BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Dec 2018 | Anonymizováno (ÚOOÚ UOOU-08001/18-14)The entity was fined 40,000 CZK by the UOOU for insufficient security measures in the processing of personal data. The authority cited inadequate audit logs and a lack of regular access checks to electronic health records. | CZ | UOOU | GDPR | €1,549 | ↗ |
| 28 Apr 2022 | Il Sole 24 Ore S.p.a.Il Sole 24 Ore S.p.a. was fined by the Garante EUR 40,000 for publishing a court order containing the personal data of an adopted minor. The authority also found an incomplete and delayed response to a data access request. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Dec 2025 | Anticimex s.r.l.Anticimex s.r.l. was fined EUR 40,000 by the Garante for breaching data protection rules. The company failed to provide an employee with access to personal data, including work-related emails and CRM access logs, despite a request under Article 15 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 23 Sept 2010 | Regione PugliaRegione Puglia was fined EUR 40,000 by the Italian data protection authority, Garante. The case concerned the online publication of sensitive health data relating to disabled individuals, in breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Apr 2022 | ISWEB S.p.A.ISWEB S.p.A. was fined EUR 40,000 by the Italian supervisory authority, Garante. The authority found that the company failed to properly regulate its relationship with the hosting service provider in relation to data processing for Azienda ospedaliera di Perugia, in breach of Article 28 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 24 May 2017 | Call Solution s.r.l.Call Solution s.r.l. was fined EUR 40,000 by the Garante for making unsolicited promotional calls to numbers listed in the public opt-out registry. The conduct breached data protection rules and the requirements governing telephone marketing. | IT | Garante | GDPR | €40,000 | ↗ |
| 09 Feb 2023 | Anonymizováno (ÚOOÚ UOOU-04020/22-13)The entity was fined for repeatedly sending unsolicited commercial communications by electronic means without recipients' consent. The authority found a breach of Czech rules on information society services. | CZ | UOOU | ePrivacy | €1,688 | ↗ |
| 18 Dec 2018 | ORGANIZACION NACIONAL DE CIEGOS (ONCE)ONCE was fined EUR 40,000 by the AEPD for sending more than 200 unsolicited commercial emails without prior consent. The authority found this to be a breach of Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €40,000 | ↗ |
| 03 Feb 2021 | NBQ TECHNOLOGY, S.A.U.NBQ TECHNOLOGY, S.A.U. was fined by the AEPD 40,000 EUR for processing personal data without a legal basis. The case was linked to a denied financial operation following an identity theft incident. | ES | AEPD | GDPR | €40,000 | ↗ |
| 21 Oct 2019 | Anonymizováno (ÚOOÚ UOOU-02928/19-13)The entity was fined for publishing personal data related to criminal proceedings on its website. The authority found a breach of GDPR rules on the processing and disclosure of personal data. | CZ | UOOU | GDPR | €1,561 | ↗ |
| 13 Mar 2025 | Interflora Italia S.p.A.Interflora Italia S.p.A. was fined EUR 40,000 by the Garante for sending promotional SMS messages without providing an opt-out option. The case indicates a breach of GDPR requirements for marketing communications and data subject rights. | IT | Garante | GDPR | €40,000 | ↗ |
| 11 Apr 2013 | Casa di cura La Quiete srlCasa di cura La Quiete srl was fined by the Garante for failing to notify data processing activities related to patients’ laboratory tests. The data could reveal infectious diseases, which required notification under the Italian data protection code. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 Sept 2011 | Agenzia per le erogazioni in agricoltura (AGEA)The Italian Data Protection Authority fined Agenzia per le erogazioni in agricoltura (AGEA) EUR 40,000 for violations related to the processing of personal data within the National Agricultural Information System (Sian). The case concerned compliance of the processing activities with personal data protection requirements. | IT | Garante | GDPR | €40,000 | ↗ |
| 22 Nov 2012 | Synergo s.r.l.Synergo s.r.l. was fined by the Italian Garante for failing to notify the processing of sensitive health data. The case involved information on HIV status and infectious diseases, which should have been notified under the Italian data protection code. | IT | Garante | GDPR | €40,000 | ↗ |
| 06 Dec 2012 | Assicurazioni Generali s.p.a.Assicurazioni Generali s.p.a. was fined 40,000 EUR by the Garante for making an unsolicited promotional phone call. The call was placed despite the recipient's prior objection to the processing of personal data for marketing purposes. | IT | Garante | GDPR | €40,000 | ↗ |
| 10 Nov 2022 | Doctolib SrlDoctolib Srl was fined EUR 40,000 by the Italian Garante for violations linked to insufficient transparency in the online information provided to patients. The case concerned, in particular, how consent for processing health data was obtained. | IT | Garante | GDPR | €40,000 | ↗ |
| 21 Sept 2017 | AMI S.p.A.AMI S.p.A. was fined by the Garante for installing electronic monitoring and localization devices on public transport vehicles without proper notification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 16 Nov 2023 | Amazon Italia Transport s.r.l.Amazon Italia Transport s.r.l. was fined €40,000 by the Garante for failing to respond to a former employee’s request for access to personal data. The authority found a breach of Article 15 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 05 Mar 2020 | CoolblueCoolblue was fined 40,000 EUR by the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, for unlawfully collecting personal data through cookies without active consent. The violation occurred in 2020, and the company updated its cookie banner after the authority’s investigation. | NL | Autoriteit Persoonsgegevens | GDPR | €40,000 | ↗ |
| 22 Nov 2024 | Maynooth UniversityThe Irish DPC imposed a fine of EUR 40,000 on Maynooth University in inquiry IN-19-9-3. The penalty has been collected. | IE | DPC | GDPR | €40,000 | ↗ |