BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 May 2022 | Azienda Sanitaria Locale Roma 1The Garante fined Azienda Sanitaria Locale Roma 1 EUR 46,000 for the unauthorized publication of health-related personal data on its institutional website. The case concerned a breach of data protection rules through the disclosure of sensitive information without a lawful basis. | IT | Garante | GDPR | €46,000 | ↗ |
| 28 Nov 2013 | Axa società cooperativa a responsabilità limitataAxa società cooperativa a responsabilità limitata was fined by the Garante 46,000 EUR for using biometric systems to monitor employee attendance and working hours. The authority found that the processing took place without proper consent and required notifications, in breach of data protection rules. | IT | Garante | GDPR | €46,000 | ↗ |
| 22 Feb 2018 | Bar La Piazzetta s.a.s.Bar La Piazzetta s.a.s. was fined EUR 46,000 by the Italian Garante. The authority found that surveillance footage was kept longer than permitted, access was not password-protected, and the required privacy notices were not provided. | IT | Garante | GDPR | €46,000 | ↗ |
| 15 Feb 2018 | Genova Car Sharing SrlGenova Car Sharing Srl was fined EUR 46,000 by the Garante. The authority found that customers were not fully informed about vehicle geolocation and that separate consent was not obtained for newsletter communications. | IT | Garante | GDPR | €46,000 | ↗ |
| 30 Nov 2022 | Dane anonimowe (N. B. oraz T. M., wspólników spółki cywilnej Kancelaria)UODO imposed an administrative fine on N. B. and T. M., partners in the civil-law partnership Kancelaria. The authority found that they processed personal data of clients and prospective clients without a legal basis. | PL | UODO | GDPR | €9,799 | ↗ |
| 07 Jul 2022 | Senseonics Inc.Senseonics Inc. was fined EUR 45,000 by the Garante for violations related to the processing of personal data. The authority cited issues with data integrity and confidentiality, including health data. | IT | Garante | GDPR | €45,000 | ↗ |
| 12 Mar 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 45,000 EUR by the AEPD for sending continuous SMS messages to a complainant despite a prior request to cancel personal data. The authority found this conduct to be a breach of data protection principles. | ES | AEPD | GDPR | €45,000 | ↗ |
| 11 Feb 2021 | Istituti ospedalieri bergamaschiThe Garante fined Istituti ospedalieri bergamaschi EUR 45,000 for a data protection breach. Online medical reports were accessible to other patients, exposing sensitive personal data. | IT | Garante | GDPR | €45,000 | ↗ |
| 28 Nov 2017 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 45,000 EUR by the AEPD for sending commercial emails without providing a valid electronic address for exercising the right to object. The authority found this to be a breach of LSSI rules on commercial communications. | ES | AEPD | ePrivacy | €45,000 | ↗ |
| 01 Jan 2018 | CANARY ISLANDS CAR S.L.CANARY ISLANDS CAR S.L. was fined by the AEPD 45,000 EUR for inaccurate processing of personal data. As a result, a traffic violation was incorrectly attributed to a person who had not rented the vehicle. | ES | AEPD | GDPR | €45,000 | ↗ |
| 18 Sept 2008 | Suzuki Italia S.p.A.Suzuki Italia S.p.A. was fined for failing to provide the required privacy notice to individuals whose personal data was obtained from a third party. The breach was found under the Italian Data Protection Code. | IT | Garante | GDPR | €45,000 | ↗ |
| 09 Jan 2024 | 20 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined 45,000 EUR by the AEPD for publicly exposing the image of a victim of an alleged crime. The authority found that this constituted a breach of data protection rules. | ES | AEPD | GDPR | €45,000 | ↗ |
| 18 Jul 2023 | Comune di ModicaThe Garante fined Comune di Modica EUR 45,000 for inadequate data protection measures linked to video surveillance in public areas. The issues affected a large number of individuals over an extended period, and those recorded were not properly informed. | IT | Garante | GDPR | €45,000 | ↗ |
| 07 May 2015 | Nappo Nicola JolandaNappo Nicola Jolanda was fined EUR 45,000 by the Garante for activating 37 phone cards in the names of 15 individuals without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €45,000 | ↗ |
| 29 Apr 2021 | Comune di TriesteComune di Trieste was fined for the unauthorized disclosure of personal data relating to individuals involved in accidents, including names, damage details, and compensation amounts. The data was improperly accessible, constituting a breach of GDPR requirements. | IT | Garante | GDPR | €45,000 | ↗ |
| 10 Apr 2025 | Stefanelli FedericaThe Garante imposed a 45,000 EUR fine on Stefanelli Federica for processing personal data without proper consent in unauthorized call-center operations. The case also involved sensitive data, including payment method information, which could have led to unauthorized contract activations. | IT | Garante | GDPR | €45,000 | ↗ |
| 04 Jun 2025 | Noi Compriamo Auto.it S.r.l.The Italian Supervisory Authority fined Noi Compriamo Auto.it S.r.l. 45,000 EUR for sending unsolicited promotional emails without proper consent documentation. The case indicates a breach of GDPR requirements for lawful direct marketing. | IT | Garante | GDPR | €45,000 | ↗ |
| 01 Jan 2012 | VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined by the AEPD in the amount of EUR 44,001 for sending unsolicited commercial communications to a non-customer. The authority found this conduct to be in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €44,001 | ↗ |
| 22 Jan 2015 | Istituto Nazionale Previdenza SocialeIstituto Nazionale Previdenza Sociale was fined EUR 44,000 by the Garante. The authority found that the required privacy notice was not provided to users, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €44,000 | ↗ |
| 09 May 2018 | Telefonika s.r.l.sTelefonika s.r.l.s was fined by the Italian data protection authority, Garante, in the amount of EUR 42,000. The sanction concerned numerous unsolicited promotional phone calls made without proper consent. | IT | Garante | GDPR | €42,000 | ↗ |