BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Jul 2016 | Personal club s.r.l.Personal club s.r.l. was fined by the Garante in the amount of EUR 2,400 for failing to provide simplified information about the use of a video surveillance system. The breach concerned the data protection information duties applicable to such processing. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 May 2021 | persoană fizicăA natural person was fined EUR 200 by ANSPDCP for violating GDPR requirements. The case concerned breaches related to the processing of personal data. | RO | ANSPDCP | GDPR | €200 | ↗ |
| 27 Mar 2023 | persoană fizicăAn individual was fined EUR 450 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with obligations under personal data protection rules. | RO | ANSPDCP | GDPR | €450 | ↗ |
| 19 Jan 2017 | Perrone Rosaria e Azienda Universitaria Ospedaliera Ospedali Riuniti di TriestePerrone Rosaria and Azienda Universitaria Ospedaliera Ospedali Riuniti di Trieste were fined by the Garante 20,000 EUR. The sanction concerned unauthorized access by medical staff to personal health data, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 08 May 2026 | Permanent TSBPermanent TSB was fined EUR 277,500 by Ireland's Data Protection Commission. The case involved fraudsters impersonating customers at a contact centre, resulting in three GDPR breaches and financial loss to three customers. | IE | Data Protection Commission | GDPR | €277,000 | ↗ |
| 17 Jul 2025 | Perla Odontoiatria Veneta S.r.l.The Garante fined Perla Odontoiatria Veneta S.r.l. EUR 7,500 for failing to meet information and transparency obligations in the processing of health data. The authority cited breaches of GDPR Articles 5, 9, and 15. | IT | Garante | GDPR | €7,500 | ↗ |
| 05 Sept 2013 | Perini GianfrancoPerini Gianfranco was fined EUR 2,400 by the Garante. The authority found that individuals were given inadequate data protection information, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 08 Jul 2015 | Perez s.r.l.Perez s.r.l. was fined by the Garante for failing to provide the required privacy notice to users whose personal data were collected through its website. This constituted a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 28 May 2015 | People & Comunication s.r.l.People & Comunication s.r.l. was fined EUR 20,000 by the Garante. The authority found that the company retained telephone traffic data for more than 24 months, in breach of Article 132 of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 09 Oct 2014 | People & Communication s.r.l.People & Communication s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The case concerned the sending of pre-recorded promotional phone calls without obtaining the required consent from recipients. | IT | Garante | GDPR | €20,000 | ↗ |
| 28 Feb 2023 | PELAYO MUTUA DE SEGUROS Y REASEGUROS A PRIMA FIJAPelayo Mutua de Seguros y Reaseguros A Prima Fija was fined 70,000 EUR by the AEPD. The authority found that the company disclosed personal data to a third party without consent, breaching GDPR confidentiality and security obligations. | ES | AEPD | GDPR | €70,000 | ↗ |
| 07 May 2015 | Pelamatti GiacomoPelamatti Giacomo was fined by the Garante EUR 10,000 for activating phone cards in the names of individuals without their knowledge. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Nov 2020 | PEDROSO Y GÓMEZ ASESORÍA DE EMPRESAS, S.L.The company was fined by the AEPD in the amount of 6,000 EUR for sending emails without the recipients' consent. The authority also noted the absence of contact information for exercising data protection rights. | ES | AEPD | GDPR | €6,000 | ↗ |
| 18 Sept 2024 | Paula Stradiņa klīniskā universitātes slimnīcaA fine of EUR 2,000 was imposed. The decision has entered into force. | LV | DVI | GDPR | €2,000 | ↗ |
| 07 May 2015 | Patru Dumitra DanielaPatru Dumitra Daniela was fined by the Garante in the amount of EUR 2,400 for operating a video surveillance system at the bar “New Liberty” without providing adequate simplified information. The authority treated this as a breach of privacy rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 11 Jul 2013 | Patronato ENCALPatronato ENCAL was fined by the Garante 10,000 EUR for failing to implement minimum security measures in the assignment and use of authentication credentials for access to INPS databases. The breach concerned inadequate access control over systems containing sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Jan 2021 | PATIO ANCESTRAL, S.L.PATIO ANCESTRAL, S.L. was fined by the AEPD in the amount of EUR 5,000 for sending a letter containing personal data to the complainant's workplace. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 30 Jul 2015 | Pastore srlPastore srl was fined by the Garante in the amount of 2,400 EUR for publishing an inadequate privacy notice on its website. The notice lacked several required elements under the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Nov 2015 | Pasticceria Gelateria Bar D.D. & D. di Davide Busato & C. s.n.c.The company was fined by the Garante 2,400 EUR for operating a video surveillance system without providing the simplified information notice required under data protection law. The breach concerned the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Sept 2006 | Pasquadibisceglie PaoloPasquadibisceglie Paolo was fined by the Garante 3,000 EUR for failing to provide adequate information to individuals recorded by a video surveillance system in a commercial establishment. The authority found a breach of privacy rules. | IT | Garante | GDPR | €3,000 | ↗ |