BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Apr 2017 | Linea Com s.r.l.Linea Com s.r.l. was fined by the Garante EUR 40,000 for retaining customers' telephone and telematic traffic data beyond the legal retention periods. The authority found that the storage periods exceeded the limits set by data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Dec 2023 | Azienda socio sanitaria territoriale nord MilanoAzienda socio sanitaria territoriale nord Milano was fined by the Garante EUR 40,000 for allowing unrestricted access to patient data across hospital departments. The authority found breaches of data minimization and purpose limitation principles during the COVID-19 emergency. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 Aug 2025 | FIATC MUTUA DE SEGUROS Y REASEGUROSFIATC Mutua de Seguros y Reaseguros was fined €40,000 by the AEPD after unauthorized access to its systems. The incident may have exposed personal data, including DNI/CIF, and the authority found inadequate security measures and a breach of Article 5(1)(f) GDPR. | ES | AEPD | GDPR | €40,000 | ↗ |
| 26 Mar 2015 | Okcom S.p.a.Okcom S.p.a. was fined EUR 40,000 by the Italian Garante. The authority found non-compliance with strong authentication requirements and a failure to notify the Garante about compliance with data protection measures. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Mar 2026 | INPS – Istituto nazionale previdenza socialeThe Italian Data Protection Authority fined INPS EUR 40,000 for improperly displaying personal data of individuals residing in a care facility during an ISEE precompilation request. The authority found a breach of data protection principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 20 Jan 2021 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 40,000 by the AEPD for failing to respond to a data access request. The case concerns non-compliance with GDPR obligations relating to data subject rights. | ES | AEPD | GDPR | €40,000 | ↗ |
| 08 Sept 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD €40,000 for processing personal data without a legal basis. The case involved fraudulent contracts created in individuals’ names without their consent, breaching the principle of lawful processing. | ES | AEPD | GDPR | €40,000 | ↗ |
| 15 Mar 2018 | Lombardia Informatica S.p.A.Lombardia Informatica S.p.A. was fined EUR 40,000 by the Garante for allowing unauthorized access to personal data through its portal. The case concerned a breach of data protection rules and indicated insufficient access controls. | IT | Garante | GDPR | €40,000 | ↗ |
| 27 Nov 2025 | InfobelThe Belgian Data Protection Authority (APD) imposed a EUR 40,000 fine on Infobel on 2025-11-27. The authority found that the company resold telecom-derived personal data for marketing purposes without valid consent and ordered it to inform its business customers of the decision. | BE | Autorité de protection des données (APD) | GDPR | €40,000 | ↗ |
| 05 Oct 2017 | Start S.p.A.Start S.p.A. was fined by the Garante 40,000 EUR for operating a geolocation system on its buses without full compliance with data protection rules. The case concerned location data processing without the required legal basis and safeguards. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Jul 2023 | Compara Facile S.r.l.Compara Facile S.r.l. was fined EUR 40,000 by the Garante for making unsolicited marketing calls to a number listed in the Public Register of Oppositions without prior informed consent. The authority also found that the company failed to respond to data subject rights requests, indicating non-compliance with data protection obligations. | IT | Garante | GDPR | €40,000 | ↗ |
| 31 Oct 2022 | FACTOR ENERGÍA, S.A.FACTOR ENERGÍA, S.A. was fined by the AEPD EUR 40,000 for sending personalized marketing messages using personal data without a legal basis. The authority found a breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €40,000 | ↗ |
| 08 Apr 2022 | AVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCAAVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCA was fined by the AEPD for failing to implement robust access controls. The weakness enabled attackers to encrypt files and demand a ransom, indicating significant gaps in technical and organizational safeguards. | ES | AEPD | GDPR | €40,000 | ↗ |
| 10 Nov 2022 | Azienda Usl Valle d’AostaAzienda Usl Valle d’Aosta was fined EUR 40,000 by the Garante for unlawful access to a patient's health dossier. The access was made by a healthcare professional not involved in the patient's care, breaching GDPR data processing principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 Dec 2025 | KomendantaUODO imposed an administrative fine of PLN 40,000 on Komendanta for unlawful processing of personal data, including special category data, by publishing it on a website without a legal basis. The authority also found that appropriate technical and organizational measures were not implemented and ordered the processing operations to be brought into compliance with GDPR requirements. | PL | UODO | GDPR | €9,457 | ↗ |
| 11 Apr 2013 | Diners Club Italia s.r.l.Diners Club Italia s.r.l. was fined €40,000 by the Garante for breaches of data protection rules. The authority found that the company failed to designate data processing officers and did not update the security program document. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Apr 2022 | Azienda ospedaliera di PerugiaAzienda ospedaliera di Perugia was fined by the Garante EUR 40,000 for breaches related to the protection of whistleblower identities. The authority found that adequate personal data protection measures were not in place. | IT | Garante | GDPR | €40,000 | ↗ |
| 26 Sept 2023 | RESTART ENERGY ONE S.A.RESTART ENERGY ONE S.A. was fined by ANSPDCP in the amount of RON 40,000 for additional GDPR violations. The authority also imposed corrective measures to improve data protection processes. | RO | ANSPDCP | GDPR | €8,048 | ↗ |
| 18 Sept 2014 | Meridi s.r.l.Meridi s.r.l. was fined by the Garante 40,000 EUR for failing to provide adequate information about video surveillance and for not appointing data processing officers. The authority found a breach of data security measures. | IT | Garante | GDPR | €40,000 | ↗ |
| 17 May 2023 | Volkswagen Leasing GmbHVolkswagen Leasing GmbH was fined EUR 40,000 by the Garante for failing to adequately respond to a data access request. The authority found a breach of GDPR provisions on data subject rights. | IT | Garante | GDPR | €40,000 | ↗ |