BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Oct 2012 | American Express Services Europe LimitedAmerican Express Services Europe Limited was fined by the Garante EUR 40,000 for making promotional calls without the data subject's consent. The case concerns a breach of privacy rules governing telephone marketing. | IT | Garante | GDPR | €40,000 | ↗ |
| 03 Jul 2020 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALIberia was fined by the AEPD 40,000 EUR for failing to provide the complainant access to their personal data, including telephone recordings. The authority found a breach of the right of access to personal data. | ES | AEPD | GDPR | €40,000 | ↗ |
| 20 Jul 2017 | InvalsiInvalsi was fined EUR 40,000 by the Italian Garante for unlawful processing of personal data. The case concerned the online publication of files containing disaggregated student personal data, including sensitive information. | IT | Garante | GDPR | €40,000 | ↗ |
| 25 Jan 2018 | Trivenet s.r.l.Trivenet s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company retained call data longer than permitted under data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 10 Dec 2015 | Aruba s.p.a.Aruba s.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 40,000. The case concerned the sending of promotional emails without obtaining the required consent, in breach of articles 23 and 130 of the Italian data protection code. | IT | Garante | GDPR | €40,000 | ↗ |
| 15 Feb 2018 | APS Holding S.p.a.APS Holding S.p.a. was fined by the Garante 40,000 EUR for failing to properly notify the data processing activities linked to the geolocation of vehicles used in its car sharing service. The authority found that the notification obligations under the Italian data protection code were not met. | IT | Garante | GDPR | €40,000 | ↗ |
| 22 Sept 2011 | C.T.M. s.p.a.C.T.M. s.p.a. was fined 40,000 EUR by the Italian data protection authority, Garante. The case concerned the failure to formally designate data processors and a breach of minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 14 Nov 2024 | Provvedimento del 14 novembre 2024 [10104860]Garante imposed a EUR 40,000 fine on a healthcare company for failing to update its security assessments in response to increased cyberattacks. The authority found a breach of GDPR Article 32 because technical and organizational measures were not adjusted to the changed risk level. | IT | Garante | GDPR | €40,000 | ↗ |
| 11 Feb 2021 | Bonatti S.p.ABonatti S.p.A was fined EUR 40,000 by the Garante for violating data protection rules. The company improperly shared an employee's medical data with a third party. | IT | Garante | GDPR | €40,000 | ↗ |
| 27 Apr 2023 | Geico S.p.A.Geico S.p.A. was fined 40,000 EUR by the Garante for keeping former employees' email accounts active after the employment relationship ended. The authority found that the company accessed the contents of those accounts in breach of GDPR requirements. | IT | Garante | GDPR | €40,000 | ↗ |
| 21 Dec 2018 | Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act. | NL | AP | GDPR | €40,000 | ↗ |
| 19 Nov 2021 | Working Capital Management España, S.L.Working Capital Management España, S.L. was fined by the AEPD 40,000 EUR for unlawfully processing personal data. The company included an individual's data in a credit information system without a valid contract, in connection with an identity theft case. | ES | AEPD | GDPR | €40,000 | ↗ |
| 21 May 2020 | TuslaThe Irish DPC imposed a fine of EUR 40,000 on Tusla in case IN-19-12-8. The fine was collected. | IE | DPC | GDPR | €40,000 | ↗ |
| 13 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined 40,000 EUR by the AEPD for charging a customer's phone bill without consent. The authority found a breach of Article 6(1) GDPR due to the lack of a lawful basis for processing. | ES | AEPD | GDPR | €40,000 | ↗ |
| 18 Dec 2025 | LTL S.p.A.LTL S.p.A. was fined 40,000 EUR by the Garante for unlawfully maintaining access to an ex-employee’s email account after termination. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 23 Mar 2023 | La Risorsa Umana.it s.r.l.La Risorsa Umana.it s.r.l. was fined EUR 40,000 by the Garante for monitoring employee email communications without providing proper information to employees. The authority found that this conduct breached GDPR requirements on transparency of processing and data security. | IT | Garante | GDPR | €40,000 | ↗ |
| 27 Jan 2022 | T.S.M. s.r.l.T.S.M. s.r.l. was fined EUR 40,000 by the Italian supervisory authority, the Garante. The sanction concerned the failure to respond to information requests, which breached GDPR obligations related to data subject rights. | IT | Garante | GDPR | €40,000 | ↗ |
| 19 Dec 2024 | SOCIETE EXERCANT UNE ACTIVITE D'AGENCE IMMOBILIERECNIL imposed an administrative fine of EUR 40,000 on SOCIETE EXERCANT UNE ACTIVITE D'AGENCE IMMOBILIERE. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €40,000 | ↗ |
| 12 Mar 2026 | La7 S.p.A.La7 S.p.A. was fined 40,000 EUR by the Garante for broadcasting personal data, including phone numbers and names, during a news segment. The authority found a breach of GDPR Article 5 on data processing principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 19 Jun 2020 | IBERDROLA CLIENTES, SAUThe AEPD fined IBERDROLA CLIENTES, SAU EUR 40,000 for emailing a customer's electricity bill, which contained sensitive personal data, to an unrelated third party. The incident indicates a breach of confidentiality and personal data protection obligations. | ES | AEPD | GDPR | €40,000 | ↗ |