BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Feb 2020 | BAZAR SUSANABAZAR SUSANA was fined EUR 4,000 by the AEPD for improperly obtaining and disseminating personal images from a video surveillance system. The case concerns a breach of data protection rules and the unlawful processing of CCTV footage. | ES | AEPD | GDPR | €4,000 | ↗ |
| 27 Mar 2025 | Istituto di Istruzione Superiore “P. 96012510796The Garante imposed a fine on an educational institution for breaches of GDPR Articles 5, 6, and 9 in connection with data processing activities. The case concerned deficiencies in the lawful basis and principles of processing, including special-category data. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 Apr 2016 | CityFan s.r.l.CityFan s.r.l. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned the failure to formally designate employees and collaborators as data processors under Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Mar 2023 | Ministero dell’InternoMinistero dell’Interno was fined EUR 4,000 by the Garante for unlawfully communicating personal data, including health information, to the police without proper justification. The case concerned a breach of lawfulness and purpose limitation requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Mar 2014 | Paolo ZaniniPaolo Zanini was fined EUR 4,000 by the Garante for sending unsolicited promotional faxes. The conduct breached data protection rules and the requirement for prior consent for marketing communications. | IT | Garante | GDPR | €4,000 | ↗ |
| 11 Oct 2024 | ORTHOPHONISTE (procédure simplifiée)The CNIL imposed a 4,000 EUR penalty on ORTHOPHONISTE (procédure simplifiée) in connection with the liquidation of an astreinte. The case concerns compliance with a prior obligation under the data protection authority’s supervision. | FR | CNIL | GDPR | €4,000 | ↗ |
| 04 Jul 2013 | Comune di CiampinoThe Municipality of Ciampino was fined EUR 4,000 by the Garante for publishing on its website a list containing personal data of individuals eligible to serve as polling station scrutineers. The publication was made without an appropriate legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Apr 2023 | Università degli studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined EUR 4,000 by the Garante for improperly disclosing a complainant’s personal data to all Italian universities. The disclosure also included data relating to criminal offenses, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 20 Dec 2024 | English Home SRLEnglish Home SRL was fined €4,000 by ANSPDCP for violating Article 21 of the GDPR. The case concerned failure to respect the data subject’s right to object to processing. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 09 Jun 2016 | Comune di LevantoThe Municipality of Levanto was fined EUR 4,000 by the Garante for publishing on its website a list of candidates for regional contributions. The disclosure of personal data lacked sufficient legal basis and breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 03 May 2022 | Megareduceri TV S.R.L.Megareduceri TV S.R.L. was fined by ANSPDCP in the amount of EUR 4,000 for failing to provide requested information to the supervisory authority. The breach concerned obligations under the GDPR. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 23 Jan 2008 | Italmarmo di Rossin EzioItalmarmo di Rossin Ezio was fined EUR 4,000 by the Garante for failing to provide timely access to personal data upon request. The case concerned non-compliance with data protection obligations. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Jun 2024 | MEDECIN GENERALISTE (procédure simplifiée)CNIL imposed an administrative fine of EUR 4,000 on MEDECIN GENERALISTE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €4,000 | ↗ |
| 13 Feb 2025 | Azienda ULSS n. 02573090236The public health company was fined for making a disciplinary proceeding document visible to unauthorized employees. The authority found breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Jun 2025 | Comune di LatinaThe Garante fined Comune di Latina EUR 4,000 for violations linked to the activation process for the “Dedicata a te” card. Requiring a payment to avoid cancellation of the benefit raised compliance concerns. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Feb 2016 | Hans Christoph Josef DietrichHans Christoph Josef Dietrich was fined EUR 4,000 by the Garante. The case concerned the public display of a list of patients who had not paid for medical services, which amounted to unauthorized disclosure of personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jun 2023 | LOCAL VERTICALS, S.L.LOCAL VERTICALS, S.L. was fined EUR 4,000 by the AEPD for failing to provide information about the website owner and for not having a privacy policy. The case concerns breaches of data protection information obligations. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 16 Jul 2025 | Georgescu CălinThe operator Georgescu Călin was fined by ANSPDCP in the amount of EUR 4,000 for violations of GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 02 Jul 2020 | Comune di Greve in ChiantiComune di Greve in Chianti was fined by the Garante for unlawfully disclosing personal data relating to criminal convictions and proceedings. The conduct breached the principles of lawfulness, fairness, and transparency in data processing. | IT | Garante | GDPR | €4,000 | ↗ |
| 02 Jul 2015 | Ordinanza ingiunzione - 2 luglio 2015 [4337649]The condominium administrator did not respond to requests for information related to a data protection complaint. Garante imposed a fine of EUR 4,000 for violating data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |