BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Jul 2024 | Provvedimento del 17 luglio 2024 [10070330]The Garante imposed a fine of EUR 4,000 for violations related to the processing of health data. The case highlights the need to comply with data protection principles when handling special category data. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Jul 2024 | Azienda ULSS n. 14The Garante fined Azienda ULSS n. 14 EUR 22,000 for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies resulted in a data breach involving sensitive health data. | IT | Garante | GDPR | €22,000 | ↗ |
| 17 Jul 2024 | Selectra S.p.A.Selectra S.p.A. was fined EUR 80,000 by the Garante for unlawfully accessing and retaining a former employee's email account after the end of the collaboration. The authority found that the company's conduct breached data protection rules. | IT | Garante | GDPR | €80,000 | ↗ |
| 17 Jul 2024 | Hera Comm S.p.A.Hera Comm S.p.A. was fined by the Garante 5,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy contracts and insurance policies with forged signatures. | IT | Garante | GDPR | €5,000,000 | ↗ |
| 17 Jul 2024 | Mark s.r.l.s.Mark s.r.l.s. was fined by the Garante for operating a video surveillance system without the required signage. The case concerned a breach of GDPR information obligations. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Jul 2024 | A.S. Watson Health & Beauty Continental Europe B.V.A.S. Watson Health & Beauty Continental Europe B.V. was fined 600,000 EUR by the Dutch AP. The authority found that the company processed personal data without a lawful basis because it failed to obtain consent for tracking cookies on kruidvat.nl, breaching GDPR Articles 5 and 6. | NL | AP | GDPR | €600,000 | ↗ |
| 16 Jul 2024 | AS Watson / KruidvatThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of EUR 600,000 on AS Watson / Kruidvat. The case concerns a breach of GDPR cookie consent rules. | NL | Autoriteit Persoonsgegevens | GDPR | €600,000 | ↗ |
| 15 Jul 2024 | ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD 200,000 EUR for failing to properly handle a data subject’s request for deletion and for processing personal data without a legal basis. The case concerns breaches of core data protection obligations. | ES | AEPD | GDPR | €200,000 | ↗ |
| 12 Jul 2024 | CLIDEA DESARROLLO, S.A.CLIDEA DESARROLLO, S.A. was fined by the AEPD 3,000 EUR for sending an email to 349 recipients without using the BCC field. This exposed the personal email addresses of all recipients. | ES | AEPD | GDPR | €3,000 | ↗ |
| 11 Jul 2024 | EOS MatrixAZOP imposed a EUR 5.47 million fine on EOS Matrix for a personal data protection breach following an incident involving the data of 181,641 debtors. The case was described as a GDPR violation and the largest fine in the authority's history. | HR | AZOP | GDPR | €5,470,000 | ↗ |
| 10 Jul 2024 | Dane anonimowe (Panią A. Z. prowadzącą działalność gospodarczą pod firmą B. z siedzibą w W przy ul.)The President of UODO imposed an administrative fine on an individual conducting business activity. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for supervisory tasks. | PL | UODO | GDPR | €5,129 | ↗ |
| 08 Jul 2024 | COMERCIAL GIRONA DE LLIBRES, S.L.COMERCIAL GIRONA DE LLIBRES, S.L. was fined by the AEPD 20,000 EUR for inadequate security measures. The authority cited, among other issues, the sending of credentials by email, which breached Article 32 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 08 Jul 2024 | CALLBELL S.A.S.CALLBELL S.A.S. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial messages to a complainant despite a request to stop. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 05 Jul 2024 | PUBLICACIONES Y EDICIONES BARACA 208, S.L.The company published personal data, including health information, in a digital newspaper article. The authority found a breach of data minimisation and the rules on special category data under GDPR Articles 5(1)(c) and 9. | ES | AEPD | GDPR | €10,000 | ↗ |
| 04 Jul 2024 | Provvedimento del 4 luglio 2024 [10068075]The Garante imposed a EUR 400 fine on an individual for improperly installing a surveillance system. The cameras captured public street areas, which breached privacy rules. | IT | Garante | GDPR | €400 | ↗ |
| 04 Jul 2024 | Nomodidattica S.r.l.Nomodidattica S.r.l. was fined EUR 10,000 by the Garante for publishing a court ruling online without anonymizing minors' data. The authority found this breached GDPR data protection principles. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Jul 2024 | Lapis SasThe Garante fined Lapis Sas EUR 1,500 for incorrectly presenting itself as the data controller. This created public confusion and constituted a prolonged breach of GDPR requirements. | IT | Garante | GDPR | €1,500 | ↗ |
| 04 Jul 2024 | Comune di TrevisoThe Garante fined Comune di Treviso EUR 7,000 for failing to adopt internal measures governing data processing in connection with the TrevisoSicura application. The authority also found that the municipality incorrectly assumed the role of data processor instead of properly defining its data protection responsibilities. | IT | Garante | GDPR | €7,000 | ↗ |
| 04 Jul 2024 | Postel S.p.A.Postel S.p.A. was fined by the Garante EUR 900,000 for a data breach following a ransomware attack. The attack exploited vulnerabilities in the Microsoft Exchange platform, resulting in unauthorized access to data and publication on the dark web. | IT | Garante | GDPR | €900,000 | ↗ |
| 04 Jul 2024 | Comune di VillasimiusComune di Villasimius was fined for failing to respond to a request to remove personal data from its website and for unlawfully publishing personal data. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |