BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Oct 2023 | Regione LombardiaThe Garante fined Regione Lombardia EUR 20,000 for improperly publishing the personal data of numerous workers online. The disclosed information also included health-related data, which breached privacy rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 11 Mar 2021 | Azienda Ospedaliera San Giovanni AddolorataAzienda Ospedaliera San Giovanni Addolorata was fined EUR 20,000 by the Garante for inadequate data protection measures concerning patient health data. The authority found breaches of GDPR Articles 5 and 32. | IT | Garante | GDPR | €20,000 | ↗ |
| 04 Mar 2025 | WEBRASOFT SRLIn January 2025, the National Supervisory Authority for Personal Data Processing completed an investigation into WEBRASOFT SRL and found a breach of GDPR provisions. As a result, the operator was fined EUR 20,000. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 02 Mar 2023 | Il Fatto Quotidiano S.p.A.The Garante fined Il Fatto Quotidiano S.p.A. EUR 20,000 for the unlawful dissemination of personal data linked to a judicial case involving the complainants' father. The authority found that the publication breached personal data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 06 Feb 2014 | Regione PugliaRegione Puglia was fined EUR 20,000 by the Italian data protection authority, Garante. The breach involved unlawfully publishing health data of individuals with disabilities on its institutional website. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Sept 2020 | PLAY ORENES, S.L.PLAY ORENES, S.L. was fined by the AEPD €20,000 for improperly positioning surveillance cameras. The cameras captured public areas, which breached data protection rules. | ES | AEPD | GDPR | €20,000 | ↗ |
| 03 May 2023 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined EUR 20,000 by the AEPD for irregularities in the cookie policy on its website. The authority found a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 11 Jan 2024 | dott. BagnatoA doctor was fined by the Garante for breaching privacy rules. The case involved improper handling of medical prescriptions outside the office, which could expose sensitive personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 04 Apr 2007 | Asl Brindisi 1The Garante fined Asl Brindisi 1 for failing to notify the processing of personal data under the Italian Data Protection Code. Article 37 was violated, and the fine amounted to EUR 20,000. | IT | Garante | GDPR | €20,000 | ↗ |
| 30 Mar 2017 | Provincia di CasertaProvincia di Caserta was fined EUR 20,000 by the Garante. The authority found that the province failed to designate data processing officers and did not update the security program document required under the data protection code. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Oct 2022 | Occhiali24.it S.r.l.Occhiali24.it S.r.l. was fined by the Garante 20,000 EUR for sending unsolicited marketing communications without prior consent. The authority also found that the company failed to respond to data subject rights requests, indicating non-compliance with data protection obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Nov 2017 | Superbeton S.p.a.Superbeton S.p.a. was fined 20,000 EUR by the Garante for failing to properly notify the use of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 17 Nov 2010 | Azienda trasporti di MessinaAzienda trasporti di Messina was fined 20,000 EUR by the Garante for processing sensitive personal data without providing the required information notice and without obtaining consent from the data subjects. The case concerns breaches of core transparency and lawful-processing obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 06 Apr 2017 | Regione AbruzzoThe Garante fined Regione Abruzzo EUR 20,000 for unlawfully publishing lists on its website that revealed candidates' health status. The case involved the disclosure of sensitive personal data relating to individuals with disabilities. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Nov 2014 | GROUPALIA COMPRA COLECTIVA, S.L.GROUPALIA COMPRA COLECTIVA, S.L. was fined by the AEPD 20,000 EUR for continuing to send commercial emails after the user requested deletion of personal data and opted out of communications. The case indicates a failure to respect the data subject’s withdrawal of consent and request to stop marketing processing. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 07 Apr 2021 | MZN HELLAS A.E.The company was fined for sending unsolicited marketing SMS messages to a customer who had explicitly objected to such communications. The authority found this to be a breach of GDPR rules on data subject rights and data protection by design. | GR | HDPA | GDPR | €20,000 | ↗ |
| 12 Dec 2024 | Ambiente 2000 S.r.l.Ambiente 2000 S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company required employees to disclose passwords to their work email and files containing personal data, in breach of the GDPR. | IT | Garante | GDPR | €20,000 | ↗ |
| 02 Apr 2015 | Ales Groupe Italia S.p.A.Ales Groupe Italia S.p.A. was fined EUR 20,000 by the Garante for violations related to data processing on its website. Users were asked to provide personal data without proper consent mechanisms. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Nov 2025 | SOCIETE EXPLOITANT UN FONDS DE COMMERCE DE DISTRIBUTION A DOMINANTE ALIMENTAIRE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on the company. The case concerns a breach of rules under the data protection authority’s supervision. | FR | CNIL | GDPR | €20,000 | ↗ |
| 15 Jun 2020 | Bostadsrättsförening HalmstadBRF Gårdsbjörken was fined by IMY for unlawful video and audio surveillance in common areas. The authority found breaches of GDPR principles, including data minimization and transparency. | SE | IMY | GDPR | €1,898 | ↗ |