BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Mar 2017 | Obiettivo Ferrari s.r.l.Obiettivo Ferrari s.r.l. was fined by the Garante €16,000 for making an unsolicited promotional call. The company did not provide the required data protection information or obtain consent from the recipient. | IT | Garante | GDPR | €16,000 | ↗ |
| 16 Mar 2017 | Cigno d’Argento s.r.l.Cigno d’Argento s.r.l. was fined by the Garante 36,000 EUR for data protection violations. The case concerned the improper use of video surveillance systems without the required authorization. | IT | Garante | GDPR | €36,000 | ↗ |
| 20 Mar 2017 | Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined EUR 10,000 by the HDPA. The authority found that the bank did not adequately satisfy the complainant’s right of access to recorded telephone conversations. The case concerned the legal obligation to provide access to such recordings. | GR | HDPA | GDPR | €10,000 | ↗ |
| 23 Mar 2017 | Azienda Sanitaria ULSS 6 di VicenzaAzienda Sanitaria ULSS 6 di Vicenza was fined by the Garante 10,000 EUR for unlawfully communicating an individual's health data to the Comune di Arcugnano without proper authorization. The case involved a breach of lawful processing rules and safeguards for special-category data. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Mar 2017 | Ente Nazionale per L’Aviazione Civile (ENAC)ENAC was fined by the Garante in the amount of 10,000 EUR. The authority found that adequate security measures were not implemented, in breach of Articles 33 and 34 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Mar 2017 | IMPACTING EMAIL MARKETING SOLUTIONS S.L.IMPACTING EMAIL MARKETING SOLUTIONS S.L. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent. The authority found this conduct to be in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 30 Mar 2017 | Acantho s.p.a.Acantho s.p.a. was fined by the Garante in the amount of EUR 30,000 for retaining telephone and telematic traffic data longer than legally permitted. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 30 Mar 2017 | Grand Hotel Des Bains s.r.l.Grand Hotel Des Bains s.r.l. was fined by the Garante 12,000 EUR for retaining surveillance footage longer than permitted under the video surveillance guidelines. The case concerns a breach of data retention rules for CCTV recordings. | IT | Garante | GDPR | €12,000 | ↗ |
| 30 Mar 2017 | Provincia di CasertaProvincia di Caserta was fined EUR 20,000 by the Garante. The authority found that the province failed to designate data processing officers and did not update the security program document required under the data protection code. | IT | Garante | GDPR | €20,000 | ↗ |
| 31 Mar 2017 | B.B.B.B.B.B. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The emails continued despite repeated requests from the recipient to stop, which breached the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 06 Apr 2017 | Effepì Credit s.r.l.Effepì Credit s.r.l. was fined by the Garante in the amount of EUR 10,000 for inadequate security measures. The authority cited weak and outdated passwords as a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Apr 2017 | Siportal s.r.l.Siportal s.r.l. was fined by the Garante for retaining telephone and internet traffic data longer than permitted by law. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 06 Apr 2017 | Regione AbruzzoThe Garante fined Regione Abruzzo EUR 20,000 for unlawfully publishing lists on its website that revealed candidates' health status. The case involved the disclosure of sensitive personal data relating to individuals with disabilities. | IT | Garante | GDPR | €20,000 | ↗ |
| 06 Apr 2017 | CLARIMARKET S.L.CLARIMARKET S.L. was fined EUR 600 by the AEPD. The sanction concerned sending unsolicited commercial emails in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 17 Apr 2017 | WIZINK BANK S.A.WIZINK BANK S.A. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial communications by email. The conduct violated the recipient's request to opt out of advertising. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 20 Apr 2017 | Linea Com s.r.l.Linea Com s.r.l. was fined by the Garante EUR 40,000 for retaining customers' telephone and telematic traffic data beyond the legal retention periods. The authority found that the storage periods exceeded the limits set by data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 20 Apr 2017 | Hotel Savoia Genova s.r.l.Hotel Savoia Genova s.r.l. was fined €16,800 by the Garante. The authority found that the company failed to provide the required information to individuals about its video surveillance system and kept surveillance footage longer than permitted. | IT | Garante | GDPR | €16,800 | ↗ |
| 04 May 2017 | Easy C@ll s.r.l.Easy C@ll s.r.l. was fined EUR 32,000 by the Garante for making unsolicited promotional calls to individuals listed in the public opt-out register. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 04 May 2017 | McDonald’s Development ItalyMcDonald’s Development Italy was fined EUR 15,000 by the Garante. The authority found that the company retained surveillance footage longer than permitted under the video surveillance guidelines. | IT | Garante | GDPR | €15,000 | ↗ |
| 04 May 2017 | Starweb s.r.l.Starweb s.r.l. was fined €16,000 by the Garante for making unsolicited promotional calls. The authority found that the company failed to provide the required information notice and did not obtain consent from the contacted individuals. | IT | Garante | GDPR | €16,000 | ↗ |