BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Jan 2013 | United Music s.r.l.United Music s.r.l. was fined for failing to notify the cessation of personal data processing activities related to profiling and personality definition through its websites. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Feb 2017 | Consorzio unico di bacino per le Province di Napoli e CasertaConsorzio unico di bacino for the Provinces of Naples and Caserta was fined EUR 20,000 by the Garante. The authority found that the employer processed employees' biometric data, including fingerprints, for attendance tracking without a proper legal basis. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Mar 2024 | Banca di Credito Cooperativo Appulo Lucana soc. cooperativaThe Garante fined Banca di Credito Cooperativo Appulo Lucana 20,000 EUR for failing to provide adequate access to personal data requested by a former employee. The authority found a breach of GDPR Article 15 on the right of access. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Feb 2018 | Car2Go Italia s.r.l.Car2Go Italia s.r.l. was fined EUR 20,000 by the Garante. The authority found a breach of data protection rules for failing to designate employees as data processors in connection with geolocation data processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 02 Mar 2017 | MM Group s.r.l.MM Group s.r.l. was fined EUR 20,000 by the Garante for making unsolicited promotional calls. The calls were placed to a number listed in the public opt-out register, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Jul 2021 | LABORATORIOS GONZÁLEZ, S.L.LABORATORIOS GONZÁLEZ, S.L. was fined by the AEPD 20,000 EUR for sharing an employee’s COVID-19 antibody test result with the employee’s superior without consent. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €20,000 | ↗ |
| 27 Jan 2016 | Planetcall s.r.l.Planetcall s.r.l. was fined €20,000 by the Garante for failing to designate data processors and for using inadequate authentication credentials. The case concerned breaches of the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 10 Nov 2022 | Sportitalia, società sportiva dilettantistica a responsabilità limitataSportitalia was fined €20,000 by the Italian supervisory authority, Garante. The case concerned the use of a biometric system to record employee attendance without a proper legal basis, in breach of GDPR rules on data processing and special categories of data. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Jul 2018 | Active Network S.p.a.Active Network S.p.a. was fined by the Garante 20,000 EUR for retaining telematic traffic data for more than 12 months. The authority found that this practice breached data protection rules in the context of crime detection and repression. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Apr 2015 | Novelli DonataNovelli Donata was fined EUR 20,000 by the Garante. The case concerned the activation of eight phone cards in the names of four individuals without their knowledge, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 08 Nov 2023 | SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA MISE EN OEUVRE DE LOGICIELS DE SURVEILLANCE DES EMPLOYES (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on the company under a simplified procedure. The decision concerns breaches linked to the company's activity in employee monitoring software. | FR | CNIL | GDPR | €20,000 | ↗ |
| 27 Dec 2012 | Euro-Catering O.E.The company installed a CCTV system without notifying the supervisory authority, failed to display required informational signs, and collected excessive data. These actions breached privacy protection rules. | GR | HDPA | GDPR | €20,000 | ↗ |
| 26 Nov 2020 | Concentrix Cvg Italy s.r.l.Concentrix Cvg Italy s.r.l. was fined 20,000 EUR by the Garante for violating GDPR principles. The case concerned a company policy that improperly handled employees' personal data, including a requirement to keep personal items visible on desks. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Dec 2023 | Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 02 Mar 2017 | Trilogy s.r.l.Trilogy s.r.l. and Fastweb s.p.a. were fined for making unsolicited promotional calls to a phone number listed in the public opt-out register. The conduct breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale città di MilanoAzienda sanitaria locale città di Milano was fined by the Garante EUR 20,000 for improperly processing personal data concerning health and sexual life without adequate safeguards. The authority found that the processing breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 28 Apr 2022 | Comune di TarantoComune di Taranto was fined by the Garante in the amount of EUR 20,000 for violations related to the installation of surveillance cameras without proper data protection measures. The authority found a lack of transparency and a failure to provide the required information to data subjects. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Feb 2018 | Casa della legalità e della cultura onlusCasa della legalità e della cultura onlus was fined EUR 20,000 by the Garante. The authority found a data protection breach because the organization failed to respond to requests for information about the publication of personal data on its websites. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Mar 2025 | NOVATES ALIMENTACIÓN MADRID, S.L.NOVATES ALIMENTACIÓN MADRID, S.L. was fined by the AEPD for a personal data protection breach involving the improper handling of video surveillance footage. The footage was shared via WhatsApp without adequate security measures, increasing the risk of unauthorized access. | ES | AEPD | GDPR | €20,000 | ↗ |
| 16 Sept 2021 | Azienda Ospedaliero-Universitaria di ModenaAzienda Ospedaliero-Universitaria di Modena was fined by the Garante for the incorrect handling of sensitive health data, including HIV diagnoses, during the COVID-19 emergency. The case concerned breaches of personal data protection rules and medical confidentiality. | IT | Garante | GDPR | €20,000 | ↗ |