BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Jul 2024 | Dane anonimowe (Panią A. Z. prowadzącą działalność gospodarczą pod firmą B. z siedzibą w W przy ul.)The President of UODO imposed an administrative fine on an individual conducting business activity. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for supervisory tasks. | PL | UODO | GDPR | €5,129 | ↗ |
| 05 Jan 2021 | Dane anonimowe (M. Sp. z o.o. z siedzibą w Z. przy)The President of UODO imposed an administrative fine of PLN 21,397 on M. Sp. z o.o. The company failed to cooperate with the authority and did not provide information needed to assess a complaint concerning personal data processing. | PL | UODO | GDPR | €4,705 | ↗ |
| 21 May 2025 | Menarini Silicon Biosystems SpAThe Garante imposed a 21,000 EUR fine on Menarini Silicon Biosystems SpA for violations related to personal data processing. The case involved inadequate safeguards in the use of algorithms to identify at-risk patients and online reports accessible to other patients. | IT | Garante | GDPR | €21,000 | ↗ |
| 20 Jul 2017 | Centro Laser s.r.l.Centro Laser s.r.l. was fined EUR 20,400 by the Garante for using inadequate password procedures and failing to provide required information on data processing to users. The case concerns breaches of data protection rules. | IT | Garante | GDPR | €20,400 | ↗ |
| 14 Sept 2006 | Banca Sella S.p.a.Banca Sella S.p.a. was fined EUR 20,000 by the Garante for processing biometric data without the notification required under the privacy code. The authority found this to be a breach of Italian privacy rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Oct 2023 | Edizioni Proposta Sud S.r.l.The Garante fined Edizioni Proposta Sud S.r.l. €20,000 for publishing false information about an individual's health status without verifying its accuracy. The authority found this breached GDPR principles on data protection and accuracy. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Apr 2018 | Gianluigi GuarinoGianluigi Guarino, director of the online newspaper Casertace.net, was fined by the Garante. The sanction concerned his failure to respond to an information request about data processing, which breached Article 164 of the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 31 Jan 2026 | SC Tensa Art Design SAThe Romanian data protection authority fined SC Tensa Art Design SA, operator of the Lensa brand, EUR 20,000 under the GDPR. The sanction followed the company’s failure to respond to the authority’s investigative request concerning cookie tracking and behavioral advertising on its website. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €20,000 | ↗ |
| 08 Jul 2024 | COMERCIAL GIRONA DE LLIBRES, S.L.COMERCIAL GIRONA DE LLIBRES, S.L. was fined by the AEPD 20,000 EUR for inadequate security measures. The authority cited, among other issues, the sending of credentials by email, which breached Article 32 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 15 Mar 2018 | Directafin s.p.a.Directafin s.p.a. was fined by the Garante in the amount of EUR 20,000 for using a single consent flag for multiple processing purposes. This included marketing and sharing personal data with third parties without valid consent. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jan 2018 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 20,000 EUR by the AEPD for sending unsolicited marketing emails. The authority found that recipients were not given an effective unsubscribe option, despite a request to be removed from the mailing list. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 15 Nov 2025 | Państwowego Powiatowego Inspektora Sanitarnego w M., ul.UODO imposed a PLN 20,000 administrative fine on the State District Sanitary Inspector in M. The authority found that appropriate technical and organizational measures based on a risk assessment were not implemented, and that the effectiveness of safeguards for data processed on external media was not regularly tested. The case concerned a breach of the integrity and confidentiality principle. | PL | UODO | GDPR | €4,725 | ↗ |
| 07 Apr 2022 | Made in Italy s.r.l.s.Made in Italy s.r.l.s. was fined EUR 20,000 by the Garante for carrying out promotional contacts without obtaining consent. The authority also found that the company failed to respond to data subject rights requests, which is a breach of data protection obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jun 2023 | Cooperjob S.p.A.Cooperjob S.p.A. was fined EUR 20,000 by the Garante for failing to respond within the required timeframe to a job applicant’s request to delete personal data. The authority found a breach of GDPR Article 12 on timely handling of data subject requests. | IT | Garante | GDPR | €20,000 | ↗ |
| 09 Oct 2019 | Vreau Credit S.R.L.Vreau Credit S.R.L. was fined by ANSPDCP in the amount of 20,000 EUR for failing to notify a personal data breach without undue delay. The company had been aware of the incident since December 2018 but did not inform the supervisory authority promptly. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 01 Jan 2016 | EASYVOYAGE SASEASYVOYAGE SAS was fined by the AEPD in the amount of 20,000 EUR for sending unsolicited commercial emails. The conduct continued despite requests for data cancellation, which breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 27 Jan 2025 | Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 26 Jul 2012 | Comune di MilanoThe Garante fined Comune di Milano EUR 20,000 for failing to implement minimum security measures on two computer stations at a primary school. The case concerned non-compliance with data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Dec 2021 | FCA Italy s.p.a.FCA Italy s.p.a. was fined 20,000 EUR by the Garante for breaching GDPR provisions on the right of access and transparency obligations. The case arose from a complaint by an English citizen about the handling of their personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Sept 2017 | Coleman s.p.a.Coleman s.p.a. was fined by the Garante 20,000 EUR for failing to implement minimum security measures for online booking requests. This allowed access to personal data without authentication. | IT | Garante | GDPR | €20,000 | ↗ |