BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2018 | PROSAD CONSULTORES, S.L.PROSAD CONSULTORES, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited promotional emails without prior consent. The conduct breached Article 21.1 of the LSSI on electronic commercial communications. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 01 Jan 2018 | SHANA RETAIL S.L.SHANA RETAIL S.L. was fined by the AEPD for improperly disposing of documents containing personal data. The breach concerned data protection rules and the need to prevent unauthorized disclosure of information. | ES | AEPD | GDPR | €15,000 | ↗ |
| 01 Jan 2018 | ADGOALS MEDIA S.L.ADGOALS MEDIA S.L. was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited SMS advertisements without prior recipient consent. The authority also found that no opt-out mechanism was provided, which constitutes a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 01 Jan 2018 | G.L. GISOFT ANÁLISIS Y DISEÑO, S.L.G.L. GISOFT ANÁLISIS Y DISEÑO, S.L. was fined 600 EUR by the AEPD. The case concerned the sending of unsolicited commercial emails, which breaches Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 11 Jan 2018 | N.J.L. & Time di Bernasconi NadiaN.J.L. & Time di Bernasconi Nadia was fined 68,000 EUR by the Garante. The authority found that promotional emails were sent without proper consent, in breach of data protection rules. | IT | Garante | GDPR | €68,000 | ↗ |
| 15 Jan 2018 | Alkis Alqi Zarbala ZarballaA fine was imposed for operating a video surveillance system without the required notification and for monitoring employee workspaces. These actions breached data protection rules. | GR | HDPA | GDPR | €1,000 | ↗ |
| 18 Jan 2018 | Telecom Italia S.p.A.Telecom Italia S.p.A. was fined EUR 840,000 by the Garante for making promotional phone calls to individuals who had not consented to the processing of their data for marketing purposes. The case indicates a breach of lawful processing rules and consent requirements. | IT | Garante | GDPR | €840,000 | ↗ |
| 18 Jan 2018 | C.S. GROUP S.p.a.C.S. GROUP S.p.a. was fined by the Italian Garante in the amount of €60,000. The case concerned profiling and the processing of personal data without a proper legal basis in connection with vehicle rental services. | IT | Garante | GDPR | €60,000 | ↗ |
| 18 Jan 2018 | KRI S.p.A.KRI S.p.A. was fined by the Italian data protection authority, Garante, for failing to notify the cessation of certain personal data processing activities. The case involved geolocation data and profiling, and the required notification was not made under the Italian data protection code. | IT | Garante | GDPR | €180,000 | ↗ |
| 18 Jan 2018 | Italia Consulenza e Formazione s.r.l.Italia Consulenza e Formazione s.r.l. was fined EUR 32,000 by the Garante for sending promotional emails without proper consent. The case concerns a breach of data protection rules governing direct marketing. | IT | Garante | GDPR | €32,000 | ↗ |
| 25 Jan 2018 | Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined by the Garante 60,000 EUR for publishing special-category personal data, including health information, on its institutional website. The disclosure breached data protection rules and triggered supervisory enforcement. | IT | Garante | GDPR | €60,000 | ↗ |
| 25 Jan 2018 | Avis Budget Italia s.p.a.Avis Budget Italia s.p.a. was fined EUR 60,000 by the Garante for improper installation and notification of geolocation devices on its vehicle fleet. The authority found that the company did not comply with data protection requirements. | IT | Garante | GDPR | €60,000 | ↗ |
| 25 Jan 2018 | Trivenet s.r.l.Trivenet s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company retained call data longer than permitted under data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 25 Jan 2018 | Scaramuzza MarioScaramuzza Mario was fined EUR 140,000 by the Garante for the unauthorized activation of multiple payment cards using personal data without the consent of the individuals concerned. The case indicates a breach of lawful processing requirements and the absence of a valid legal basis. | IT | Garante | GDPR | €140,000 | ↗ |
| 25 Jan 2018 | ATAM S.p.A. – Azienda territoriale Arezzo Mobilità S.p.A.ATAM S.p.A. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned failures to meet notification obligations related to a geolocation system used to track vehicles. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Feb 2018 | Car2Go Italia s.r.l.Car2Go Italia s.r.l. was fined EUR 20,000 by the Garante. The authority found a breach of data protection rules for failing to designate employees as data processors in connection with geolocation data processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Feb 2018 | Provincia di BeneventoProvincia di Benevento was fined by the Garante for unlawfully publishing special-category personal data on its website, including health information and tax codes. The authority found a breach of data protection rules. | IT | Garante | GDPR | €60,000 | ↗ |
| 01 Feb 2018 | Car City Club s.r.l.Car City Club s.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to designate data processors among its employees, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Feb 2018 | Transpe S.p.A.Transpe S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to notify the installation of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Feb 2018 | Iqbal QuasimIqbal Quasim was fined EUR 30,000 by the Garante. The case concerned registering phone SIM cards to third parties without their consent, which breached data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |