BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Feb 2023 | ROMBOC COMUNICACIONESROMBOC COMUNICACIONES was fined by the AEPD in the amount of 2,000 EUR for making misleading advertising calls without explicit consent from recipients. The case indicates a breach of data protection and direct marketing rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 16 Mar 2017 | Roma TPL s.c.a.r.l.Roma TPL s.c.a.r.l. was fined EUR 8,000 by the Garante for processing personal data through AVM systems on buses without full compliance with data protection rules. The case concerned improper use of monitoring and data-processing systems affecting passengers. | IT | Garante | GDPR | €8,000 | ↗ |
| 11 Feb 2021 | Roma Servizi per La Mobilita S.r.l.Roma Servizi per La Mobilita S.r.l. was fined EUR 60,000 by the Garante for inadequate security measures. The weakness led to unauthorized access to personal data related to ZTL permits. | IT | Garante | GDPR | €60,000 | ↗ |
| 21 Apr 2016 | Romana Supernegozi s.r.l.Romana Supernegozi s.r.l. was fined by the Garante 2,400 EUR for failing to provide adequate simplified information about its video surveillance system. The case concerned breaches of data protection information duties. | IT | Garante | GDPR | €2,400 | ↗ |
| 05 Nov 2015 | Romagna Giochi srlRomagna Giochi srl was fined EUR 4,800 by the Italian Garante. The authority found that the company failed to provide adequate notice about video surveillance at its premises, breaching data protection rules. | IT | Garante | GDPR | €4,800 | ↗ |
| 06 Jul 2023 | Romagna Dolciumi s.r.l.Romagna Dolciumi s.r.l. was fined by the Garante in the amount of €10,000 for failing to provide an employee with access to their personal data. The authority also found that the company engaged a private investigative agency to carry out defensive investigations without proper authorization, in breach of GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Oct 2017 | Roma Gestioni s.r.l.Roma Gestioni s.r.l. was fined EUR 30,000 by the Garante. The authority found that the company retained surveillance footage longer than permitted under privacy rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 27 Jan 2021 | Roma CapitaleRoma Capitale was fined EUR 10,000 by the Garante for publishing the personal data of a minor and the minor’s mother on its official website without a proper legal basis. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Apr 2023 | Roma CapitaleRoma Capitale was fined EUR 176,000 by the Garante for the unlawful processing and dissemination of personal health data relating to women who had terminated pregnancies. The sensitive information was displayed on crosses at a cemetery, creating a serious data protection breach. | IT | Garante | GDPR | €176,000 | ↗ |
| 17 Dec 2020 | Roma CapitaleRoma Capitale was fined 500,000 EUR by the Garante for violations related to the processing of personal data in the TuPassi system. The authority also identified shortcomings in the information provided to users. | IT | Garante | GDPR | €500,000 | ↗ |
| 22 Jul 2021 | Roma CapitaleRoma Capitale was fined EUR 800,000 by the Garante for failing to adequately protect the personal data of motorists using parking meters. The authority also found improper data retention practices, increasing the risk to data subjects. | IT | Garante | GDPR | €800,000 | ↗ |
| 13 Feb 2014 | Roma CapitaleRoma Capitale was fined for unlawfully publishing personal data related to a disciplinary action on its institutional website. The authority found that this conduct violated Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Feb 2021 | Roma CapitaleRoma Capitale was fined EUR 350,000 by the Garante for breaches of GDPR principles, including data minimization and security. The violations resulted in unauthorized access to personal data over an extended period. | IT | Garante | GDPR | €350,000 | ↗ |
| 01 Jan 2021 | RODALI GESTIÓN INMOBILIARIA, S.L.RODALI GESTIÓN INMOBILIARIA, S.L. was fined by the AEPD 5,000 EUR for failing to provide clients with information about the processing of their personal data. The authority found a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2017 | ROCK INTERNET, S.L.ROCK INTERNET, S.L. was fined by the AEPD EUR 5,000 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits such communications without prior recipient consent. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 16 Feb 2016 | ROCK INTERNET, S.L.ROCK INTERNET, S.L. was fined EUR 30,000 by the AEPD for sending unsolicited commercial emails despite the recipient’s repeated requests to unsubscribe. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 10 Oct 2016 | ROCK INTERNET S.L.ROCK INTERNET S.L. was fined 3,800 EUR by the AEPD. The case concerned sending unsolicited commercial emails without recipient consent, in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €3,800 | ↗ |
| 05 Mar 2024 | ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. was fined 5,000 EUR by the AEPD. The authority found that the company published employees’ personal data on its website without consent, breaching Article 6(1) of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 31 Aug 2023 | Robin S.r.l.The Garante fined Robin S.r.l. 25,000 EUR for publishing a photograph of minors with insufficient anonymization. The case concerns a breach of personal data protection rules applicable to children. | IT | Garante | GDPR | €25,000 | ↗ |
| 09 Dec 2020 | ROBINSON-TOURS Idegenforgalmi és Szolgáltató Kft.ROBINSON-TOURS Kft. was fined by NAIH for failing to implement appropriate data protection measures, which led to a high-risk data breach. The company did not notify the affected individuals about the incident. | HU | NAIH | GDPR | €56,000 | ↗ |