BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Apr 2021 | Società Eurosanità s.p.a.Società Eurosanità s.p.a. was fined by the Garante in the amount of 5,000 EUR for a breach involving the processing of health data. The authority found violations of GDPR Articles 5 and 9, indicating improper handling of special category personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 Jan 2023 | Società Europea di Edizioni S.p.a.The Garante fined Società Europea di Edizioni S.p.a. EUR 10,000 for publishing non-anonymized personal data concerning an individual's health status in an article. This constituted a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 May 2021 | Società e Salute S.p.a.Società e Salute S.p.a. was fined by the Garante EUR 10,000 for a data breach involving the mishandling of personal data, including health information. The authority found violations of GDPR Articles 5 and 9. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Feb 2014 | Società Editrice Sud s.p.a.Società Editrice Sud s.p.a. was fined by the Garante in the amount of 16,800 EUR for using inadequate information notices on data collection forms. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €16,800 | ↗ |
| 07 Feb 2013 | Società delle terme s.p.a.Società delle terme s.p.a. was fined by the Garante 18,400 EUR for providing inadequate information when collecting personal data and for obtaining invalid consent. The authority found violations of Articles 13 and 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €18,400 | ↗ |
| 11 Jan 2024 | Società David S.r.l.The Garante imposed an €8,000 fine on Società David S.r.l. for posting on Instagram a video of a patient undergoing a cosmetic procedure without a lawful basis. The authority found breaches of the GDPR principles of lawfulness, fairness, transparency, and purpose limitation. | IT | Garante | GDPR | €8,000 | ↗ |
| 08 May 2013 | Società Cooperativa Frantoio Oleario SanviteseThe company was fined 2,400 EUR by the Garante for providing inadequate data protection information on its website. The case concerned a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 27 May 2021 | Società Cavourese S.p.A.Società Cavourese S.p.A. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned improper handling of personal data related to employee disciplinary proceedings, in breach of the GDPR and national privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Jun 2025 | Società Autocooperative Trasporti Italiani S.p.A.The company was fined by the Garante for unlawfully disclosing sensitive personal data about employee absences, including the reasons for absence. The information was posted on company notice boards and sent by email to employees. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Nov 2017 | Società Alberghi Circeo s.r.l.Società Alberghi Circeo s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company failed to appoint data processing officers for employees handling personal data, in breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Mar 2018 | Società agricola Medici Claudio s.r.l.The company was fined for failing to comply with data protection obligations. The breach concerned not providing personal data and information related to employment management when requested by the Garante. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Apr 2023 | SOCIEDAD VASCONGADA DE PUBLICACIONES, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. AEPD found that this breached the data minimization principle. | ES | AEPD | GDPR | €150,000 | ↗ |
| 25 Jul 2019 | SOCIEDAD ESTATAL CORREOS Y TELEGRAFOS. S.A.The entity delivered correspondence to the wrong recipient, which constitutes a breach of the data protection principles in Article 5 of the GDPR. AEPD imposed a fine of EUR 40,000. | ES | AEPD | GDPR | €40,000 | ↗ |
| 05 May 2022 | SOCIEDAD ESPAÑOLA DE RADIODIFUSIÓN, S.L.The Spanish Data Protection Agency (AEPD) fined SOCIEDAD ESPAÑOLA DE RADIODIFUSIÓN, S.L. EUR 50,000 for publishing audio of a victim’s court testimony without adequate data protection safeguards. The authority found a breach of GDPR Article 5(1)(c) on data minimization. | ES | AEPD | GDPR | €50,000 | ↗ |
| 09 Jul 2025 | SOCIEDAD DE GESTIÓN DE ACTIVOS PROCEDENTES DE LA REESTRUCTURACIÓN BANCARIA, S.A. (SAREB)SAREB was fined €300,000 by the AEPD for breaches of GDPR Articles 5(1)(f) and 28. The case concerned data protection failures and insufficient contractual oversight of data processing activities. | ES | AEPD | GDPR | €300,000 | ↗ |
| 21 Feb 2024 | SOCIEDAD CONJUNTA PARA LA EMISIÓN Y GESTIÓN DE MEDIOS DE PAGO EFC SAIberia Cards was fined by the AEPD for failing to properly delete customer data after confirming cancellation. This caused issues when a former customer reapplied for a card. | ES | AEPD | GDPR | €20,000 | ↗ |
| 25 Feb 2024 | SOCIEDAD ANDALUZA DE CHARTERS ATLÁNTICOS S.L.The company was fined EUR 500 by the AEPD for collecting excessive personal data during guest registration. In particular, it obtained full copies of ID documents and facial photographs, which breached the data minimization principle. | ES | AEPD | GDPR | €500 | ↗ |
| 01 Jan 2017 | SOCIEDAD AIR FRANCE, S.A.Air France was fined by the AEPD EUR 7,000 for sending emails to a complainant despite a request to delete the personal data. The case concerns a breach of data protection rules and improper processing after a deletion request. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 13 Apr 2023 | Sociale verzekeringsbankThe Dutch AP fined Sociale verzekeringsbank EUR 150,000. The authority found that the organization failed to implement adequate technical and organizational measures to ensure a risk-appropriate level of security when processing personal data during telephone contact with AOW beneficiaries, in breach of GDPR Article 32. | NL | AP | GDPR | €150,000 | ↗ |
| 09 Dec 2024 | SOBLADA RESTAURACIÓN, S.L.SOBLADA RESTAURACIÓN, S.L. was fined by the AEPD EUR 4,500 for installing a video surveillance system without proper signage. The company also failed to inform employees about the system and its purposes, breaching GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €4,500 | ↗ |