Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Jan 2013United Music s.r.l.United Music s.r.l. was fined for failing to notify the cessation of personal data processing activities related to profiling and personality definition through its websites. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€20,000
16 Feb 2017Consorzio unico di bacino per le Province di Napoli e CasertaConsorzio unico di bacino for the Provinces of Naples and Caserta was fined EUR 20,000 by the Garante. The authority found that the employer processed employees' biometric data, including fingerprints, for attendance tracking without a proper legal basis.ITGaranteGDPR€20,000
07 Mar 2024Banca di Credito Cooperativo Appulo Lucana soc. cooperativaThe Garante fined Banca di Credito Cooperativo Appulo Lucana 20,000 EUR for failing to provide adequate access to personal data requested by a former employee. The authority found a breach of GDPR Article 15 on the right of access.ITGaranteGDPR€20,000
01 Feb 2018Car2Go Italia s.r.l.Car2Go Italia s.r.l. was fined EUR 20,000 by the Garante. The authority found a breach of data protection rules for failing to designate employees as data processors in connection with geolocation data processing.ITGaranteGDPR€20,000
02 Mar 2017MM Group s.r.l.MM Group s.r.l. was fined EUR 20,000 by the Garante for making unsolicited promotional calls. The calls were placed to a number listed in the public opt-out register, which breached data protection rules.ITGaranteGDPR€20,000
14 Jul 2021LABORATORIOS GONZÁLEZ, S.L.LABORATORIOS GONZÁLEZ, S.L. was fined by the AEPD 20,000 EUR for sharing an employee’s COVID-19 antibody test result with the employee’s superior without consent. The authority found this to be a breach of data protection rules.ESAEPDGDPR€20,000
27 Jan 2016Planetcall s.r.l.Planetcall s.r.l. was fined €20,000 by the Garante for failing to designate data processors and for using inadequate authentication credentials. The case concerned breaches of the minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€20,000
10 Nov 2022Sportitalia, società sportiva dilettantistica a responsabilità limitataSportitalia was fined €20,000 by the Italian supervisory authority, Garante. The case concerned the use of a biometric system to record employee attendance without a proper legal basis, in breach of GDPR rules on data processing and special categories of data.ITGaranteGDPR€20,000
19 Jul 2018Active Network S.p.a.Active Network S.p.a. was fined by the Garante 20,000 EUR for retaining telematic traffic data for more than 12 months. The authority found that this practice breached data protection rules in the context of crime detection and repression.ITGaranteGDPR€20,000
23 Apr 2015Novelli DonataNovelli Donata was fined EUR 20,000 by the Garante. The case concerned the activation of eight phone cards in the names of four individuals without their knowledge, which breached data protection rules.ITGaranteGDPR€20,000
08 Nov 2023SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA MISE EN OEUVRE DE LOGICIELS DE SURVEILLANCE DES EMPLOYES (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on the company under a simplified procedure. The decision concerns breaches linked to the company's activity in employee monitoring software.FRCNILGDPR€20,000
27 Dec 2012Euro-Catering O.E.The company installed a CCTV system without notifying the supervisory authority, failed to display required informational signs, and collected excessive data. These actions breached privacy protection rules.GRHDPAGDPR€20,000
26 Nov 2020Concentrix Cvg Italy s.r.l.Concentrix Cvg Italy s.r.l. was fined 20,000 EUR by the Garante for violating GDPR principles. The case concerned a company policy that improperly handled employees' personal data, including a requirement to keep personal items visible on desks.ITGaranteGDPR€20,000
07 Dec 2023Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements.ROANSPDCPGDPR€20,000
02 Mar 2017Trilogy s.r.l.Trilogy s.r.l. and Fastweb s.p.a. were fined for making unsolicited promotional calls to a phone number listed in the public opt-out register. The conduct breached data protection rules.ITGaranteGDPR€20,000
14 Sept 2006Azienda sanitaria locale città di MilanoAzienda sanitaria locale città di Milano was fined by the Garante EUR 20,000 for improperly processing personal data concerning health and sexual life without adequate safeguards. The authority found that the processing breached data protection rules.ITGaranteGDPR€20,000
28 Apr 2022Comune di TarantoComune di Taranto was fined by the Garante in the amount of EUR 20,000 for violations related to the installation of surveillance cameras without proper data protection measures. The authority found a lack of transparency and a failure to provide the required information to data subjects.ITGaranteGDPR€20,000
15 Feb 2018Casa della legalità e della cultura onlusCasa della legalità e della cultura onlus was fined EUR 20,000 by the Garante. The authority found a data protection breach because the organization failed to respond to requests for information about the publication of personal data on its websites.ITGaranteGDPR€20,000
27 Mar 2025NOVATES ALIMENTACIÓN MADRID, S.L.NOVATES ALIMENTACIÓN MADRID, S.L. was fined by the AEPD for a personal data protection breach involving the improper handling of video surveillance footage. The footage was shared via WhatsApp without adequate security measures, increasing the risk of unauthorized access.ESAEPDGDPR€20,000
16 Sept 2021Azienda Ospedaliero-Universitaria di ModenaAzienda Ospedaliero-Universitaria di Modena was fined by the Garante for the incorrect handling of sensitive health data, including HIV diagnoses, during the COVID-19 emergency. The case concerned breaches of personal data protection rules and medical confidentiality.ITGaranteGDPR€20,000