BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Mar 2015 | Hayat KhizerHayat Khizer was fined EUR 3,000 by the Garante for improper registration of SIM cards. The cards were used by persons other than the formal registrants in connection with a criminal investigation into drug trafficking. | IT | Garante | GDPR | €3,000 | ↗ |
| 07 May 2015 | Burger Joint/Maria Galioni I.K.E.The company was fined for unlawfully operating a video surveillance system in the workplace. The authority found a privacy violation because employees and customers were monitored without proper justification. | GR | HDPA | GDPR | €3,000 | ↗ |
| 20 Mar 2008 | Scuola College di Cagno Abbrescia s.r.l.Scuola College di Cagno Abbrescia s.r.l. was fined EUR 3,000 by the Garante. The case concerned the failure to provide access to personal data requested by the parents of a minor, in breach of the Italian data protection code. | IT | Garante | GDPR | €3,000 | ↗ |
| 27 Jun 2012 | OKANAOKANA was fined by the HDPA in the amount of 3,000 EUR for failing to adequately protect special-category personal data. Documents containing patients’ health data were found in trash bins, indicating a breach of data protection rules. | GR | HDPA | GDPR | €3,000 | ↗ |
| 22 Feb 2021 | B.B.B.The entity was fined by the AEPD for a video surveillance system that was improperly oriented toward private areas. The authority also found that the area was not adequately signposted, breaching data protection rules. | ES | AEPD | GDPR | €3,000 | ↗ |
| 01 Jan 2025 | MONUMENTAL FORMA SPORT, S.L.MONUMENTAL FORMA SPORT, S.L. was fined by the AEPD EUR 3,000 for requesting excessive personal data, including banking information, in connection with a free gym access promotion. The authority found that the data requested breached the GDPR data minimisation principle under Article 5(1)(c). | ES | AEPD | GDPR | €3,000 | ↗ |
| 18 Jul 2023 | ING BANK NV Amsterdam Sucursala BucureștiING Bank NV Amsterdam Sucursala București received a fine from ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 16 Jun 2010 | Anonymised (HDPA 29/2010)The company was fined EUR 3,000 by the HDPA for sending unsolicited marketing emails and faxes without subscriber consent. This conduct breached ePrivacy rules on electronic marketing communications. | GR | HDPA | ePrivacy | €3,000 | ↗ |
| 01 Mar 2017 | A.A.A.A.A.A. was fined €3,000 by the AEPD. The authority found that cookies were installed on its websites without prior information and consent, in breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 09 May 2024 | Ordine dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche, della Riabilitazione e della Prevenzione della provincia di MantovaThe Garante imposed a 3,000 EUR fine on the Ordine dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche, della Riabilitazione e della Prevenzione della provincia di Mantova for breaches of data protection principles. The authority found non-compliance with lawfulness, fairness, transparency, and data minimization. The infringement affected a significant number of data subjects. | IT | Garante | GDPR | €3,000 | ↗ |
| 23 Mar 2023 | Consiglio Nazionale dell'Ordine degli Assistenti SocialiConsiglio Nazionale dell'Ordine degli Assistenti Sociali was fined EUR 3,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data during a recruitment process, including disclosure of information about a candidate's exclusion. | IT | Garante | GDPR | €3,000 | ↗ |
| 15 Feb 2022 | ASOCIACIÓN DE AFICIONADOS Y PEQUEÑOS ACCIONISTAS UNIDAD HERCULANAThe organization was fined by the AEPD 3,000 EUR for failing to provide a privacy policy compliant with Article 13 of the GDPR on its website. It collected personal data through various forms but did not provide the required information to data subjects. | ES | AEPD | GDPR | €3,000 | ↗ |
| 13 Mar 2025 | ImmosanremoImmosanremo was fined EUR 3,000 by the Garante for sending unsolicited marketing messages via WhatsApp without valid consent. The authority found that the conduct breached GDPR rules on processing personal data for promotional purposes. | IT | Garante | GDPR | €3,000 | ↗ |
| 12 Feb 2026 | Comune di AnconaThe Garante fined Comune di Ancona EUR 3,000 for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found that no proper contract was in place with a data processor, in breach of GDPR Articles 5 and 28. | IT | Garante | GDPR | €3,000 | ↗ |
| 30 Apr 2014 | COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD 3,000 EUR for sending unsolicited and misleading commercial messages by electronic means. The authority found a breach of Article 21 of the LSSI on marketing communications without prior consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jun 2023 | Comune di NapoliComune di Napoli was fined for improperly communicating performance evaluation results of former employees. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 02 Oct 2020 | INSTITUTO DEL DAÑO CEREBRAL Y PSÍQUICO, S.L.The entity did not provide timely access to clinical records, which constituted a breach of data protection obligations. Deficiencies were also identified in the website's cookie policy, leading the AEPD to impose a fine. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 24 Oct 2023 | Mensajero SRLMensajero SRL was fined EUR 3,000 by ANSPDCP for a data security breach on its website. A link allowed access to downloadable files containing customer invoices and product warranty certificates. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 09 May 2024 | Polisportiva Mimmo Ferrito s.r.l.The Garante fined Polisportiva Mimmo Ferrito s.r.l. EUR 3,000 for failing to respond to a data subject's request to exercise their rights. The case concerns non-compliance with data protection obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 11 Dec 2008 | Comune di PontenureComune di Pontenure was fined EUR 3,000 by the Garante for failing to provide the required data protection notice when sending a questionnaire about waste management tariffs. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |