BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Nov 2024 | Provvedimento del 14 novembre 2024 [10104860]Garante imposed a EUR 40,000 fine on a healthcare company for failing to update its security assessments in response to increased cyberattacks. The authority found a breach of GDPR Article 32 because technical and organizational measures were not adjusted to the changed risk level. | IT | Garante | GDPR | €40,000 | ↗ |
| 14 Nov 2024 | Comune di Torre AnnunziataThe Garante imposed a EUR 2,000 fine on Comune di Torre Annunziata for failing to communicate the contact details of its Data Protection Officer. This obligation arises under Article 37(7) GDPR and is intended to ensure the supervisory authority can reach the DPO. | IT | Garante | GDPR | €2,000 | ↗ |
| 13 Nov 2024 | Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 8,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data. The decision indicates non-compliance with core rules on lawful and proper processing. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Nov 2024 | Sligo County CouncilThe Irish DPC imposed a fine of EUR 29,500 on Sligo County Council in inquiry 07/SIU/2018. The case status is listed as not confirmed. | IE | DPC | GDPR | €29,500 | ↗ |
| 13 Nov 2024 | FederprivacyFederprivacy was fined EUR 6,000 by the Garante after a data breach caused by a cyberattack. The attack compromised the website, email accounts, and social media, indicating inadequate technical and organizational measures. | IT | Garante | GDPR | €6,000 | ↗ |
| 13 Nov 2024 | Montini Group S.r.l.Montini Group S.r.l. was fined EUR 6,000 by the Garante. The case concerned contacting an employee’s general practitioner without consent, which breached GDPR rules on processing health data. | IT | Garante | GDPR | €6,000 | ↗ |
| 13 Nov 2024 | Illumia S.p.A.Illumia S.p.A. was fined by the Italian data protection authority, Garante, for violations related to the processing of personal data for telemarketing purposes. The authority cited inadequate contractual arrangements with sub-processors and insufficient oversight of commercial partners. | IT | Garante | GDPR | €678,000 | ↗ |
| 13 Nov 2024 | Spinacqua S.r.l.Spinacqua S.r.l. was fined by the Garante €10,000 for making unsolicited promotional calls to a number listed in the Public Opposition Register. The company did not obtain consent and failed to verify the number’s registration status before contacting it. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Nov 2024 | Thermogen S.r.l.Thermogen S.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The conduct breached the GDPR and national privacy laws. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Nov 2024 | UP ROMÂNIA SRLUP ROMÂNIA SRL was fined EUR 4,000 by ANSPDCP for processing employees’ identification and location data during their free time without a legal basis. The authority found breaches of legality, transparency, and data minimization principles. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 13 Nov 2024 | Istituto Nazionale della Previdenza SocialeThe Italian Data Protection Authority fined Istituto Nazionale della Previdenza Sociale (INPS) EUR 40,000 for violations related to the processing of personal data for official statistics. The authority found that the processing did not comply with core data protection principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 13 Nov 2024 | Comune di UgentoThe Garante fined Comune di Ugento 2,400 EUR for publishing data on its website that could reveal individuals' health status. The case involved the improper disclosure of sensitive information in a public online setting. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Nov 2024 | Dane anonimowe (A. z siedzibą w W. przy ul.)The Polish DPA (UODO) imposed administrative fines on the controller and the processor for breaches of GDPR obligations. The case concerned, among others, integrity and confidentiality, accountability, data protection by design, processor arrangements, and security measures. | PL | UODO | GDPR | €351,000 | ↗ |
| 12 Nov 2024 | Dane anonimowe (X. w Y.)UODO imposed an administrative fine of PLN 24,555 on Anonymous entity (X. in Y.) for breaches of Articles 24(1), 25(1), and 32(1)-(2) of the GDPR. The authority also ordered the processing operations to be brought into compliance with Regulation (EU) 2016/679. | PL | UODO | GDPR | €5,644 | ↗ |
| 12 Nov 2024 | Uptime-IT ApSUptime-IT ApS was fined by Datatilsynet 40,000 DKK for failing to implement adequate security measures as a data processor. This led to a ransomware attack that encrypted sensitive personal data, including health information and CPR numbers, which could not be restored. | DK | Datatilsynet | GDPR | €5,362 | ↗ |
| 08 Nov 2024 | AECORP 005, S.L.AECORP 005, S.L. was fined EUR 6,000 by the AEPD for failing to provide access to information requested during an investigation. The authority found a breach of Article 58.1 GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 08 Nov 2024 | PPC Energie Muntenia S.AThe National Supervisory Authority for Personal Data Processing completed an investigation at PPC Energie Muntenia S.A and found a violation of GDPR provisions. As a result, a fine of EUR 1,000 was imposed. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 04 Nov 2024 | Blackcab Systems SRLANSPDCP completed an investigation at Blackcab Systems SRL in October 2024 and found a breach of GDPR provisions. As a result, a fine of EUR 1,000 was imposed. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 02 Nov 2024 | Intesa SanpaoloThe Italian Data Protection Authority fined Intesa Sanpaolo €31.8 million for a data breach involving unauthorized access to banking information of more than 3,500 clients. The authority also found that the bank detected the activity late and filed an incomplete and delayed breach notification. | IT | Garante per la protezione dei dati personali | GDPR | €31,800 | ↗ |
| 01 Nov 2024 | SIA "North Technology Group"A monetary penalty of 500 EUR was imposed on SIA "North Technology Group" by the DVI. The decision entered into force on 1 November 2024. | LV | DVI | GDPR | €500 | ↗ |