BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Apr 2013 | Sound station s.a.s.Sound station s.a.s. was fined 30,000 EUR by the Garante for registering numerous phone SIM cards to unaware third parties. The conduct breached data protection requirements. | IT | Garante | GDPR | €30,000 | ↗ |
| 18 Jun 2020 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD in the amount of EUR 30,000 for consulting personal data in credit files without an existing contractual relationship. The authority found that this conduct breached data processing principles. | ES | AEPD | GDPR | €30,000 | ↗ |
| 10 Jan 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 30,000 for a data protection breach. A customer's data was incorrectly linked to another person, which allowed unauthorized access to personal information. | ES | AEPD | GDPR | €30,000 | ↗ |
| 28 Mar 2022 | VUELING AIRLINES, S.A.Vueling Airlines, S.A. was fined EUR 30,000 by the AEPD for breaching data protection rules. The company required customers to accept commercial data sharing in order to purchase tickets on its website, without providing an option to refuse cookies. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 10 Jul 2025 | Centro Medico Italiano S.r.l.Centro Medico Italiano S.r.l. was fined by the Garante 30,000 EUR for failing to provide an adequate response to a data subject’s request for access to health data and information about its processing. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €30,000 | ↗ |
| 04 Oct 2011 | Villa Azzurra Hospital s.r.l.Villa Azzurra Hospital s.r.l. was fined by the Garante in the amount of 30,000 EUR for failing to comply with data processing notification requirements. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 22 Dec 2016 | Planetel s.r.l.Planetel s.r.l. was fined by the Garante in the amount of EUR 30,000 for using inadequate authentication procedures to access telecommunication traffic data. The authority also found that required security measures for data storage were not implemented. | IT | Garante | GDPR | €30,000 | ↗ |
| 29 Apr 2025 | Ordine professionale degli psicologi della LombardiaOn 2025-04-29, the Italian Data Protection Authority fined the Ordine professionale degli psicologi della Lombardia EUR 30,000. The sanction concerned breaches of Articles 5(1)(f) and 32 GDPR following a data breach and the failure to implement adequate security measures. | IT | Garante per la protezione dei dati personali | GDPR | €30,000 | ↗ |
| 16 Feb 2016 | ROCK INTERNET, S.L.ROCK INTERNET, S.L. was fined EUR 30,000 by the AEPD for sending unsolicited commercial emails despite the recipient’s repeated requests to unsubscribe. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 21 Oct 2010 | Giomi s.p.a. - Gestione Istituti Ortopedici nel mezzogiorno d'ItaliaGiomi s.p.a. was fined €30,000 by the Italian data protection authority, Garante. The case concerned data processing activities carried out without the required notification under the Italian data protection code. | IT | Garante | GDPR | €30,000 | ↗ |
| 22 Feb 2018 | Comune di FiumicinoComune di Fiumicino was fined by the Garante for failing to notify a data breach within the required timeframe. The authority found a violation of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 04 Apr 2025 | MEDCENTER SRLMEDCENTER SRL was fined EUR 30,000 by ANSPDCP for breaching GDPR requirements. The company failed to inform affected individuals about a personal data security breach. | RO | ANSPDCP | GDPR | €30,000 | ↗ |
| 27 Apr 2023 | Tiziana Life Science LimitedTiziana Life Science Limited was fined by the Italian Garante in the amount of EUR 30,000. The case concerned failure to provide information and obtain consent for processing personal and genetic data acquired from the bankrupt company Shar.Dna S.p.A. for scientific research purposes. | IT | Garante | GDPR | €30,000 | ↗ |
| 23 Jan 2023 | ENFOKA SISTEMAS GLOBALES, S.L.ENFOKA SISTEMAS GLOBALES, S.L. was fined by the AEPD 30,000 EUR for processing personal data without consent. The company signed an energy supply contract in the complainant's name without their knowledge, which breaches Article 6(1) of the GDPR. | ES | AEPD | GDPR | €30,000 | ↗ |
| 15 Dec 2022 | Eurosanità S.P.A.Eurosanità S.P.A. was fined by the Garante in the amount of 30,000 EUR for violations related to the processing of health data. The authority cited inadequate personal data protection measures. | IT | Garante | GDPR | €30,000 | ↗ |
| 29 Sept 2021 | Comune di FormiaComune di Formia was fined for processing personal data linked to parking subscription services without providing adequate information to data subjects. The authority also found excessive data collection and a failure to clearly define the role of the external data processor. | IT | Garante | GDPR | €30,000 | ↗ |
| 31 Mar 2023 | APOLLONIA TOPCO, S.L.APOLLONIA TOPCO, S.L. was fined by the AEPD EUR 30,000 for improperly requesting copies of clients’ ID documents. The authority also noted a failure to respond to a data protection complaint, in breach of data minimization and purpose limitation principles. | ES | AEPD | GDPR | €30,000 | ↗ |
| 15 Feb 2022 | Organismos Limenos Irakleiou A.E.Organismos Limenos Irakleiou A.E. was fined 30,000 EUR by the HDPA for breaching the data subject’s right of access. The company failed to provide requested video footage and incorrectly claimed that the data had been deleted. | GR | HDPA | GDPR | €30,000 | ↗ |
| 01 Mar 2018 | Comune di San Mango PiemonteComune di San Mango Piemonte was fined for unlawfully using a biometric system based on fingerprint processing to record employee attendance. The authority found that this processing breached data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 12 Jun 2015 | ALPHA BANKALPHA BANK was fined 30,000 EUR by the HDPA. The authority found that the bank failed to notify the location and facilities used for ICAP data processing. | GR | HDPA | GDPR | €30,000 | ↗ |