BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Oct 2021 | VENTANAS MAKE YOURSELF, S.L.The company was fined by the AEPD EUR 4,000 for not having a privacy policy and a cookie policy on its website. The breach concerned GDPR and LSSI requirements on information provided to users. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 24 Nov 2022 | Società Lombarda Sport s.r.l.Società Lombarda Sport s.r.l. was fined by the Garante 4,000 EUR for processing personal data without an adequate legal basis. The authority also found failures to ensure data integrity and confidentiality in connection with the issuance of medical certificates for non-competitive sports activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Feb 2026 | Comune di Mazara del ValloComune di Mazara del Vallo was fined EUR 4,000 by the Garante for breaches of data protection principles. The authority found that the municipality failed to provide adequate information to data subjects and did not carry out a data protection impact assessment for its video surveillance system. | IT | Garante | GDPR | €4,000 | ↗ |
| 20 Mar 2008 | Marco TardelliMarco Tardelli was fined by the Garante for failing to provide a complete response to a personal data access request. The authority found a breach of the Italian data protection code. | IT | Garante | GDPR | €4,000 | ↗ |
| 14 May 2020 | Anonymizováno (ÚOOÚ spr-563809-118)The entity was fined for operating a camera system without meeting the information obligations required under Czech data protection law. The case concerns a breach of transparency duties toward individuals subject to surveillance. | CZ | UOOU | GDPR | €145 | ↗ |
| 13 Sept 2012 | Ruzzo Reti S.p.a.Ruzzo Reti S.p.a. was fined EUR 4,000 by the Italian Garante. The authority found that the company failed to designate data processors, meaning it did not adopt the minimum security measures required by the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Nov 2015 | Comune di RecaleComune di Recale was fined EUR 4,000 by the Garante for publishing an individual's personal data on its institutional website without proper legal basis. The case concerned violations of privacy and personal data processing rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Jan 2022 | Medicina & Lavoro s.r.l.Medicina & Lavoro s.r.l. was fined by the Garante 4,000 EUR for failing to provide an adequate response to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Nov 2016 | Comune di Sant'AgnelloComune di Sant'Agnello was fined EUR 4,000 by the Garante. The authority found that personal data of children had been published on the municipality's website, in breach of privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Jul 2016 | M2G Solution s.r.l.M2G Solution s.r.l. was fined 4,000 EUR by the Garante for making promotional calls to a number listed in the public opposition register. The authority found this to be a breach of the right to object to direct marketing. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Jan 2019 | Istituto Comprensivo Paolo StefanelliIstituto Comprensivo Paolo Stefanelli was fined by the Garante 4,000 EUR for publishing personal data on its website that revealed individuals' health status. The case involved a breach of privacy rules and the protection of sensitive data. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Apr 2022 | Anonymisé (CNPD decision-10-fr-2022)The public transport organization breached GDPR requirements on storage limitation, data minimization, and providing adequate information to data subjects. CNPD imposed a fine of EUR 4,000. | LU | CNPD | GDPR | €4,000 | ↗ |
| 10 Mar 2021 | B.B.B.The entity was fined by the AEPD in the amount of 4,000 EUR for installing a video surveillance system aimed at public areas. The authority also found that images were captured without justified cause and retained longer than permitted by law. | ES | AEPD | GDPR | €4,000 | ↗ |
| 12 May 2016 | Leonardo SestaLeonardo Sesta, a lawyer, was fined by the Italian data protection authority, Garante. The violation concerned transmitting personal data by email instead of registered mail, contrary to data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jan 2015 | Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined EUR 4,000 by the Garante. The authority found that personal data had been unlawfully published on its website for longer than the legally permitted fifteen days. | IT | Garante | GDPR | €4,000 | ↗ |
| 03 Jun 2020 | MALAGATROM, S.L.U.MALAGATROM, S.L.U. was fined by the AEPD 4,000 EUR for processing and disclosing personal data on Amazon without consent. The authority found this conduct to be contrary to Article 6 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 13 Jul 2016 | Italian Lab s.r.l.Italian Lab s.r.l. was fined EUR 4,000 by the Garante. The case concerned the processing of personal data for a mailing list and newsletter without obtaining user consent. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Nov 2023 | LOS NIÑOS DE MONTESSORI, S.L.The company was fined by the AEPD for failing to publish a privacy policy on its website and for installing non-exempt cookies without informing users or obtaining consent. The case reflects deficiencies in basic transparency and consent requirements under data protection rules. | ES | AEPD | GDPR | €4,000 | ↗ |
| 28 Mar 2019 | Vestas s.r.l.Vestas s.r.l. was fined by the Garante 4,000 EUR for obtaining a single mandatory consent covering different processing purposes. This approach breached data protection rules because consent was not separated by purpose. | IT | Garante | GDPR | €4,000 | ↗ |
| 03 Sept 2014 | Anonymised (HDPA 119/2014)A fine was imposed for the unlawful collection and processing of personal data, including email addresses, and for sending unsolicited marketing emails without subscriber consent. The case concerns breaches of lawful processing requirements and the need for prior consent for marketing communications. | GR | HDPA | ePrivacy | €4,000 | ↗ |