BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Sept 2023 | Asl Napoli 3 SudThe Garante fined Asl Napoli 3 Sud EUR 30,000 for inadequate security measures that led to a data breach. The incident caused limited service disruption. | IT | Garante | GDPR | €30,000 | ↗ |
| 28 Jun 2023 | Fortis Insolvency LimitedFortis Insolvency Limited sent 558,354 direct marketing SMS messages without valid consent, of which 527,481 were received by subscribers between 26 July 2020 and 26 July 2021. This breached regulation 22 of PECR. The company was fined £30,000 and issued with an enforcement notice. | GB | ICO | ePrivacy | €34,713 | ↗ |
| 20 Feb 2026 | VodafoneThe Greek Data Protection Authority fined Vodafone EUR 30,000 for GDPR breaches related to a subscriber’s request to access recorded phone conversations. The authority found violations of transparency obligations under Article 12 and of the rights of access and restriction of processing under Articles 15 and 18 GDPR. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €30,000 | ↗ |
| 14 Oct 2024 | National Debt Advice LimitedNational Debt Advice Limited sent 129,902 unsolicited direct marketing text messages, breaching regulation 22 of PECR. The activity generated more than 4,000 complaints to the 7726 spam reporting service. The ICO imposed a £30,000 fine and issued an enforcement notice. | GB | ICO | ePrivacy | €35,856 | ↗ |
| 05 Oct 2017 | Comune di CivitavecchiaComune di Civitavecchia was fined by the Garante for unlawfully transmitting sensitive data revealing the health status of disabled students to service providers without a proper legal basis. The authority found that the processing breached data protection and confidentiality requirements. | IT | Garante | GDPR | €30,000 | ↗ |
| 14 Jul 2011 | Il Tarì società consortile per azioniIl Tarì società consortile per azioni was fined €30,000 by the Garante for failing to provide adequate information and notification about the processing of personal data using biometric systems. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 29 Sept 2021 | GEDI News Network S.p.A.GEDI News Network S.p.A. was fined 30,000 EUR by the Garante for publishing personal data and detailed information about an individual involved in a workplace accident. The authority found a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 16 Dec 2021 | Progetto Udire S.r.l.Progetto Udire S.r.l. was fined by the Garante 30,000 EUR. The authority found that the company sent unsolicited marketing communications without proper consent and failed to provide information on the origin of personal data when requested by the data subject. | IT | Garante | GDPR | €30,000 | ↗ |
| 20 Mar 2015 | IANO OIKONOMIKE EKDOSEIS AEIANO OIKONOMIKE EKDOSEIS AE was fined EUR 30,000 by the HDPA for sending unsolicited electronic communications. The company collected a large number of email addresses without consent, breaching data protection rules. | GR | HDPA | ePrivacy | €30,000 | ↗ |
| 16 Apr 2025 | 20 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined by the AEPD for the unauthorized dissemination of a video containing personal data. The authority found a breach of the data minimization principle under Article 5(1)(c) GDPR. | ES | AEPD | GDPR | €30,000 | ↗ |
| 16 Dec 2009 | Casa di cura Villa Russo s.p.a.Casa di cura Villa Russo s.p.a. was fined by the Garante for processing personal data without proper notification. The authority found violations of articles 37 and 38 of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 22 Feb 2018 | FAMAS S.R.L.FAMAS S.R.L. was fined by the Garante for using a biometric system based on fingerprint recognition to record employee attendance without a proper legal basis. The case concerned the processing of biometric data in an employment context, where specific lawful grounds are required. | IT | Garante | GDPR | €30,000 | ↗ |
| 09 May 2024 | Unicredit S.p.a.Unicredit S.p.a. was fined EUR 30,000 by the Garante for failing to respond to a personal data access request submitted by an heir. The authority found a breach of GDPR Article 15 and the Italian privacy code. | IT | Garante | GDPR | €30,000 | ↗ |
| 29 Nov 2012 | G & W Invest s.r.l.G & W Invest s.r.l. was fined €30,000 by the Italian data protection authority, Garante. The case concerned processing biometric data without timely notification, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 21 Sept 2018 | Anonymizováno (ÚOOÚ UOOU-01895/18-25)The entity was fined by the UOOU for processing personal data without consent and for failing to implement adequate security measures. The authority found these actions to be in breach of Czech data protection law. | CZ | UOOU | GDPR | €1,173 | ↗ |
| 21 Aug 2014 | GROUPON SPAIN, S.L.U.Groupon Spain, S.L.U. was fined by the AEPD EUR 30,000 for sending unsolicited commercial emails to the complainant. The authority found that the conduct breached the Spanish LSSI requirements governing marketing communications. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 05 Dec 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 30,000 for inaccurately processing personal data. The company claimed a debt for a service that had already been terminated and had no outstanding balance. | ES | AEPD | GDPR | €30,000 | ↗ |
| 08 Jun 2023 | L’Editoriale Nazionale S.r.l.The Garante fined L’Editoriale Nazionale S.r.l. EUR 30,000 for publishing articles that breached privacy rules. The company disclosed personal and sensitive data relating to a deceased minor without showing that the information was essential. | IT | Garante | GDPR | €30,000 | ↗ |
| 13 May 2015 | Gelpi Elettrodomestici S.r.l.Gelpi Elettrodomestici S.r.l. was fined 30,000 EUR by the Garante. The case concerned the activation of SIM cards in individuals' names without their knowledge, which breached data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 22 Jul 2021 | Flowbird s.r.l.Flowbird s.r.l. was fined EUR 30,000 by the Garante for processing personal data through parking meters in Rome without a legal basis. The authority also found that the company failed to maintain a record of processing activities. | IT | Garante | GDPR | €30,000 | ↗ |