatives and staff. | NO | Datatilsynet | GDPR | €196,000 | ↗ |
| 21 Jun 2021 | Storstockholms Lokaltrafik, SLStorstockholms Lokaltrafik, SL was fined by IMY for using body-worn cameras without a legal basis. The authority found breaches of the GDPR principles of lawfulness, transparency, and data minimization. | SE | IMY | GDPR | €1,566,000 | ↗ |
| 19 Dec 2024 | STOMATOLOGUE (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on STOMATOLOGUE under a simplified procedure. The case concerned a breach that resulted in an administrative sanction. | FR | CNIL | GDPR | €5,000 | ↗ |
| 27 Jan 2021 | STOCKHUNTERS, S.L.STOCKHUNTERS, S.L. was fined EUR 4,000 by the AEPD for failing to comply with GDPR Article 13. The authority found that the website privacy policy did not meet the required information standards. | ES | AEPD | GDPR | €4,000 | ↗ |
| 20 Mar 2024 | Stjarnan ehf.Stjarnan ehf., operating Subway in Iceland, was fined by Persónuvernd for unlawful electronic surveillance of employees. The authority found that employees were not properly notified and were not adequately informed about their rights. | IS | Persónuvernd | GDPR | €10,095 | ↗ |
| 15 Dec 2016 | Stireria Rosa di HU XINStireria Rosa di HU XIN was fined 2,400 EUR by the Garante. The authority found that the company failed to inform data subjects about the processing of personal data through a video surveillance system covering public areas. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Apr 2013 | Stifter Josef KG.Stifter Josef KG. was fined by the Garante for failing to provide the required data protection notice to customers when collecting personal data during e-commerce transactions. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Apr 2013 | Stifter Josef KGStifter Josef KG was fined 2,400 EUR by the Garante. The company failed to provide the required data protection notice to customers when collecting personal data during online orders. | IT | Garante | GDPR | €2,400 | ↗ |
| 08 Jul 2025 | Stichting Oud LemmerStichting Oud Lemmer was fined by the AP 500 EUR for processing personal data without a legal basis. The case concerned live streaming camera footage of public spaces, which breached GDPR Articles 5 and 6. | NL | AP | GDPR | €500 | ↗ |
| 11 May 2021 | Stichting Ondersteuning Provinciale Fractie Overijssel Partij voor de Vrijheid (PVV Overijssel)PVV Overijssel was fined by the AP EUR 7,500 for failing to report a personal data breach within the required 72-hour period. The case concerns a delayed notification to the supervisory authority about a security incident. | NL | AP | GDPR | €7,500 | ↗ |