BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Jan 2021 | STOCKHUNTERS, S.L.STOCKHUNTERS, S.L. was fined EUR 4,000 by the AEPD for failing to comply with GDPR Article 13. The authority found that the website privacy policy did not meet the required information standards. | ES | AEPD | GDPR | €4,000 | ↗ |
| 13 Dec 2018 | Ministero dell’Istruzione, dell’Università e della Ricerca – Ufficio Scolastico Regionale per la Lombardia – Ufficio III – Ambito territoriale di BergamoThe Ministry of Education’s regional office in Bergamo was fined for unlawfully publishing personal data related to disciplinary proceedings on its website. The authority found a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Apr 2015 | Comune di CastelplanioComune di Castelplanio was fined by the Garante for publishing personal data, including names, on its online notice board. This conduct breached privacy regulations. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Oct 2019 | Partito Democratico, Coordinamento Metropolitano di FirenzePartito Democratico, Coordinamento Metropolitano di Firenze was fined by the Garante €4,000 for a data protection breach. The incident resulted from a cyber attack on its website that exposed personal data of party members. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Jun 2014 | Ministero della GiustiziaThe Ministry of Justice was fined for unlawfully publishing personal data on its institutional website without a legal basis. The disclosure included names, dates of birth, and tax codes, in breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 08 Oct 2015 | Amministrazione provinciale di PordenoneAmministrazione provinciale di Pordenone was fined 4,000 EUR by the Garante. The authority found that the annual Security Programmatic Document was not updated by the required deadline, breaching data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 May 2015 | Comune di GenovaThe Municipality of Genoa was fined by the Garante for unlawfully keeping personal and judicial data on its institutional website beyond the legally permitted period. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 May 2024 | SOCIETE AYANT POUR ACTIVITE LE COMMERCE DE DETAIL OPTIQUE (procédure simplifiée)The CNIL ordered liquidation of a penalty payment of EUR 4,000 against SOCIETE AYANT POUR ACTIVITE LE COMMERCE DE DETAIL OPTIQUE. The measure relates to non-compliance with a prior obligation in simplified proceedings. | FR | CNIL | GDPR | €4,000 | ↗ |
| 12 May 2023 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union sent an email containing personal data of election officials and representatives without their consent. AEPD found this to be a breach of data protection rules and imposed a 4,000 EUR fine. | ES | AEPD | GDPR | €4,000 | ↗ |
| 28 Jul 2016 | Comune di San Lorenzo NuovoComune di San Lorenzo Nuovo was fined EUR 4,000 by the Garante for unlawfully publishing the list of court jurors online for longer than legally permitted. This resulted in unauthorized disclosure of personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 May 2022 | Concordia Capital IFN S.A.The company was fined for installing audio-video cameras in employee offices. The authority found that this monitoring violated data protection rules. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 20 Mar 2008 | Professioni didattiche moderne-P.D.M. s.r.l.P.D.M. s.r.l. was fined for failing to comply with a request to communicate the conformity of personal data processing. The authority found a breach of Article 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 May 2008 | G. & T. Design Comunication s.r.l.G. & T. Design Comunication s.r.l. was fined €4,000 by the Garante for failing to provide the requested information on the acquisition and processing of an email address. The authority treated this as a breach of data protection requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Apr 2015 | avv. Pasquale GiordanoAvv. Pasquale Giordano was fined EUR 4,000 by the Italian data protection authority, Garante. The sanction concerned the disclosure of a client's personal data to the opposing party's lawyer in a divorce proceeding without the client's consent, in breach of Article 23 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Aug 2022 | B.B.B.A lawyer sent personal data without authorization via WhatsApp for professional promotion. The AEPD found a breach of GDPR Articles 6 and 5(1)(f) and imposed a fine of 4,000 EUR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 21 Jan 2016 | Comune di AdriaComune di Adria was fined EUR 4,000 by the Garante for unlawfully disclosing personal data of third parties. The authority sent photographic results to a complainant that contained data relating to other individuals, breaching data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Mar 2026 | ING Bank NV Amsterdam – Sucursala București S.A.The fine was imposed for failing to implement adequate technical and organizational measures to ensure the confidentiality of personal data. As a result, an unauthorized third party received a bank account statement. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 28 Jan 2021 | TRES-F-NETWORK, S.A.UTRES-F-NETWORK, S.A.U was fined by the AEPD 4,000 EUR for sending commercial SMS messages without the recipient's consent and without an existing commercial relationship. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 12 Feb 2026 | Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di MacerataOrdine dei Medici Chirurghi e degli Odontoiatri della Provincia di Macerata was fined EUR 4,000 by the Garante. The authority found breaches of the principles of lawfulness, fairness, transparency, and data minimization. The case indicates non-compliance with core GDPR processing requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Sept 2024 | B.B.B.B.B.B. was fined by the AEPD €4,000 for failing to properly inform individuals about the presence of surveillance cameras. The authority also found the surveillance system disproportionate because it recorded audio and retained images longer than permitted. | ES | AEPD | GDPR | €4,000 | ↗ |