Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Apr 2013I.S.P. Italia srlI.S.P. Italia srl was fined by the Garante for sending unsolicited promotional faxes without the required information notice and without obtaining recipients’ consent. The authority found that the conduct breached rules on prior consent and information duties.ITGaranteGDPR€32,000
06 Dec 2012Wire s.r.l.Wire s.r.l. was fined by the Garante in the amount of EUR 32,000 for making pre-recorded electoral propaganda calls without prior, specific, and informed consent from the recipients. The authority found this to be a breach of data protection rules.ITGaranteGDPR€32,000
19 Oct 2017Grant Change s.r.l.Grant Change s.r.l. was fined €32,000 by the Italian data protection authority, Garante. The penalty concerned the sending of promotional SMS messages and emails without valid consent from recipients, in breach of data protection rules.ITGaranteGDPR€32,000
04 May 2017Easy C@ll s.r.l.Easy C@ll s.r.l. was fined EUR 32,000 by the Garante for making unsolicited promotional calls to individuals listed in the public opt-out register. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€32,000
11 Jun 2015Banca Nazionale del Lavoro S.p.a.Banca Nazionale del Lavoro S.p.a. was fined by the Garante 32,000 EUR for processing personal data without first informing the data subjects and without obtaining their consent. The case concerns a breach of core notice and consent obligations in personal data processing.ITGaranteGDPR€32,000
31 May 2017Unit Contact s.r.l.Unit Contact s.r.l. was fined €32,000 by the Italian authority Garante. The case concerned unsolicited promotional calls made without the required information notice and without obtaining consent, in breach of data protection rules.ITGaranteGDPR€32,000
20 Nov 2014Aimon s.r.l.Aimon s.r.l. was fined EUR 32,000 by the Garante for sharing customers’ personal data with various companies without proper notice and consent. The authority found that the conduct breached privacy rules.ITGaranteGDPR€32,000
18 Jan 2018Italia Consulenza e Formazione s.r.l.Italia Consulenza e Formazione s.r.l. was fined EUR 32,000 by the Garante for sending promotional emails without proper consent. The case concerns a breach of data protection rules governing direct marketing.ITGaranteGDPR€32,000
01 Dec 2011Soprintendenza per i beni architettonici, paesaggistici, storici, artistici e etnoantropologici per Napoli e provinciaThe Garante fined Soprintendenza 32,000 EUR for violations related to the processing of biometric data. The authority found that the processing did not comply with the required legal requirements.ITGaranteGDPR€32,000
08 May 2013Agro Informatica di Buracchi GinoAgro Informatica di Buracchi Gino was fined 32,000 EUR by the Garante for sending unsolicited promotional emails without prior explicit consent. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code.ITGaranteGDPR€32,000
21 Mar 2012Solar Energy Group s.p.aSolar Energy Group s.p.a was fined by the Garante 32,000 EUR for processing personal data collected through online forms without providing the required information or obtaining consent. The authority found breaches of Articles 13 and 23 of the Italian Privacy Code.ITGaranteGDPR€32,000
12 Apr 2018Azienda Ospedaliera Sant’Andrea di RomaAzienda Ospedaliera Sant’Andrea di Roma was fined 32,000 EUR by the Garante for violations related to the processing of personal data in healthcare services. The case concerned deficiencies in consent handling and patient information forms.ITGaranteGDPR€32,000
26 Feb 2026Dedalus Italia S.p.A.Dedalus Italia S.p.A. was fined EUR 32,000 by the Garante for inadequate security measures that led to a data breach. The company implemented corrective actions promptly, but prior violations were taken into account when setting the penalty.ITGaranteGDPR€32,000
18 Oct 2012Verzeri MaurizioVerzeri Maurizio was fined EUR 32,000 by the Italian data protection authority, Garante. The case concerned the sending of unsolicited promotional faxes without prior recipient consent and without providing the information required under the data protection code.ITGaranteGDPR€32,000
30 Aug 2022Dane anonimowe (T. Spółkę z ograniczoną odpowiedzialnością z siedzibą w W.)The President of UODO imposed an administrative fine of PLN 31,988 on T. Ltd. The authority found that the company failed to provide access to information necessary for the President of UODO to carry out his duties.PLUODOGDPR€6,759
02 Nov 2024Intesa SanpaoloThe Italian Data Protection Authority fined Intesa Sanpaolo €31.8 million for a data breach involving unauthorized access to banking information of more than 3,500 clients. The authority also found that the bank detected the activity late and filed an incomplete and delayed breach notification.ITGarante per la protezione dei dati personaliGDPR€31,800
01 Jan 2022RIANLU EUROPA S.L.RIANLU EUROPA S.L. was fined EUR 30,010 by the AEPD for sending commercial SMS messages without providing recipients with an opt-out mechanism. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€30,010
25 Mar 2017IMPACTING EMAIL MARKETING SOLUTIONS S.L.IMPACTING EMAIL MARKETING SOLUTIONS S.L. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent. The authority found this conduct to be in breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
21 Mar 2012GROUPON SPAIN SLGROUPON SPAIN SL was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails. The messages were sent despite the recipient's requests to unsubscribe, which breached Article 21 of the LSSI.ESAEPDePrivacy€30,001
01 Jan 2013SPAIN ON LINE, S.L.SPAIN ON LINE, S.L. was fined €30,001 by the AEPD for sending unsolicited promotional emails despite requests to stop. The conduct breached Article 21 of the LSSI on marketing communications without consent.ESAEPDePrivacy€30,001