Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Jun 2022Anonymisé (CNPD decision-12-fr-2022)CNPD imposed a EUR 4,000 fine on Anonymisé for failing to inform data subjects, including employees and third parties, about data processing activities. The authority found breaches of GDPR transparency requirements and data minimization principles.LUCNPDGDPR€4,000
23 Nov 2017Fantozzi Marinella e Banca Nazionale del Lavoro S.p.A.Fantozzi Marinella and Banca Nazionale del Lavoro S.p.A. were fined by the Garante in the amount of 4,000 EUR for breaches of data protection measures under the Italian Privacy Code. The case concerned non-compliance with requirements for the protection of personal data.ITGaranteGDPR€4,000
06 May 2019Regione AbruzzoThe Garante fined Regione Abruzzo EUR 4,000 for violations linked to data processing through public service apps. The authority found that adequate data protection and security measures were not ensured.ITGaranteGDPR€4,000
29 Jul 2020CALLESGARCIA S.C.CALLESGARCIA S.C. was fined by the AEPD €4,000 for using a wedding photo in business advertising without authorization. The authority found a breach of Article 6 GDPR on lawful processing of personal data.ESAEPDGDPR€4,000
21 Jul 2016Planet Book Service di Mario Manna & C. s.a.s.Planet Book Service di Mario Manna & C. s.a.s. was fined by the Garante for failing to respond to an information request. The conduct breached Article 157 of the Italian Data Protection Code.ITGaranteGDPR€4,000
22 Oct 2015Comune di Montelupo FiorentinoThe Municipality of Comune di Montelupo Fiorentino was fined 4,000 EUR by the Garante for unlawfully publishing personal data online. The case concerned the results of participants in a competitive examination disclosed without a proper legal basis.ITGaranteGDPR€4,000
04 Jun 2015SIAS srlSIAS srl was fined EUR 4,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unlawful processing of personal data, including the acquisition of income data without consent.ITGaranteGDPR€4,000
04 Nov 2025COLLECTIVITE TERRITORIALE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on COLLECTIVITE TERRITORIALE under a simplified procedure. The decision concerns a breach of data protection rules.FRCNILGDPR€4,000
23 Oct 2025Istituto d'Istruzione Superiore “Statista Aldo Moro” di Fara SabinaThe school published on its website a document containing personal data related to a student's disciplinary proceeding. Garante found that this breached the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
01 Jan 2021MAX2PROTECT, S.L.MAX2PROTECT, S.L. was fined by the AEPD 4,000 EUR for sending spam emails without recipient consent. The authority also found unlawful processing of personal data collected from public websites without proper legal basis.ESAEPDGDPR€4,000
02 Apr 2015Ministero dell'Interno – Dipartimento della Pubblica SicurezzaThe Ministry of the Interior – Department of Public Security was fined 4,000 EUR for publishing a ranking list containing personal data without a legal or regulatory basis. This constituted a breach of Article 19 of the Italian Privacy Code.ITGaranteGDPR€4,000
21 Oct 2020HEREDAD DE UREÑA, S.L.HEREDAD DE UREÑA, S.L. was fined by the AEPD EUR 4,000 for not having a privacy policy on its website, lacking a cookies policy, and sending unsolicited marketing emails without consent. The case indicates failures in basic transparency obligations and consent requirements for electronic communications.ESAEPDGDPR€4,000
13 Apr 2023Unione PilotiUnione Piloti was fined by the Garante in the amount of 4,000 EUR for violations related to the processing of personal data. The authority found that the company failed to ensure lawful, fair, and transparent data handling.ITGaranteGDPR€4,000
05 Jun 2014Comune di GraffignanoComune di Graffignano was fined EUR 4,000 by the Garante. The authority found that personal data remained published on the institutional website for longer than the legally allowed 15 days.ITGaranteGDPR€4,000
29 May 2008impresa individuale Campodonico PierluigiThe sole proprietorship Campodonico Pierluigi was fined EUR 4,000 by the Garante. The sanction concerned sending unsolicited promotional messages by fax, in breach of data protection rules.ITGaranteGDPR€4,000
05 Sept 2013Ri.Dat. di Boldetti RenatoRi.Dat. di Boldetti Renato was fined EUR 4,000 by the Garante. The sanction concerned sending unsolicited promotional emails without proper consent, in breach of data protection rules.ITGaranteGDPR€4,000
07 May 2024PINKGREEN BARCELONA, S.L.PINKGREEN BARCELONA, S.L. was fined by the AEPD 4,000 EUR for disclosing personal data of individuals in responses to negative Google reviews. The authority found that the processing breached Articles 6 and 9 of the GDPR.ESAEPDGDPR€4,000
28 Jul 2016Rigamonti s.r.l.Rigamonti s.r.l. was fined 4,000 EUR by the Garante for sending promotional SMS messages without obtaining the recipient’s prior specific consent. The conduct breached data protection rules governing direct marketing.ITGaranteGDPR€4,000
27 Nov 2024Comune di TorrenovaThe Garante fined Comune di Torrenova 4,000 EUR for breaches of GDPR principles, including lawfulness, fairness, and transparency in data processing. The case indicates failures to meet basic data protection requirements in the public authority's processing activities.ITGaranteGDPR€4,000
24 Nov 2022Azienda per la tutela della salute - ATS SardegnaATS Sardegna was fined by the Garante for breaching data protection principles in its handling of personal data relating to an employee's vaccination status. The authority found violations of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000