BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Nov 2025 | THERE’S AN AI FOR THAT S.R.LTHERE’S AN AI FOR THAT S.R.L. was fined 30,000 RON by ANSPDCP. The sanction concerns a breach of the national ePrivacy law. | RO | ANSPDCP | ePrivacy | €5,898 | ↗ |
| 29 Apr 2021 | Azienda Usl di BolognaThe Garante fined Azienda Usl di Bologna EUR 30,000 for violations related to the processing of personal data in the electronic health record. The case resulted in a data breach, indicating deficiencies in the protection or handling of patient data. | IT | Garante | GDPR | €30,000 | ↗ |
| 24 Apr 2024 | Rossi Carta S.r.l. UnipersonaleRossi Carta S.r.l. Unipersonale was fined by the Garante 30,000 EUR for sending unsolicited promotional emails and failing to respond to a data subject rights request. The authority also noted the use of an outdated content management system on the company website, which created potential security risks for personal data. | IT | Garante | GDPR | €30,000 | ↗ |
| 25 Jan 2012 | Porto 2000 società cooperativa a r. l.Porto 2000 società cooperativa a r. l. was fined EUR 30,000 by the Garante. The authority found that the company had not appointed data processing officers and had failed to implement minimum security measures for the video surveillance system at the Ancona tourist port. | IT | Garante | GDPR | €30,000 | ↗ |
| 31 Aug 2023 | GEDI News Network S.p.a.The Garante imposed a EUR 30,000 fine on GEDI News Network S.p.a. for publishing a photo of minors with insufficient pixelation, making them identifiable. The authority found this to be a breach of data protection rules concerning children. | IT | Garante | GDPR | €30,000 | ↗ |
| 13 Jun 2025 | GRUPO BONATEL SLGRUPO BONATEL SL was fined by the AEPD after an incident in which its database was encrypted and a ransom was demanded to prevent public disclosure. The authority found a breach of Article 5(1)(f) GDPR on integrity and confidentiality of personal data. | ES | AEPD | GDPR | €30,000 | ↗ |
| 25 Aug 2023 | This Is The Big Deal LimitedThis Is The Big Deal Limited sent or instigated 41,417,889 unsolicited direct marketing messages to individuals without consent, breaching regulation 22 of PECR. In addition, 102,132 text messages were sent without the required opt-out information under regulation 23 of PECR. The ICO imposed a fine of 30,000 GBP. | GB | ICO | ePrivacy | €35,028 | ↗ |
| 15 Dec 2022 | Verizon Connect Italy S.p.A.Verizon Connect Italy S.p.A. was fined EUR 30,000 by the Garante for violations linked to the unauthorized installation of a geolocation device in a vehicle. The authority found that the processing of personal data breached GDPR requirements. | IT | Garante | GDPR | €30,000 | ↗ |
| 01 Oct 2015 | San Vincenzo di Fernando Rota s.r.l.San Vincenzo di Fernando Rota s.r.l. was fined by the Garante for processing employees’ biometric data without notifying the authority and without requesting prior verification. The conduct breached privacy rules and the requirements applicable to sensitive data processing. | IT | Garante | GDPR | €30,000 | ↗ |
| 03 Jan 2023 | QUALITY-PROVIDER, S.A.QUALITY-PROVIDER, S.A. was fined by the AEPD in the amount of 30,000 EUR for processing personal data without consent. The data were then shared with third parties, who used them to contact the complainant via a personal social network. | ES | AEPD | GDPR | €30,000 | ↗ |
| 11 Oct 2012 | Casa di cura Eretenia S.p.a.The Garante fined Casa di cura Eretenia S.p.a. €30,000 for failing to provide proper data protection notices in its video surveillance system. The authority found a breach of privacy rules and the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €30,000 | ↗ |
| 14 Mar 2022 | RAMONA FILMS, S.LRAMONA FILMS, S.L was fined by the AEPD for failing to provide requested information to the Spanish Data Protection Agency. The breach concerned the duty to cooperate under GDPR Article 58(1). | ES | AEPD | GDPR | €30,000 | ↗ |
| 22 Dec 2020 | Anonymizováno (ÚOOÚ UOOU-004103/19-31)The company was fined for unlawfully processing personal data of members of homeowners' associations by publishing the data on its website without consent. The authority found this conduct to be in breach of the GDPR. | CZ | UOOU | GDPR | €1,141 | ↗ |
| 01 Jan 2022 | HOSPITAL POVISA, S.A.HOSPITAL POVISA, S.A. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned the improper inclusion of private health test results in a public health system, which violated the complainant’s privacy. | ES | AEPD | GDPR | €30,000 | ↗ |
| 14 Dec 2017 | Telenando di Sannino Caterina e C s.a.s.Telenando di Sannino Caterina e C s.a.s. was fined by the Garante EUR 30,000 for registering phone cards to unaware third parties without their consent. The case concerned a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 07 Feb 2022 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined €30,000 by the AEPD for using non-essential cookies on its website without obtaining prior user consent. The case concerns non-compliance with cookie consent rules and related user information requirements. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 20 Nov 2008 | Banca di Roma S.p.A.Banca di Roma S.p.A. was fined EUR 30,000 by the Garante for unauthorized access to the Bank of Italy's risk center. The authority also found that the company failed to provide adequate information to data subjects, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 06 Apr 2017 | Siportal s.r.l.Siportal s.r.l. was fined by the Garante for retaining telephone and internet traffic data longer than permitted by law. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 06 Nov 2025 | Lead Pronto LtdLead Pronto Ltd received an MPN and an EN from the ICO for sending unsolicited SMS messages promoting Government funded boiler grants. The case indicates a breach of direct marketing rules and consent requirements. | GB | ICO | GDPR | €34,065 | ↗ |
| 02 Dec 2021 | Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.The Garante imposed a EUR 30,000 fine on Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting patient health data. | IT | Garante | GDPR | €30,000 | ↗ |