Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Nov 2011PUBLIACCION, PUBLICIDAD Y COMUNICACION S.L.U.PUBLIACCION, PUBLICIDAD Y COMUNICACION S.L.U. was fined by the AEPD €1,200 for sending unsolicited SMS messages without recipient consent. The conduct breached Article 21 of the LSSI on unsolicited electronic communications.ESAEPDePrivacy€1,200
26 Mar 2026PSK AD Network S.r.l.PSK AD Network S.r.l. was fined EUR 5,000 by the Garante. The case concerned the failure to respond to a data subject’s deletion request and the failure to provide information requested by the authority, in breach of Article 157 of the Codice.ITGaranteGDPR€5,000
01 Jan 2025PROYECTOS VISUALES ZARAGOZA SLPROYECTOS VISUALES ZARAGOZA SL was fined by the AEPD 50,000 EUR for a personal data breach. The authority found that the company failed to ensure data integrity and confidentiality under Article 5(1)(f) GDPR.ESAEPDGDPR€50,000
11 Sept 2025Provvedimento dell'11 settembre 2025 [10184654]The decision imposes a fine on a healthcare company for cybersecurity-related breaches following a security incident involving patient data. The authority found non-compliance with Articles 25 and 32 GDPR.ITGaranteGDPR€8,000
11 Sept 2025Provvedimento dell'11 settembre 2025 [10184252]A public entity was fined by the Garante EUR 500 for installing a video surveillance system in a public parking area without providing adequate information to data subjects. The authority found a breach of GDPR transparency and information obligations.ITGaranteGDPR€500
09 Oct 2025Provvedimento del 9 ottobre 2025 [10184697]The Garante imposed a EUR 70,000 fine on a company managing a hospital for violations related to the processing of health data. The case also involved a change in the complainant's treatment path and a failure to notify the authority of a data breach.ITGaranteGDPR€70,000
09 May 2024Provvedimento del 9 maggio 2024 [10027595]The authority imposed a fine on an anonymized healthcare entity for unauthorized access to patient health records by personnel without proper authorization. The case concerned GDPR requirements on data protection and processing security.ITGaranteGDPR€25,000
06 Jul 2023Provvedimento del 6 luglio 2023 [9925450The Garante imposed a EUR 2,000 fine on an individual for posting images of other people on social media without their consent. The authority found a breach of GDPR rights, including the rights to erasure and objection.ITGaranteGDPR€2,000
04 Jul 2024Provvedimento del 4 luglio 2024 [10068075]The Garante imposed a EUR 400 fine on an individual for improperly installing a surveillance system. The cameras captured public street areas, which breached privacy rules.ITGaranteGDPR€400
31 Aug 2023Provvedimento del 31 agosto 2023 [9938463]The decision concerned a breach of rules on the processing of health data by a medical center. Garante imposed a fine of EUR 10,000.ITGaranteGDPR€10,000
27 Mar 2025Provvedimento del 27 marzo 2025 [10140216]The Garante fined Powerfit, Soleo, and Zero Due Villa for sending promotional SMS messages without the recipients’ consent. The messages also did not provide an opt-out mechanism, which breached GDPR requirements.ITGaranteGDPR€6,000
27 Apr 2023Provvedimento del 27 aprile 2023 [9896468]A fine of EUR 400 was imposed for improper use of a video surveillance system that captured images of a public street without the required authorization. The case concerned a breach of personal data processing rules in the context of video monitoring.ITGaranteGDPR€400
26 Oct 2023Provvedimento del 26 ottobre 2023 [9960920]The Garante imposed a EUR 1,000 fine on a condominium administrator for installing a video surveillance system without a proper legal basis or assembly resolution. The conduct was found to breach GDPR rules on lawful processing.ITGaranteGDPR€1,000
26 Mar 2026Provvedimento del 26 marzo 2026 [10246060]The entity was fined for operating a video surveillance system without providing adequate informational signage. The authority found this to be a breach of GDPR Article 13 on the duty to inform data subjects.ITGaranteGDPR€2,000
26 Mar 2026Provvedimento del 26 marzo 2026 [10241477]A doctor did not comply with a request to delete data and provided patients with incomplete information, which constituted a breach of GDPR Article 13. The Garante imposed a fine of EUR 2,000.ITGaranteGDPR€2,000
23 Oct 2025Provvedimento del 23 ottobre 2025 [10210718]The Garante imposed a EUR 10,000 fine on an individual tobacco shop owner for suspicious financial transactions involving the misuse of a third party’s identification data with a prepaid card. The case concerns unauthorized use of personal data in the context of payment operations.ITGaranteGDPR€10,000
23 Oct 2025Provvedimento del 23 ottobre 2025 [10195910]A fine of EUR 1,000 was imposed for the unlawful online publication of personal data by a local authority. The conduct breached core data protection principles.ITGaranteGDPR€1,000
23 May 2024Provvedimento del 23 maggio 2024 [10043051]The Garante imposed a fine of EUR 400 for the unlawful use of surveillance cameras capturing public areas without a proper legal basis. The conduct breached privacy and data protection requirements.ITGaranteGDPR€400
20 Jun 2024Provvedimento del 20 giugno 2024 [10105123]The Municipality of XX was fined for unlawfully disclosing personal and health data by publishing it on its Facebook page. The authority found that the public disclosure of this information breached data protection rules.ITGaranteGDPR€10,000
20 Jun 2024Provvedimento del 20 giugno 2024 [10037411]The Garante imposed a fine on a healthcare entity for delays in providing preoperative photographs. The delay affected the complainant's legal position in ongoing proceedings.ITGaranteGDPR€4,000