Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Feb 2018SIDA GROUP SrlSIDA GROUP Srl was fined by the Garante for failing to promptly update its company name and registered office in its data processing notification. The case concerned non-compliance with data protection obligations.ITGaranteGDPR€20,000
19 Oct 2017A.N.S.A. s.r.l.A.N.S.A. s.r.l. was fined for processing personal health data without notifying the Garante. The authority found a breach of Articles 37 and 38 of the Italian Privacy Code.ITGaranteGDPR€20,000
16 Oct 2025SUPERMARCHE (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on SUPERMARCHE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
06 Feb 2020R.T.I. - Reti Televisive Italiane s.p.a.R.T.I. - Reti Televisive Italiane s.p.a. was fined EUR 20,000 by the Garante for broadcasting a segment on “Le Iene”. The segment made the complainant identifiable through her voice and personal information, breaching data protection rules.ITGaranteGDPR€20,000
27 Apr 2011Iniziative immobiliari s.p.a.Iniziative immobiliari s.p.a. was fined 20,000 EUR by the Garante. The authority found that the company collected personal data through a website form without providing adequate information and failed to appoint data processing personnel or implement minimum security measures.ITGaranteGDPR€20,000
28 Apr 2022Amiu s.p.a.Amiu s.p.a. was fined EUR 20,000 by the Italian supervisory authority, Garante. The case concerned breaches of lawfulness, fairness, transparency, and purpose limitation in the improper use of surveillance cameras in waste management services.ITGaranteGDPR€20,000
08 Aug 2024SOCIETE DE COURTAGE EN ENERGIE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COURTAGE EN ENERGIE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
08 Dec 2025SOCIETE EXERCANT UNE ACTIVITE DE COMMERCE DE DETAIL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE EXERCANT UNE ACTIVITE DE COMMERCE DE DETAIL. The case was handled under a simplified procedure.FRCNILGDPR€20,000
12 Apr 2018Tonino CeciliaTonino Cecilia, owner of Telefonia Trigoria, was fined by the Italian authority Garante. The penalty concerned activating phone cards for two individuals without their consent, which breached data protection rules.ITGaranteGDPR€20,000
12 Dec 2024SOCIETE EDITANT DES LOGICIELS OUTILS DE DEVELOPPEMENT ET DE LANGAGES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE EDITANT DES LOGICIELS OUTILS DE DEVELOPPEMENT ET DE LANGAGES and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
15 Feb 2018AUTONOLEGGI 24 S.a.s. DI GIAQUINTO GIOVANNIAUTONOLEGGI 24 S.a.s. was fined by the Garante for processing personal data through a geolocation system without the required notification. The case concerned breaches of notification and supervisory obligations linked to that processing.ITGaranteGDPR€20,000
12 Apr 2018Insurances Global Services S.r.l.Insurances Global Services S.r.l. was fined by the Garante EUR 20,000 for violations involving access to and handling of client data from credit risk databases without proper authorization. The case concerned the unauthorized use of personal data in the context of credit risk assessment.ITGaranteGDPR€20,000
27 Jun 2024METRO AEBEThe supervisory authority found that the company did not properly investigate and notify a personal data breach. It also failed to comply with data subject requests for access and erasure.GRHDPAGDPR€20,000
05 Feb 2026Tensa Art Design S.AThe National Supervisory Authority for Personal Data Processing completed an investigation in January 2026 at Tensa Art Design S.A. It found violations of GDPR provisions and imposed a fine of EUR 20,000.ROANSPDCPGDPR€20,000
30 Jul 2024NUDE PROJECT, S.L.NUDE PROJECT, S.L. was fined EUR 20,000 by the AEPD for sending unsolicited advertising emails to a customer without obtaining explicit consent. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€20,000
21 Sept 2017Tra.n.sider S.p.A.Tra.n.sider S.p.A. was fined EUR 20,000 by the Italian Garante. The case concerned the failure to notify the installation of a geolocation system on company vehicles, breaching data protection notification requirements.ITGaranteGDPR€20,000
16 Dec 2009Campolongo Hospital s.p.a.Campolongo Hospital s.p.a. was fined by the Garante in the amount of 20,000 EUR. The case concerned the processing of personal data without the required notification under the Italian Data Protection Code.ITGaranteGDPR€20,000
13 Mar 2025Encore Thermoengineering s.r.l.Encore Thermoengineering s.r.l. was fined EUR 20,000 by the Garante. The case concerned an inadequate response to former employees’ requests about the status and deletion of their email accounts, which infringed data protection rights.ITGaranteGDPR€20,000
10 Jun 2021dott. MariniThe Garante imposed a EUR 20,000 fine on dott. Marini for unlawfully collecting information about patients' HIV status. The authority found a breach of the principles of necessity and proportionality in personal data processing.ITGaranteGDPR€20,000
03 Dec 2024VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a customer who had opted out. The authority also found that there was no effective mechanism to revoke consent.ESAEPDePrivacy€20,000