BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Jan 2015 | Comunicando di Rizzotto Fabio & C. s.a.s.Comunicando di Rizzotto Fabio & C. s.a.s. was fined €80,000 by the Garante for activating 88 phone cards in the names of 16 individuals without their knowledge. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €80,000 | ↗ |
| 29 Jan 2015 | Comune di BarzagoComune di Barzago was fined for failing to provide the required information notice to individuals whose personal data were processed for sending informational SMS messages. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 29 Jan 2015 | Iper Market Yi-Gou s.r.l.Iper Market Yi-Gou s.r.l. was fined EUR 6,000 by the Italian supervisory authority, Garante. The case concerned the failure to provide the required information to data subjects about personal data processing through a video surveillance system. | IT | Garante | GDPR | €6,000 | ↗ |
| 29 Jan 2015 | Azienda Ospedaliera Universitaria Policlinico Sant'Orsola-MalpighiAzienda Ospedaliera Universitaria Policlinico Sant'Orsola-Malpighi was fined EUR 2,400 by the Garante. The authority found that personal data collected through the website’s “contact us” form was processed without the required privacy notice, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 05 Feb 2015 | Comune di BellizziComune di Bellizzi was fined for unlawfully publishing sensitive personal data revealing health information on its institutional website. The conduct breached privacy rules governing the processing and disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Feb 2015 | Comune di San Giuseppe JatoComune di San Giuseppe Jato was fined by the Garante for unlawfully publishing sensitive personal data revealing health status on its website. The conduct breached privacy rules governing the processing and disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Feb 2015 | Azienda Regionale per il diritto allo studio universitario della ToscanaAzienda Regionale per il diritto allo studio universitario della Toscana was fined EUR 10,000 by the Garante. The authority found that its website unlawfully disclosed personal data revealing the health status of students with disabilities. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Feb 2015 | Comune di MerìComune di Merì was fined EUR 10,000 by the Garante for unlawfully publishing sensitive personal data on its website. The disclosure included information about individuals' health status and mandatory medical treatments, breaching data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Feb 2015 | Comune di MontagnarealeThe Garante fined Comune di Montagnareale 10,000 EUR for unlawfully publishing personal data revealing health status on its institutional website. The breach involved disclosure of sensitive data without an adequate legal basis or safeguards. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2015 | Comune di Castelvetrano SelinunteComune di Castelvetrano Selinunte was fined by the Garante for unlawfully publishing personal data revealing health conditions on its website. The case involved a breach of data protection rules and the confidentiality of sensitive information. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2015 | Comune di CalatabianoComune di Calatabiano was fined 10,000 EUR by the Garante for unlawfully publishing personal data revealing health conditions on its institutional website. The conduct breached privacy rules governing the processing and disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2015 | Comune di JesiComune di Jesi was fined for unlawfully publishing personal data related to a public competition on its website without a legislative or regulatory basis. The authority found that this breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Feb 2015 | Aloisio AngeloAloisio Angelo was fined EUR 25,000 by the Italian data protection authority, Garante. The case involved activating 15 phone cards in the names of 5 individuals without their knowledge, which breached data protection rules. | IT | Garante | GDPR | €25,000 | ↗ |
| 12 Feb 2015 | Enescu Georgiana OfeliaEnescu Georgiana Ofelia was fined 2,400 EUR by the Italian supervisory authority Garante. The case concerned failure to provide data subjects with the required information about video surveillance at the business premises, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Feb 2015 | Enel Energia S.p.a.Enel Energia S.p.a. was fined by the Garante 200,000 EUR for failing to provide information and obtain consent for processing personal data for promotional purposes. The breach affected a large database of approximately 43.1 million contacts. | IT | Garante | GDPR | €200,000 | ↗ |
| 12 Feb 2015 | Visini FabioVisini Fabio was fined EUR 12,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection requirements. | IT | Garante | GDPR | €12,000 | ↗ |
| 13 Feb 2015 | LA QUINIELA INTELIGENTE S.L.LA QUINIELA INTELIGENTE S.L. was fined by the AEPD EUR 2,600 for sending unsolicited commercial emails. The authority found that the messages did not provide recipients with an effective way to object to further communications, breaching Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,600 | ↗ |
| 13 Feb 2015 | COMERCIAL POLINDUS, 21, S.L.COMERCIAL POLINDUS, 21, S.L. was fined by the AEPD 3,000 EUR for sending unsolicited commercial communications. The case concerned Article 21 of the LSSI, which prohibits such messages without prior recipient consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 19 Feb 2015 | VUELING AIRLINES S.A.VUELING AIRLINES S.A. was fined by the AEPD EUR 3,500 for sending unsolicited commercial emails to the complainant. The conduct breached Article 21.1 of the LSSI on marketing communications without prior consent. | ES | AEPD | ePrivacy | €3,500 | ↗ |
| 19 Feb 2015 | HHHH was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice for its video surveillance system. The authority found a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |