BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Mar 2016 | Comune di Ischia di CastroThe Municipality of Comune di Ischia di Castro was fined 4,000 EUR by the Garante for unlawfully publishing personal data of jury members on its online notice board for longer than the legally permitted period. The case concerned a breach of data protection rules and retention limits. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Jun 2015 | Azienda Ospedaliera Ospedale di Circolo Fondazione MacchiAzienda Ospedaliera Ospedale di Circolo Fondazione Macchi was fined by the Garante 4,000 EUR for processing sensitive personal data without obtaining written consent. This breached the Italian Data Protection Code. The case highlights the need for a valid legal basis before processing special-category data. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Jan 2019 | Istituto Statale di Istruzione Superiore “Guglielmo Marconi”Istituto Statale di Istruzione Superiore “Guglielmo Marconi” was fined by the Garante €4,000 for unlawfully processing personal data. The school published teacher rankings on its website that disclosed health information, breaching privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Nov 2024 | UP ROMÂNIA SRLUP ROMÂNIA SRL was fined EUR 4,000 by ANSPDCP for processing employees’ identification and location data during their free time without a legal basis. The authority found breaches of legality, transparency, and data minimization principles. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 25 Feb 2016 | COF Lanzo Hospital SpaCOF Lanzo Hospital Spa was fined by the Garante for failing to respond to an information request concerning the handling of patient medical records. The authority found a breach of Article 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Jan 2021 | CLUB DEPORTIVO RITMO DE ANDALUCÍAThe club was fined by the AEPD 4,000 EUR for failing to adequately inform users about the processing of their personal data. The authority also found that users were not given the opportunity to provide free and voluntary consent for each specific processing purpose. | ES | AEPD | GDPR | €4,000 | ↗ |
| 26 Jul 2017 | Istituto scolastico "A. Mantegna"Istituto scolastico "A. Mantegna" was fined by the Garante for unlawfully publishing students’ personal data, including sensitive information, on its website without a legal basis. The case concerned a breach of lawfulness and data minimization requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Apr 2014 | Comune di CavedineThe Municipality of Cavedine was fined by the Garante 4,000 EUR for publishing personal data online longer than legally permitted. The case concerned a breach of data protection rules and limits on online retention. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Apr 2025 | Comune di Ponte nelle AlpiThe Garante fined Comune di Ponte nelle Alpi 4,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Codice. The case concerned improper personal data processing activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Feb 2020 | Comune di Urago d'OglioComune di Urago d'Oglio was fined EUR 4,000 by the Garante for improper processing and online publication of special-category personal data, including health data. The authority found insufficient legal basis and inadequate transparency toward the data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Aug 2014 | SERVICIOS DE DEPILACION BLOC, S.L.SERVICIOS DE DEPILACION BLOC, S.L. was fined by the AEPD 4,000 EUR for sending unsolicited commercial SMS messages to a former client. The conduct breached Article 21 of the LSSI on marketing communications without prior consent. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 07 May 2015 | Comune di BagnoregioComune di Bagnoregio was fined by the Garante for unlawfully publishing personal data on its website. The conduct breached the conditions set out in the Italian data protection code. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Jul 2025 | HAMMERHOJ DESIGN, S.L.HAMMERHOJ DESIGN, S.L. was fined EUR 4,000 by the AEPD for publishing images of minors on Facebook without consent. The authority found this conduct to be in breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 29 Feb 2024 | CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on CHIRURGIEN DENTISTE under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision. | FR | CNIL | GDPR | €4,000 | ↗ |
| 09 Oct 2014 | Comune di Lamezia TermeThe Municipality of Lamezia Terme was fined 4,000 EUR by the Garante. The authority found that personal data, including names, tax codes, and IBANs, had been published on its website without a legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Apr 2026 | Istituto “Ancelle della Compagnia della Regina dei Gigli”The Garante fined the school EUR 4,000 for processing students’ personal data without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jul 2021 | Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5)Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5) was fined EUR 4,000 by the Garante for violations related to the processing of personal data, including health data, during the COVID-19 pandemic. The case concerned improper handling of sensitive data in the context of pandemic-related activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 19 Sept 2013 | dott. Luigi Ventronedott. Luigi Ventrone was fined for failing to respond to requests for information concerning the processing of personal data in connection with a complaint by Ms. Ilaria Corsale. The authority found a breach of Article 157 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 08 Apr 2021 | Anonymisé (CNPD decision-11-fr-2021)The company breached the GDPR by failing to respect data retention limits, by not adequately informing employees about data processing, and by applying insufficient security measures. The CNPD decision of 8 April 2021 resulted in a fine of 4,000 EUR. | LU | CNPD | GDPR | €4,000 | ↗ |
| 28 Apr 2026 | SIPHONE 2020, S.L.SIPHONE 2020, S.L. was fined by the AEPD 4,000 EUR for operating a video surveillance system that also recorded audio. Employees were not informed and did not consent, which breached privacy and data protection rules. | ES | AEPD | GDPR | €4,000 | ↗ |