BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Mar 2014 | Tarulli Francesca e Comune di ConversanoThe Garante imposed a EUR 4,000 fine on Tarulli Francesca and the Comune di Conversano for failing to designate data processors under the Italian Data Protection Code. The conduct breached Articles 30 and 33 and reflected a deficiency in data processing governance. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Mar 2021 | Comune di CastellanzaComune di Castellanza was fined by the Garante EUR 4,000 for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. Personal data remained accessible online for an extended period. | IT | Garante | GDPR | €4,000 | ↗ |
| 19 Mar 2015 | avv. Luciana Candriella CadettoThe lawyer transmitted a legal document containing excessive personal and sensitive data, including data relating to a minor, without proper consent. The authority found a breach of data protection rules and imposed a 4,000 EUR fine. | IT | Garante | GDPR | €4,000 | ↗ |
| 19 Mar 2015 | Comune di MorinoComune di Morino was fined EUR 4,000 by the Garante for unlawfully disclosing the personal data of an individual applying for public housing to private entities without a legal basis. The authority found a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Jan 2015 | Comune di PloagheComune di Ploaghe was fined by the Garante for unlawfully publishing personal data on its website beyond the legally permitted period. The authority found a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Jun 2015 | Azienda di Servizi per la persona "Carlo Pezzani" di VogheraThe company published the personal data of five guests on its website without a legal basis. This breached privacy rules and led to a fine imposed by the Garante. | IT | Garante | GDPR | €4,000 | ↗ |
| 28 Feb 2019 | Casinò di Venezia Meeting & Dining S.r.l.Casinò di Venezia Meeting & Dining S.r.l. was fined EUR 4,000 by the Garante. The authority found that adequate security measures had not been implemented, in breach of Article 33 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Sept 2022 | Liceo Statale "Edoardo Amaldi” di Alzano LombardoLiceo Statale “Edoardo Amaldi” was fined EUR 4,000 by the Garante for violations related to the processing of personal data, including sensitive data. The authority found that the processing lacked a proper legal basis and adequate safeguards. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Nov 2017 | Foschini Mauro e Banca Nazionale del Lavoro S.p.A.Foschini Mauro and Banca Nazionale del Lavoro S.p.A. were fined by the Garante 4,000 EUR for breaches of data protection rules. The case concerned non-compliance with provisions of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 02 Apr 2015 | Comune di FolloComune di Follo was fined for unlawfully communicating personal data of children under three years old to a private company. The authority found this breached Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Dec 2020 | Comune di Santo Stefano BelboComune di Santo Stefano Belbo was fined for unlawfully disclosing personal data, including names and legal information, on its website without a proper legal basis. The case concerned the publication of data that should not have been made publicly available. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Apr 2021 | Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante in the amount of 4,000 EUR for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization because personal data remained accessible online for an extended period. | IT | Garante | GDPR | €4,000 | ↗ |
| 30 Jan 2025 | SOCIETE DE COURTAGE EN ENERGIE (procédure simplifiée)The CNIL used a simplified procedure against SOCIETE DE COURTAGE EN ENERGIE and ordered 4,000 EUR in connection with the liquidation of an astreinte. The case concerns failure to comply with a prior obligation subject to a coercive penalty. | FR | CNIL | GDPR | €4,000 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di TriesteThe Garante fined the Ordine delle Professioni Infermieristiche di Trieste EUR 4,000 for breaches of data protection rules. The case involved improper disclosure of data to third parties and a failure to provide adequate information to data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 May 2019 | SOGIMA S.r.l.SOGIMA S.r.l. was fined by the Garante for allowing unauthorized access to personal data on its website. The breach involved names, email addresses, and bank details without the consent of the data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Oct 2020 | Borgo Fonte Scura s.r.l.Borgo Fonte Scura s.r.l. was fined by the Garante 4,000 EUR for failing to provide proper data protection information to individuals, including employees, about the use of a video surveillance system at its premises. The authority found that the required privacy notice obligations were not met. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 Aug 2024 | EXPANSION CONSULTING 2020, S.L.EXPANSION CONSULTING 2020, S.L. was fined by the AEPD in the amount of €4,000 for failing to provide access to personal data and the information requested by the data protection authority. The case concerned non-compliance with Article 58(1) GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 07 Apr 2016 | Comune di LizzanoComune di Lizzano was fined by the Garante for publishing personal data, including health information about a minor, on its online notice board. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Nov 2015 | 24 Media s.r.l.24 Media s.r.l. was fined EUR 4,000 by the Garante. The authority found that the company required mandatory consent for purposes beyond the original data collection intent, including promotional communications and sharing data with third parties. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Jun 2025 | Vodafone Romania S.A.Vodafone Romania S.A. was fined EUR 4,000 by ANSPDCP for GDPR violations. The investigation was completed in May 2025. | RO | ANSPDCP | GDPR | €4,000 | ↗ |