BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Jun 2022 | Anonymisé (CNPD decision-12-fr-2022)CNPD imposed a EUR 4,000 fine on Anonymisé for failing to inform data subjects, including employees and third parties, about data processing activities. The authority found breaches of GDPR transparency requirements and data minimization principles. | LU | CNPD | GDPR | €4,000 | ↗ |
| 23 Nov 2017 | Fantozzi Marinella e Banca Nazionale del Lavoro S.p.A.Fantozzi Marinella and Banca Nazionale del Lavoro S.p.A. were fined by the Garante in the amount of 4,000 EUR for breaches of data protection measures under the Italian Privacy Code. The case concerned non-compliance with requirements for the protection of personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 May 2019 | Regione AbruzzoThe Garante fined Regione Abruzzo EUR 4,000 for violations linked to data processing through public service apps. The authority found that adequate data protection and security measures were not ensured. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Jul 2020 | CALLESGARCIA S.C.CALLESGARCIA S.C. was fined by the AEPD €4,000 for using a wedding photo in business advertising without authorization. The authority found a breach of Article 6 GDPR on lawful processing of personal data. | ES | AEPD | GDPR | €4,000 | ↗ |
| 21 Jul 2016 | Planet Book Service di Mario Manna & C. s.a.s.Planet Book Service di Mario Manna & C. s.a.s. was fined by the Garante for failing to respond to an information request. The conduct breached Article 157 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Oct 2015 | Comune di Montelupo FiorentinoThe Municipality of Comune di Montelupo Fiorentino was fined 4,000 EUR by the Garante for unlawfully publishing personal data online. The case concerned the results of participants in a competitive examination disclosed without a proper legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Jun 2015 | SIAS srlSIAS srl was fined EUR 4,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unlawful processing of personal data, including the acquisition of income data without consent. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Nov 2025 | COLLECTIVITE TERRITORIALE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on COLLECTIVITE TERRITORIALE under a simplified procedure. The decision concerns a breach of data protection rules. | FR | CNIL | GDPR | €4,000 | ↗ |
| 23 Oct 2025 | Istituto d'Istruzione Superiore “Statista Aldo Moro” di Fara SabinaThe school published on its website a document containing personal data related to a student's disciplinary proceeding. Garante found that this breached the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Jan 2021 | MAX2PROTECT, S.L.MAX2PROTECT, S.L. was fined by the AEPD 4,000 EUR for sending spam emails without recipient consent. The authority also found unlawful processing of personal data collected from public websites without proper legal basis. | ES | AEPD | GDPR | €4,000 | ↗ |
| 02 Apr 2015 | Ministero dell'Interno – Dipartimento della Pubblica SicurezzaThe Ministry of the Interior – Department of Public Security was fined 4,000 EUR for publishing a ranking list containing personal data without a legal or regulatory basis. This constituted a breach of Article 19 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Oct 2020 | HEREDAD DE UREÑA, S.L.HEREDAD DE UREÑA, S.L. was fined by the AEPD EUR 4,000 for not having a privacy policy on its website, lacking a cookies policy, and sending unsolicited marketing emails without consent. The case indicates failures in basic transparency obligations and consent requirements for electronic communications. | ES | AEPD | GDPR | €4,000 | ↗ |
| 13 Apr 2023 | Unione PilotiUnione Piloti was fined by the Garante in the amount of 4,000 EUR for violations related to the processing of personal data. The authority found that the company failed to ensure lawful, fair, and transparent data handling. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Jun 2014 | Comune di GraffignanoComune di Graffignano was fined EUR 4,000 by the Garante. The authority found that personal data remained published on the institutional website for longer than the legally allowed 15 days. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 May 2008 | impresa individuale Campodonico PierluigiThe sole proprietorship Campodonico Pierluigi was fined EUR 4,000 by the Garante. The sanction concerned sending unsolicited promotional messages by fax, in breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Sept 2013 | Ri.Dat. di Boldetti RenatoRi.Dat. di Boldetti Renato was fined EUR 4,000 by the Garante. The sanction concerned sending unsolicited promotional emails without proper consent, in breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 May 2024 | PINKGREEN BARCELONA, S.L.PINKGREEN BARCELONA, S.L. was fined by the AEPD 4,000 EUR for disclosing personal data of individuals in responses to negative Google reviews. The authority found that the processing breached Articles 6 and 9 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 28 Jul 2016 | Rigamonti s.r.l.Rigamonti s.r.l. was fined 4,000 EUR by the Garante for sending promotional SMS messages without obtaining the recipient’s prior specific consent. The conduct breached data protection rules governing direct marketing. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Nov 2024 | Comune di TorrenovaThe Garante fined Comune di Torrenova 4,000 EUR for breaches of GDPR principles, including lawfulness, fairness, and transparency in data processing. The case indicates failures to meet basic data protection requirements in the public authority's processing activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Nov 2022 | Azienda per la tutela della salute - ATS SardegnaATS Sardegna was fined by the Garante for breaching data protection principles in its handling of personal data relating to an employee's vaccination status. The authority found violations of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |