BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Feb 2018 | Anonymizováno (ÚOOÚ UOOU-06702/17-37)The entity was fined CZK 50,000 by the Czech data protection authority for failing to provide the required cooperation during an ongoing inspection. This breached the duty to create conditions for the inspection and to allow the inspector to exercise their powers. | CZ | UOOU | GDPR | €1,985 | ↗ |
| 12 Feb 2018 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ж-453-05-10-201)The Commission fined an individual for unlawfully processing personal data by including it in a list supporting registration for a referendum campaign without consent. The case concerned a breach of the legal basis requirements for personal data processing. | BG | CPDP | GDPR | €5,113 | ↗ |
| 12 Feb 2018 | Политическа партия „Движение презареди България“The political party Movement Reload Bulgaria was fined 10,000 BGN by the CPDP for processing personal data without consent. The breach occurred during the registration of individuals as election commission members and violated the Bulgarian Personal Data Protection Act. | BG | CPDP | GDPR | €5,113 | ↗ |
| 15 Feb 2018 | Innovastem s.r.l.Innovastem s.r.l. was fined by the Garante for processing personal data without providing the required information notice and for handling health-related data without proper consent. The case indicates breaches of transparency obligations and the rules governing the lawful processing of sensitive data. | IT | Garante | GDPR | €22,400 | ↗ |
| 15 Feb 2018 | Casa della legalità e della cultura onlusCasa della legalità e della cultura onlus was fined EUR 20,000 by the Garante. The authority found a data protection breach because the organization failed to respond to requests for information about the publication of personal data on its websites. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Feb 2018 | Nazzareno SalernoNazzareno Salerno was fined for unlawful processing of personal data by sending electoral propaganda emails without proper consent. This breached Garante rules on data handling by political parties. | IT | Garante | GDPR | €12,000 | ↗ |
| 15 Feb 2018 | AUTONOLEGGI 24 S.a.s. DI GIAQUINTO GIOVANNIAUTONOLEGGI 24 S.a.s. was fined by the Garante for processing personal data through a geolocation system without the required notification. The case concerned breaches of notification and supervisory obligations linked to that processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Feb 2018 | Auto Uno s.r.l.Auto Uno s.r.l. was fined EUR 30,000 by the Italian Garante. The case concerned improper management of a video surveillance system, including excessive retention of recorded images. | IT | Garante | GDPR | €30,000 | ↗ |
| 15 Feb 2018 | APS Holding S.p.a.APS Holding S.p.a. was fined by the Garante 40,000 EUR for failing to properly notify the data processing activities linked to the geolocation of vehicles used in its car sharing service. The authority found that the notification obligations under the Italian data protection code were not met. | IT | Garante | GDPR | €40,000 | ↗ |
| 15 Feb 2018 | Genova Car Sharing SrlGenova Car Sharing Srl was fined EUR 46,000 by the Garante. The authority found that customers were not fully informed about vehicle geolocation and that separate consent was not obtained for newsletter communications. | IT | Garante | GDPR | €46,000 | ↗ |
| 19 Feb 2018 | AVIS ALQUILE UN COCHE S.A.AVIS ALQUILE UN COCHE S.A. was fined by the AEPD 10,000 EUR for improper handling of personal data. This led to the wrongful publication of an individual's details in the Official State Gazette as the responsible party for a traffic violation they did not commit. | ES | AEPD | GDPR | €10,000 | ↗ |
| 20 Feb 2018 | Anonymizováno (ÚOOÚ UOOU-12027/17-24)The entity was fined CZK 20,000 for disclosing sensitive personal data of a witness and a victim in a criminal case during a TV report. The authority found that the processing took place without explicit consent and without a valid legal exception. | CZ | UOOU | GDPR | €790 | ↗ |
| 22 Feb 2018 | SIDA GROUP SrlSIDA GROUP Srl was fined by the Garante for failing to promptly update its company name and registered office in its data processing notification. The case concerned non-compliance with data protection obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Feb 2018 | Bar La Piazzetta s.a.s.Bar La Piazzetta s.a.s. was fined EUR 46,000 by the Italian Garante. The authority found that surveillance footage was kept longer than permitted, access was not password-protected, and the required privacy notices were not provided. | IT | Garante | GDPR | €46,000 | ↗ |
| 22 Feb 2018 | Technical Hunter s.r.l.Technical Hunter s.r.l. was fined by the Garante 20,000 EUR for processing job applicants’ personal data without proper compliance with data protection rules. The data was collected and used through the company website, job portals, and social networks. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Feb 2018 | FAMAS S.R.L.FAMAS S.R.L. was fined by the Garante for using a biometric system based on fingerprint recognition to record employee attendance without a proper legal basis. The case concerned the processing of biometric data in an employment context, where specific lawful grounds are required. | IT | Garante | GDPR | €30,000 | ↗ |
| 22 Feb 2018 | Comune di FiumicinoComune di Fiumicino was fined by the Garante for failing to notify a data breach within the required timeframe. The authority found a violation of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 01 Mar 2018 | Massimo FarinaMassimo Farina was fined EUR 280,000 by the Garante. The case concerned the use of prepaid credit cards under false names without obtaining consent, which breached data protection rules. | IT | Garante | GDPR | €280,000 | ↗ |
| 01 Mar 2018 | Ministero dell’Istruzione, dell’Università e della RicercaThe Ministry of Education, University and Research was fined €16,000 by the Garante for violations related to the handling of personal data in the implementation of the “Carta docente” application. The case concerned deficiencies in the way user data was processed within the service. | IT | Garante | GDPR | €16,000 | ↗ |
| 01 Mar 2018 | Yahoo! Italia s.r.l.Yahoo! Italia s.r.l. was fined by the Garante in the amount of 60,000 EUR. The company failed to comply with a request to remove certain URLs containing personal information from its search engine and did not provide information on the implementation of that request. | IT | Garante | GDPR | €60,000 | ↗ |