BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Jan 2020 | Comune di ColledaraComune di Colledara was fined EUR 4,000 by the Garante for publishing personal data in the provisional ranking of a competition on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 May 2021 | AUTOMECANICA JÉREZ, S.L.AUTOMECANICA JÉREZ, S.L. was fined EUR 4,000 by the AEPD. The authority found that the company sent a mass email without masking personal data and sent commercial emails and SMS messages without consent. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 17 Apr 2026 | Comune di CogoletoComune di Cogoleto was fined EUR 4,000 by the Garante for failing to ensure transparency in data processing. The authority also found that no data protection impact assessment had been carried out, breaching the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Oct 2013 | Balangero SerenaBalangero Serena was fined by the Garante in the amount of 4,000 EUR for non-compliance with data protection rules in the use of surveillance cameras at Murphy's Bar. The authority found that privacy notices for individuals under surveillance were inadequate. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Sept 2018 | XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD in the amount of 4,000 EUR for sending unsolicited commercial SMS messages without the recipient’s consent. The conduct breached Article 21.1 of the LSSI, which requires prior consent for marketing communications. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 10 Jul 2025 | Istituto Comprensivo 2 C.D.The Garante fined Istituto Comprensivo 2 C.D. EUR 4,000 for breaches of data protection rules. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency in the processing of personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jan 2015 | Comune di TroinaComune di Troina was fined 4,000 EUR by the Garante for unlawfully disclosing personal data to the complainant’s sister without a legal basis. The authority found a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Mar 2023 | Azienda 1 di SassariThe Garante imposed a fine of 4,000 EUR on Azienda 1 di Sassari for violations related to the processing of personal data, including health data. The authority found that adequate security measures were not in place for this processing. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Dec 2014 | Antonio FrazzanoAntonio Frazzano was fined EUR 4,000 by the Garante for sending promotional faxes without the required information notice and without obtaining recipient consent. The case concerned violations of data protection and direct marketing rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Apr 2019 | Ordinanza ingiunzione - 4 aprile 2019 [9117119]A municipal councillor was fined by the Garante for unlawfully disclosing personal data obtained from a document without legal justification. The authority found a breach of the principles of lawful processing and data protection. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 Nov 2018 | Comune di Castel MaggioreComune di Castel Maggiore was fined by the Garante for publishing personal data on its institutional website without a legal basis. The case concerned a breach of data protection rules and unauthorized disclosure of information. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 Jan 2014 | Ordinanza ingiunzione - 9 gennaio 2014 [4785574]The Garante imposed a fine of EUR 4,000 for sending promotional emails without prior valid consent from recipients. The case concerns a breach of data protection rules and electronic marketing requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Jun 2020 | Azienda Pluriservizi Macerata S.p.A.Azienda Pluriservizi Macerata S.p.A. was fined EUR 4,000 by the Garante for processing colleagues’ personal data in a manner that did not comply with data protection principles. The authority cited breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Mar 2024 | Imperatori Immobiliari s.r.l.The Garante fined Imperatori Immobiliari s.r.l. 4,000 EUR for operating a surveillance system without the required informational signage. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Jan 2019 | Istituto di Istruzione Superiore C.Istituto di Istruzione Superiore C. was fined EUR 4,000 by the Garante for publishing sensitive personal data, including health information, on its website. The conduct breached data protection requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Feb 2015 | Comune di JesiComune di Jesi was fined for unlawfully publishing personal data related to a public competition on its website without a legislative or regulatory basis. The authority found that this breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Jun 2016 | Azienda per i servizi sanitari n. 2 IsontinaAzienda per i servizi sanitari n. 2 Isontina was fined for unlawfully publishing personal data, including negative performance evaluations, of an individual on its institutional website. The conduct breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Jul 2025 | VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 4,000 EUR for failing to notify the data breach to the supervisory authority and the affected data subjects in a timely manner. The case indicates non-compliance with the statutory notification deadlines following a security incident. | GR | HDPA | GDPR | €4,000 | ↗ |
| 01 Jan 2019 | TODO POR EL 431, S.L.TODO POR EL 431, S.L. was fined by the AEPD €4,000 for using surveillance cameras oriented toward public spaces without justified cause. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €4,000 | ↗ |
| 17 Jul 2024 | Provvedimento del 17 luglio 2024 [10070330]The Garante imposed a fine of EUR 4,000 for violations related to the processing of health data. The case highlights the need to comply with data protection principles when handling special category data. | IT | Garante | GDPR | €4,000 | ↗ |