BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Apr 2026 | Istituto Comprensivo Statale MontelibrettiIstituto Comprensivo Statale Montelibretti was fined EUR 4,000 by the Garante for breaches of data protection rules in the processing of personal data on its institutional website. The authority cited failures to comply with lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Apr 2016 | Comune di OttavianoComune di Ottaviano was fined for publishing individuals’ personal data on its website without a legal basis. The authority found this breached Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Jun 2025 | Istituto d’Istruzione Superiore “Carlo e Nello Rosselli”The Garante imposed a EUR 4,000 fine on Istituto d’Istruzione Superiore “Carlo e Nello Rosselli” for failing to appoint a Data Protection Officer and for delaying notification of the DPO’s contact details to the authority. The authority also found that transparency obligations toward data subjects were not met. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Jan 2024 | ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓNThe entity was fined €4,000 by the AEPD for processing personal data without a lawful basis and for failing to inform the data subject. The authority found breaches of Articles 6 and 14 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 10 Mar 2016 | Ministero della giustizia – Dipartimento dell’amministrazione penitenziariaThe Ministry of Justice's Department of Penitentiary Administration was fined EUR 4,000 by the Garante for unlawful processing of personal data. The breach involved disclosing the names and details of prison police personnel who received overtime compensation. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 May 2025 | SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVEE (procédure simplifiée)The CNIL used a simplified procedure against SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVEE and ordered liquidation of a penalty payment of EUR 4,000. The decision concerns failure to comply with a prior obligation imposed by the supervisory authority. | FR | CNIL | GDPR | €4,000 | ↗ |
| 08 Jun 2023 | ALTERNATIVA CORELLANA INDEPENDIENTE (ACI)ALTERNATIVA CORELLANA INDEPENDIENTE (ACI) was fined by the AEPD for failing to respond to information requests. The authority treated this as a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 07 Feb 2024 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe entity was fined by the AEPD 4,000 EUR for failing to provide access to personal data and the information requested by the data protection authority. The case concerns non-compliance with Article 58.1 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 02 Apr 2015 | Provincia di TriesteProvincia di Trieste was fined for publishing personal data on its institutional website without a legal basis. This breached Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Jul 2024 | Comune di VillasimiusComune di Villasimius was fined for failing to respond to a request to remove personal data from its website and for unlawfully publishing personal data. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Mar 2025 | Star Delta Electrical ServicesThe Jersey Data Protection Authority fined Jon Peacock t/a Star-Delta Electrical Services £4,000. The case arose from a client complaint concerning the handling of personal data by the sole trader. The penalty was issued under the Data Protection (Jersey) Law 2018. | JE | JOIC | GDPR | €4,787 | ↗ |
| 04 Dec 2014 | Itala s.p.aItala s.p.a was fined EUR 4,000 by the Garante for processing personal data related to job applications without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Mar 2021 | ALAVA NORTE, S.L.ALAVA NORTE, S.L. was fined by the AEPD in the amount of 4,000 EUR for installing surveillance cameras without sufficient justification. The cameras captured both public and private spaces, which breached data protection principles. | ES | AEPD | GDPR | €4,000 | ↗ |
| 17 Mar 2016 | Università degli studi di FoggiaUniversità degli studi di Foggia was fined 4,000 EUR by the Garante for unlawfully disclosing health-related data to third parties. The authority found that the disclosure lacked an appropriate legal basis and breached privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Jan 2014 | EASY CUT FRANQUICIA, S.L.EASY CUT FRANQUICIA, S.L. was fined by the AEPD 4,100 EUR for sending unsolicited commercial emails. The recipient had previously requested that such communications stop, but the emails continued. This constituted a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €4,100 | ↗ |
| 01 Jan 2016 | WIZINK BANK S.A.WIZINK BANK S.A. was fined by the AEPD €4,100 for sending unsolicited commercial communications by electronic means. The authority found that the legal requirements for such communications were not met. | ES | AEPD | ePrivacy | €4,100 | ↗ |
| 20 Sept 2016 | CEPSA COMERCIAL PETROLEO, S.A.U.CEPSA COMERCIAL PETROLEO, S.A.U. was fined EUR 4,100 by the AEPD for sending commercial emails to a customer after the customer had requested to unsubscribe. The authority found this to be a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €4,100 | ↗ |
| 07 Jul 2016 | ORANGE ESPAGNE, S.A.U.Orange Espagne, S.A.U. was fined EUR 4,100 by the AEPD for sending unsolicited advertising calls and SMS messages to a customer who had opted out of such contact. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €4,100 | ↗ |
| 13 Dec 2022 | Anonymisé (CNPD decision-20-fr-2022)The entity failed to meet GDPR transparency obligations, particularly by not providing information in a clear and accessible manner. CNPD imposed a fine of 4,200 EUR. | LU | CNPD | GDPR | €4,200 | ↗ |
| 12 May 2023 | CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed a fine of EUR 4,500 on CHIRURGIEN DENTISTE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €4,500 | ↗ |