BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Feb 2024 | VESTAS CEU ROMÂNIA SRLThe company was fined EUR 3,000 by ANSPDCP for unauthorized disclosure of personal data. The breach included names, place of residence, salary, and CV details. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 25 Feb 2024 | SOCIEDAD ANDALUZA DE CHARTERS ATLÁNTICOS S.L.The company was fined EUR 500 by the AEPD for collecting excessive personal data during guest registration. In particular, it obtained full copies of ID documents and facial photographs, which breached the data minimization principle. | ES | AEPD | GDPR | €500 | ↗ |
| 23 Feb 2024 | ENERGY WINNER, S.L.ENERGY WINNER, S.L. was fined EUR 600 by the AEPD. The case concerned the failure to provide access to personal data and information requested by the data protection authority, which constitutes a breach of Article 58.1 GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 22 Feb 2024 | Ossitocina24 di Patrono AntonellaOssitocina24 di Patrono Antonella was fined 5,000 EUR by the Italian Garante. The case concerned the failure to delete personal data from its website after a contract termination request, which breached GDPR data processing requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 22 Feb 2024 | Azienda Usl Valle d’AostaThe Garante imposed a EUR 75,000 fine on Azienda Usl Valle d’Aosta for unauthorized access to patient health records. Healthcare professionals who were not involved in the patients’ care accessed the data, breaching GDPR data protection requirements. | IT | Garante | GDPR | €75,000 | ↗ |
| 22 Feb 2024 | Italiaonline S.p.A.Italiaonline S.p.A. was fined by the Garante 100,000 EUR for conducting direct email marketing campaigns without proper consent. The authority also found inadequate information about data processing activities shared with Google LLC. | IT | Garante | GDPR | €100,000 | ↗ |
| 22 Feb 2024 | S.A.T.E. (Servizi Ambiente Territorio Energia)The Garante fined S.A.T.E. 6,000 EUR for breaches of data protection principles, including lawfulness, integrity, and confidentiality. The authority found that inadequate security measures led to unauthorized access to data. | IT | Garante | GDPR | €6,000 | ↗ |
| 22 Feb 2024 | Blue Work s.r.l.Blue Work s.r.l. was fined EUR 6,000 by the Garante for unlawful processing of biometric data using facial recognition for employee attendance tracking. The authority found that the same purpose could have been achieved through less intrusive means. | IT | Garante | GDPR | €6,000 | ↗ |
| 22 Feb 2024 | Coop Italia Società CooperativaCoop Italia Società Cooperativa was fined by the Garante 90,000 EUR for unlawfully processing personal data for marketing purposes without proper consent. The authority found a breach of GDPR principles, including Article 5. | IT | Garante | GDPR | €90,000 | ↗ |
| 22 Feb 2024 | Camera di Commercio Industria Artigianato e Agricoltura di XXCamera di Commercio was fined for violating data protection principles by improperly disclosing personal data. The disclosure could have allowed third parties to learn the content of a judicial decision and infringed the privacy of the individual concerned. | IT | Garante | GDPR | €2,000 | ↗ |
| 22 Feb 2024 | Unica s.r.l.s.Unica s.r.l.s. was fined by the Garante EUR 2,000 for using a facial recognition system to record employee attendance without a proper legal basis. The authority found that the processing of biometric data breached GDPR requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 22 Feb 2024 | Comune di Civita CastellanaComune di Civita Castellana was fined EUR 3,000 by the Garante for improper handling of personal data during COVID-19 data transmission. The authority found that GDPR formalities were not properly complied with. | IT | Garante | GDPR | €3,000 | ↗ |
| 22 Feb 2024 | Ordine dei Medici Veterinari della Provincia di LatinaOrdine dei Medici Veterinari della Provincia di Latina was fined by the Garante 5,000 EUR for breaches of data protection principles. The case involved the unlawful communication of personal data to its members. | IT | Garante | GDPR | €5,000 | ↗ |
| 22 Feb 2024 | BLU MANAGEMENT SPAIN, S.L.BLU MANAGEMENT SPAIN, S.L. was fined €2,000 by the AEPD for sharing a job applicant’s contact details without consent. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 22 Feb 2024 | Trasporto Passeggeri Emilia-Romagna S.p.A.The Garante fined Trasporto Passeggeri Emilia-Romagna S.p.A. 50,000 EUR for improper data processing and a lack of transparency in collecting consent for marketing purposes. The case concerned failures to properly inform data subjects and to meet consent requirements. | IT | Garante | GDPR | €50,000 | ↗ |
| 22 Feb 2024 | Ordine dei Medici Chirurghi e Odontoiatri di PadovaOrdine dei Medici Chirurghi e Odontoiatri di Padova was fined 5,000 EUR by the Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization in the handling of personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 22 Feb 2024 | Sigma s.r.l.Sigma s.r.l. was fined EUR 150,000 by the Garante for unauthorized activation of paid services and devices using customer data without consent. The authority found that the company’s conduct breached GDPR rules on personal data processing. | IT | Garante | GDPR | €150,000 | ↗ |
| 22 Feb 2024 | L’Igiene Urbana Evolution s.r.l.L’Igiene Urbana Evolution s.r.l. was fined €70,000 by the Garante for unlawfully processing biometric data through facial recognition to monitor employee attendance. The authority found that this practice violated GDPR requirements. | IT | Garante | GDPR | €70,000 | ↗ |
| 22 Feb 2024 | Airone società consortile a r.l.Airone società consortile a r.l. was fined EUR 5,000 by Garante for unlawfully processing biometric data through facial recognition to monitor employee attendance. The authority found that the same purpose could have been achieved by less intrusive means. | IT | Garante | GDPR | €5,000 | ↗ |
| 22 Feb 2024 | Comune di MonterotondoThe Garante imposed a EUR 3,000 fine on Comune di Monterotondo for breaches involving data processing agreements and security measures. The case also involved improper use of video surveillance. The authority found that the controller did not meet data protection requirements. | IT | Garante | GDPR | €3,000 | ↗ |