BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 Jan 2019 | Azienda Sanitaria Locale di AlessandriaAzienda Sanitaria Locale di Alessandria was fined by the Garante 16,000 EUR for processing personal data through the health dossier without full compliance with data protection rules. The case concerned improper handling of sensitive data in a medical system. | IT | Garante | GDPR | €16,000 | ↗ |
| 31 Jan 2019 | Istituto Statale di Istruzione Superiore “Guglielmo Marconi”Istituto Statale di Istruzione Superiore “Guglielmo Marconi” was fined by the Garante €4,000 for unlawfully processing personal data. The school published teacher rankings on its website that disclosed health information, breaching privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Jan 2019 | CT BARCT BAR was fined by the Garante for unlawful processing of personal data through its video surveillance system. The recordings were retained for 15 days without proper compliance with applicable rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 01 Feb 2019 | CAIXABANK, S.A.CAIXABANK was fined by the AEPD for introducing new data protection conditions that required consent for sharing data within its group. The authority found the measure disproportionate and lacking a proper legal basis. | ES | AEPD | GDPR | €6,500,000 | ↗ |
| 02 Feb 2019 | Ordinanza ingiunzione - 2 febbraio 2019 [9100784]The Garante imposed an administrative fine for violating data protection rules. The case concerned retaining surveillance footage for longer than the permitted 7 days. | IT | Garante | GDPR | €11,940 | ↗ |
| 02 Feb 2019 | XX S.r.l.The company was fined EUR 4,000 by the Garante. The authority found that it processed personal data for promotional purposes without obtaining valid consent from the data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 14 Feb 2019 | Ordinanza ingiunzione - 14 febbraio 2019 [9106367]A doctor used the email addresses of former patients to send electoral propaganda without first informing them or obtaining consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 20 Feb 2019 | Érintetti joggyakorlásra vonatkozó kérelem elbírálásaThe supervisory authority fined the controller for failing to facilitate the exercise of data subject rights and for not meeting transparency requirements when handling a deletion request. The case concerned an improperly handled request for erasure and insufficient information provided to the requester. | HU | NAIH | GDPR | €1,575 | ↗ |
| 21 Feb 2019 | Anonymizováno (ÚOOÚ UOOU-05185/14-53)The entity was fined by UOOU for publishing information about wiretaps and telecommunications records without consent. The authority treated this as a breach of privacy and personal data protection rules. | CZ | UOOU | GDPR | €7,018 | ↗ |
| 22 Feb 2019 | VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD €2,500 for sending commercial communications by phone and SMS without the complainant’s consent. This breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 26 Feb 2019 | телекомуникационен операторThe telecommunications operator was fined BGN 53,000 by the CPDP for processing personal data without consent. The case involved changing a subscription plan to a prepaid service without the data subject's knowledge or agreement. | BG | CPDP | GDPR | €27,099 | ↗ |
| 28 Feb 2019 | Comune di MisterbiancoComune di Misterbianco was fined by the Garante 4,000 EUR for unlawful processing of personal data. The breach involved publishing personal information on its website beyond the legally permitted period. | IT | Garante | GDPR | €4,000 | ↗ |
| 28 Feb 2019 | Kecskemét Megyei Jogú Város Polgármesteri HivatalaKecskemét City Hall transferred personal data from a public interest report to a third party without a legal basis, resulting in unauthorized access. NAIH imposed a fine of 1,000,000 HUF. | HU | NAIH | GDPR | €3,160 | ↗ |
| 28 Feb 2019 | Casinò di Venezia Meeting & Dining S.r.l.Casinò di Venezia Meeting & Dining S.r.l. was fined EUR 4,000 by the Garante. The authority found that adequate security measures had not been implemented, in breach of Article 33 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 Mar 2019 | Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined for unlawfully processing judicial data by communicating information about an ongoing criminal proceeding without a legal basis. The case concerned a breach of the rules governing the lawful processing of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Mar 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 45,000 EUR by the AEPD for sending continuous SMS messages to a complainant despite a prior request to cancel personal data. The authority found this conduct to be a breach of data protection principles. | ES | AEPD | GDPR | €45,000 | ↗ |
| 13 Mar 2019 | Anonymizováno (ÚOOÚ UOOU-12081/17-63)The entity was fined CZK 23,000 by the UOOU for repeatedly sending unsolicited commercial communications without recipients’ consent. The authority found this conduct breached Section 7 of the Czech Act on Certain Information Society Services. | CZ | UOOU | ePrivacy | €896 | ↗ |
| 14 Mar 2019 | Comune di Porto Sant’ElpidioThe Garante fined Comune di Porto Sant’Elpidio EUR 10,000 for publishing documents on its website that contained personal data revealing the health status of individuals with disabilities. The authority found a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Mar 2019 | Dane anonimowe (X. Sp. z o.o., za naruszenie stwierdzone w niniejszej decyzji,)UODO found that X. Sp. z o.o. failed to comply with its information obligation. The decision ordered remediation of the breach and imposed a fine of PLN 943,470. | PL | UODO | GDPR | €219,000 | ↗ |
| 19 Mar 2019 | Enel Energia s.p.a.Enel Energia s.p.a. was fined by the Garante EUR 80,000 for failing to implement adequate security measures. This allowed unauthorized access and massive data downloads by a third-party company using credentials of former employees. | IT | Garante | GDPR | €80,000 | ↗ |