BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Dec 2021 | Ica s.r.l.Ica s.r.l. was fined by the Garante EUR 30,000 for failing to implement adequate security measures in its online traffic-fine payment service. The weakness allowed unauthorized access to the personal data of fined citizens. | IT | Garante | GDPR | €30,000 | ↗ |
| 20 Jun 2023 | Dante International SADante International SA was fined EUR 30,000 by the Romanian authority ANSPDCP. The sanction concerned violations linked to complaints filed by three individuals from Hungary. | RO | ANSPDCP | GDPR | €30,000 | ↗ |
| 01 Jan 2019 | TWITTER INTERNATIONAL COMPANY (TWITTER SPAIN, S.L.)Twitter International Company (Twitter Spain, S.L.) was fined EUR 30,000 by the AEPD. The authority found inadequate cookie information and the use of cookies without obtaining user consent, in breach of the LSSI. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 28 Oct 2021 | TPER Trasporto Passeggeri Emilia Romagna S.p.A.TPER Trasporto Passeggeri Emilia Romagna S.p.A. was fined by the Garante EUR 30,000 for violations related to the processing of personal data of call center employees. The case involved potential unauthorized monitoring and insufficient data protection measures. | IT | Garante | GDPR | €30,000 | ↗ |
| 14 Nov 2014 | Geniki TrapezaThe bank failed to ensure the accuracy of personal data and did not respond adequately to a data access request. The case concerns breaches of data quality obligations and the handling of data subject rights. | GR | HDPA | GDPR | €30,000 | ↗ |
| 23 Mar 2023 | CAAF CGIL Lombardia s.r.l.CAAF CGIL Lombardia s.r.l. was fined EUR 30,000 by the Garante for unlawful processing of personal data. The company sent promotional emails despite a prior request to delete the data. | IT | Garante | GDPR | €30,000 | ↗ |
| 04 Mar 2021 | CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.CEDICO, a diagnostic imaging center, was fined EUR 30,000 by the AEPD. The authority found that the company unlawfully shared a patient's MRI report with a mutual insurance company, breaching data protection principles. | ES | AEPD | GDPR | €30,000 | ↗ |
| 24 Sept 2019 | VUELING AIRLINES, S.L.VUELING AIRLINES, S.L. was fined by the AEPD 30,000 EUR for failing to comply with cookie consent requirements on its website. The authority found that the company did not provide the required information and did not properly obtain user consent. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 24 Jul 2020 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALThe AEPD fined Iberia Líneas Aéreas de España, S.A. Operadora Unipersonal 30,000 EUR. The authority found that the website did not provide users with an option to reject cookies in line with consent requirements. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 23 Jan 2020 | Azienda Ospedaliero Universitaria Integrata di VeronaAzienda Ospedaliero Universitaria Integrata di Verona was fined by the Garante EUR 30,000 for employees' unauthorized access to patient health records. The authority found a breach of GDPR principles on data protection and security measures. | IT | Garante | GDPR | €30,000 | ↗ |
| 23 Oct 2025 | Zephiromedia S.r.l.Zephiromedia S.r.l. was fined EUR 30,000 by the Garante for sending unsolicited promotional emails. The authority also found that recipients were not given an effective way to unsubscribe or exercise their rights. | IT | Garante | GDPR | €30,000 | ↗ |
| 05 Nov 2025 | RAMÓN GRAU, S.L.RAMÓN GRAU, S.L. was fined by the AEPD for installing a video surveillance system that recorded audio without informing employees. The authority found breaches of GDPR Articles 6(1) and 13 due to the lack of a valid legal basis and required transparency information. | ES | AEPD | GDPR | €30,000 | ↗ |
| 14 Jan 2021 | Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined by the Garante €30,000 for unlawfully processing employees’ biometric data to monitor attendance. The conduct breached GDPR requirements on lawful processing and data minimisation. | IT | Garante | GDPR | €30,000 | ↗ |
| 24 Jun 2021 | Soluzione Tasse S.p.A.Soluzione Tasse S.p.A. was fined by the Garante 30,000 EUR for sending unsolicited emails without proper consent. The case concerned GDPR principles on data processing and transparency. | IT | Garante | GDPR | €30,000 | ↗ |
| 23 May 2025 | OCI CINE, S.L.OCI CINE, S.L. was fined EUR 30,000 by the AEPD after an incident in which a user's personal information was auto-filled with another person's details in its app. The authority found a breach of data accuracy and processing security principles. | ES | AEPD | GDPR | €30,000 | ↗ |
| 12 Oct 2017 | Roma Gestioni s.r.l.Roma Gestioni s.r.l. was fined EUR 30,000 by the Garante. The authority found that the company retained surveillance footage longer than permitted under privacy rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 01 Feb 2018 | Iqbal QuasimIqbal Quasim was fined EUR 30,000 by the Garante. The case concerned registering phone SIM cards to third parties without their consent, which breached data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 24 Apr 2024 | Gestore Dei Servizi Energetici - Gse S.p.A.The Garante fined Gestore Dei Servizi Energetici - Gse S.p.A. 30,000 EUR for failing to respond to a data subject access request. The request concerned the individual's personal performance evaluation records for 2019 and 2020. | IT | Garante | GDPR | €30,000 | ↗ |
| 09 Feb 2011 | Istituto Ninetta Rosano s.r.lIstituto Ninetta Rosano s.r.l was fined EUR 30,000 by the Garante for violating data protection rules. The authority found non-compliance with the requirements of Article 37 of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 25 Nov 2021 | Ordinanza ingiunzione - 25 novembre 2021 [9733002]A healthcare professional was fined by the Garante EUR 30,000 for unlawfully disclosing a patient's personal data, including unpaid medical bills and health information, to third parties. The authority found that the processing lacked a legal basis and breached the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €30,000 | ↗ |