BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Nov 2011 | C.O.E.STRA. S.p.A.C.O.E.STRA. S.p.A. was fined EUR 30,000 by the Italian data protection authority, Garante. The sanction concerned the failure to appoint data processing officers, which breached the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 12 Jun 2015 | Tiresias AETiresias AE was fined for failing to implement measures to control access to personal data files. This failure led to unauthorized access by ICAP. | GR | HDPA | GDPR | €30,000 | ↗ |
| 26 Nov 2024 | Dane anonimowe (X. ul.)UODO imposed an administrative fine of PLN 29,684.04 on Dane anonimowe (X. ul.) for breaching Article 33(1) and Article 34(1) and (2) of the GDPR. The authority also ordered the controller to notify the affected data subject about the personal data breach. | PL | UODO | GDPR | €6,886 | ↗ |
| 13 Nov 2024 | Sligo County CouncilThe Irish DPC imposed a fine of EUR 29,500 on Sligo County Council in inquiry 07/SIU/2018. The case status is listed as not confirmed. | IE | DPC | GDPR | €29,500 | ↗ |
| 01 Apr 2025 | Dane anonimowe (G. M. prowadzącą działalność gospodarczą pod firmą)UODO imposed an administrative fine of PLN 29,043 on the business operator. The authority found that appropriate technical and organizational measures proportionate to the risk of personal data processing were not implemented, and that their effectiveness was not regularly tested, measured, and assessed. | PL | UODO | GDPR | €6,938 | ↗ |
| 04 Oct 2012 | Abbanoa s.p.a.Abbanoa s.p.a. was fined EUR 28,000 by the Garante for failing to provide the required privacy notice in its video surveillance systems. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €28,000 | ↗ |
| 22 May 2018 | C.R.M. S.r.l.C.R.M. S.r.l. was fined EUR 28,000 for using a biometric system to record employee attendance without prior notification to the Garante. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €28,000 | ↗ |
| 30 Dec 2022 | Dane anonimowe (K. S.A. z siedzibą w K. ul.)The President of UODO imposed an administrative fine of PLN 27,418 on the company. The sanction concerned failure to provide access to information necessary for the authority to perform its duties. | PL | UODO | GDPR | €5,858 | ↗ |
| 22 Nov 2012 | Mediabusiness Int. s.r.l.Mediabusiness Int. s.r.l. was fined EUR 26,000 by the Garante for sending unsolicited promotional faxes. The authority found that the company did not obtain valid consent from recipients, which breached data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |
| 08 Mar 2018 | INFOMOBILITY S.P.A.INFOMOBILITY S.P.A. was fined EUR 26,000 by the Garante for providing inadequate information to customers about geolocation activities in its car sharing service. The authority found that the disclosures did not meet transparency requirements for users. | IT | Garante | GDPR | €26,000 | ↗ |
| 06 Dec 2011 | Composad s.r.l.Composad s.r.l. was fined by the Garante €26,000 for processing personal data collected through its website without properly appointing a data processor. The case concerned a breach of data protection rules and related organizational obligations. | IT | Garante | GDPR | €26,000 | ↗ |
| 12 Nov 2015 | Giuseppina GhezziGiuseppina Ghezzi was fined by the Garante 26,000 EUR for registering 100 phone cards to an unaware third party. The required data protection information was not provided and consent was not obtained, constituting a breach of data protection law. | IT | Garante | GDPR | €26,000 | ↗ |
| 18 Mar 2018 | Cristiano PanepintoCristiano Panepinto was fined €26,000 by the Garante for sending promotional emails without obtaining users’ free and specific consent. The conduct breached Article 130 of the Italian Privacy Code. | IT | Garante | GDPR | €26,000 | ↗ |
| 26 Jul 2018 | Associazione MEVALAUTE ONLUSThe association was fined by the Garante for sending unsolicited PEC communications. The authority found that personal data were processed without consent, in breach of data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |
| 26 Jul 2018 | MEVALUATE ITALIA S.R.L.MEVALUATE ITALIA S.R.L. was fined by the Garante 26,000 EUR for sending promotional emails without obtaining specific consent. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |
| 24 Oct 2013 | Claudio ContiClaudio Conti was fined EUR 26,000 by the Garante for activating 100 phone cards in the name of an unaware third party. Required information was not provided and consent was not obtained, constituting a data protection breach. | IT | Garante | GDPR | €26,000 | ↗ |
| 14 Apr 2025 | niegoAn administrative fine of 25,255 PLN was imposed for failure to comply with an order contained in an administrative decision of the President of UODO. The case concerns non-fulfilment of an obligation imposed by the supervisory authority. | PL | UODO | GDPR | €5,893 | ↗ |
| 05 Jul 2021 | Anonymisoitu (TSV 943)The controller unlawfully processed employees' location data, breaching the GDPR principles of data minimization and lawfulness. The case concerned processing that went beyond what was necessary for the stated purpose. | FI | TSV | GDPR | €25,000 | ↗ |
| 25 Nov 2015 | Video s.r.l.Video s.r.l. was fined by the Garante 25,000 EUR for registering 500 phone cards to five unaware individuals without their consent. The case concerns a breach of data protection rules and the absence of a lawful basis for processing personal data. | IT | Garante | GDPR | €25,000 | ↗ |
| 01 Jan 2022 | CAIXABANK S.A.CaixaBank was fined EUR 25,000 by the AEPD for failing to update a customer's address despite repeated requests. The authority found this to be a breach of the GDPR right to rectification. | ES | AEPD | GDPR | €25,000 | ↗ |