Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Mar 2015Provincia di PisaProvincia di Pisa was fined €10,000 by the Garante. The authority found that employees at the employment center were not designated as data processing officers, resulting in insufficient security measures for handling personal data.ITGaranteGDPR€10,000
13 May 2015Provincia di NapoliProvincia di Napoli was fined for unlawfully publishing personal data, including health information, on its institutional website. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
07 May 2015Provincia di FrosinoneProvincia di Frosinone was fined for failing to update the Security Policy Document (DPS) for several years. The authority found this to be a breach of security measures required under the Italian Data Protection Code.ITGaranteGDPR€10,000
16 Sept 2010Provincia di FoggiaProvincia di Foggia was fined by the Garante for making health-related personal data publicly accessible through Google and its website. The case involved improper disclosure of sensitive data, which breached data protection rules.ITGaranteGDPR€20,000
11 Jan 2024Provincia di CatanzaroThe Garante fined Provincia di Catanzaro EUR 2,000 for violations of data protection obligations under Article 37 GDPR. The case concerned non-compliance with requirements related to the designation of a data protection officer.ITGaranteGDPR€2,000
30 Mar 2017Provincia di CasertaProvincia di Caserta was fined EUR 20,000 by the Garante. The authority found that the province failed to designate data processing officers and did not update the security program document required under the data protection code.ITGaranteGDPR€20,000
01 Feb 2018Provincia di BeneventoProvincia di Benevento was fined by the Garante for unlawfully publishing special-category personal data on its website, including health information and tax codes. The authority found a breach of data protection rules.ITGaranteGDPR€60,000
29 Jan 2026Provincia della Congregazione dei Fratelli delle Suore CristianeThe entity was fined for failing to ensure sufficient transparency in data processing and for not carrying out a data protection impact assessment for workplace surveillance systems. The authority found breaches of the GDPR and the national privacy code.ITGaranteGDPR€12,000
25 Sept 2025Provincia Autonoma di TrentoProvincia Autonoma di Trento was fined for processing personal data without a legal basis, lacking transparency, and failing to conduct a data protection impact assessment. The authority found breaches of several GDPR provisions.ITGaranteGDPR€8,000
09 Jul 2023PROSULTING, S.L.N.E.PROSULTING, S.L.N.E. was fined by the AEPD in the amount of 1,000 EUR for failing to provide data subjects with the information required under Article 13 GDPR. The case concerned a lack of proper notice about the processing of personal data.ESAEPDGDPR€1,000
01 Jan 2016PROSAD CONSULTORES, S.L.PROSAD CONSULTORES, S.L. was fined by the AEPD 600 EUR for sending unsolicited commercial emails without prior consent. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€600
06 Oct 2020PROSAD CONSULTORES, S.L.PROSAD CONSULTORES, S.L. was fined by the AEPD 12,000 EUR for sending unsolicited commercial emails without prior consent. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€12,000
01 Jan 2018PROSAD CONSULTORES, S.L.PROSAD CONSULTORES, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited promotional emails without prior consent. The conduct breached Article 21.1 of the LSSI on electronic commercial communications.ESAEPDePrivacy€1,000
01 Jan 2016PROSAD CONSULTORES S.L.PROSAD CONSULTORES S.L. was fined by the AEPD EUR 800 for sending unsolicited commercial emails. The recipient had not given prior consent and was listed on the Robinson List, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€800
30 Mar 2021PROMOTECH DIGITAL, S.L.PROMOTECH DIGITAL, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited SMS messages without recipient consent. The authority also found that the company did not provide an easy opt-out mechanism, in breach of data protection rules.ESAEPDGDPR€5,000
02 Dec 2011PROMOMOVIL TELECOMUNICACIONES S.L.PROMOMOVIL TELECOMUNICACIONES S.L. was fined by the AEPD 1,200 EUR for sending unsolicited promotional SMS messages without recipient consent. The conduct breached Article 21 of the LSSI on commercial communications without prior consent.ESAEPDePrivacy€1,200
20 Mar 2008PromofaxPromofax was fined by the Italian authority Garante in the amount of EUR 3,000. The case concerned sending advertising material by fax without providing recipients with prior and adequate information, in breach of data protection rules.ITGaranteGDPR€3,000
20 Oct 2022Promofarma Sviluppo s.r.l.Promofarma Sviluppo s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate data security measures and for lacking transparency in the authentication process on vaccine booking portals. These shortcomings made the system vulnerable to fraudulent access and misuse.ITGaranteGDPR€10,000
02 Sept 2024Prokuraturę KrajowąUODO imposed an administrative fine of 85,000 PLN on the National Prosecutor's Office for breaches of Article 6(1), Article 9(1), Article 33(1), and Article 34(1) and (2) of the GDPR. The authority also ordered notification of the affected data subjects.PLUODOGDPR€19,883
16 Dec 2021Progetto Udire S.r.l.Progetto Udire S.r.l. was fined by the Garante 30,000 EUR. The authority found that the company sent unsolicited marketing communications without proper consent and failed to provide information on the origin of personal data when requested by the data subject.ITGaranteGDPR€30,000