BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Feb 2018 | SIDA GROUP SrlSIDA GROUP Srl was fined by the Garante for failing to promptly update its company name and registered office in its data processing notification. The case concerned non-compliance with data protection obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Oct 2017 | A.N.S.A. s.r.l.A.N.S.A. s.r.l. was fined for processing personal health data without notifying the Garante. The authority found a breach of Articles 37 and 38 of the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Oct 2025 | SUPERMARCHE (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on SUPERMARCHE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 06 Feb 2020 | R.T.I. - Reti Televisive Italiane s.p.a.R.T.I. - Reti Televisive Italiane s.p.a. was fined EUR 20,000 by the Garante for broadcasting a segment on “Le Iene”. The segment made the complainant identifiable through her voice and personal information, breaching data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Apr 2011 | Iniziative immobiliari s.p.a.Iniziative immobiliari s.p.a. was fined 20,000 EUR by the Garante. The authority found that the company collected personal data through a website form without providing adequate information and failed to appoint data processing personnel or implement minimum security measures. | IT | Garante | GDPR | €20,000 | ↗ |
| 28 Apr 2022 | Amiu s.p.a.Amiu s.p.a. was fined EUR 20,000 by the Italian supervisory authority, Garante. The case concerned breaches of lawfulness, fairness, transparency, and purpose limitation in the improper use of surveillance cameras in waste management services. | IT | Garante | GDPR | €20,000 | ↗ |
| 08 Aug 2024 | SOCIETE DE COURTAGE EN ENERGIE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COURTAGE EN ENERGIE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 08 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE DE COMMERCE DE DETAIL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE EXERCANT UNE ACTIVITE DE COMMERCE DE DETAIL. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 12 Apr 2018 | Tonino CeciliaTonino Cecilia, owner of Telefonia Trigoria, was fined by the Italian authority Garante. The penalty concerned activating phone cards for two individuals without their consent, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Dec 2024 | SOCIETE EDITANT DES LOGICIELS OUTILS DE DEVELOPPEMENT ET DE LANGAGES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE EDITANT DES LOGICIELS OUTILS DE DEVELOPPEMENT ET DE LANGAGES and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 15 Feb 2018 | AUTONOLEGGI 24 S.a.s. DI GIAQUINTO GIOVANNIAUTONOLEGGI 24 S.a.s. was fined by the Garante for processing personal data through a geolocation system without the required notification. The case concerned breaches of notification and supervisory obligations linked to that processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Apr 2018 | Insurances Global Services S.r.l.Insurances Global Services S.r.l. was fined by the Garante EUR 20,000 for violations involving access to and handling of client data from credit risk databases without proper authorization. The case concerned the unauthorized use of personal data in the context of credit risk assessment. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Jun 2024 | METRO AEBEThe supervisory authority found that the company did not properly investigate and notify a personal data breach. It also failed to comply with data subject requests for access and erasure. | GR | HDPA | GDPR | €20,000 | ↗ |
| 05 Feb 2026 | Tensa Art Design S.AThe National Supervisory Authority for Personal Data Processing completed an investigation in January 2026 at Tensa Art Design S.A. It found violations of GDPR provisions and imposed a fine of EUR 20,000. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 30 Jul 2024 | NUDE PROJECT, S.L.NUDE PROJECT, S.L. was fined EUR 20,000 by the AEPD for sending unsolicited advertising emails to a customer without obtaining explicit consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 21 Sept 2017 | Tra.n.sider S.p.A.Tra.n.sider S.p.A. was fined EUR 20,000 by the Italian Garante. The case concerned the failure to notify the installation of a geolocation system on company vehicles, breaching data protection notification requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Dec 2009 | Campolongo Hospital s.p.a.Campolongo Hospital s.p.a. was fined by the Garante in the amount of 20,000 EUR. The case concerned the processing of personal data without the required notification under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Mar 2025 | Encore Thermoengineering s.r.l.Encore Thermoengineering s.r.l. was fined EUR 20,000 by the Garante. The case concerned an inadequate response to former employees’ requests about the status and deletion of their email accounts, which infringed data protection rights. | IT | Garante | GDPR | €20,000 | ↗ |
| 10 Jun 2021 | dott. MariniThe Garante imposed a EUR 20,000 fine on dott. Marini for unlawfully collecting information about patients' HIV status. The authority found a breach of the principles of necessity and proportionality in personal data processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 03 Dec 2024 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a customer who had opted out. The authority also found that there was no effective mechanism to revoke consent. | ES | AEPD | ePrivacy | €20,000 | ↗ |