BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2024 | SUPERVISTA OPTICS SLUSUPERVISTA OPTICS SLU was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a user who had previously opted out. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 25 Sept 2025 | S.C. PRIMONET RO S.R.L.The company was fined for a data security breach that enabled unauthorized transactions on affected cards. The incident caused financial losses to the data subjects. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 28 Sept 2023 | SOCIETE AYANT UNE ACTIVITE DE COMMERCE DE DETAIL OPTIQUE (procédure simplifiée)CNIL imposed a fine of EUR 20,000 on SOCIETE AYANT UNE ACTIVITE DE COMMERCE DE DETAIL OPTIQUE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 10 Apr 2025 | SOCIETE DE COMMERCE DE DETAIL D'ARTICLES DE SPORT EN MAGASIN SPECIALISE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COMMERCE DE DETAIL D'ARTICLES DE SPORT EN MAGASIN SPECIALISE. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 05 Aug 2022 | Cosmopol Security S.p.A.Cosmopol Security S.p.A. was fined EUR 20,000 by the Garante for failing to respond to a data subject's request to exercise GDPR rights. The case also involved not explaining the origin of the personal data after electronic invoices were received without any contractual relationship. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Jul 2022 | Intesa Sanpaolo Vita S.p.a.Intesa Sanpaolo Vita S.p.a. was fined by the Garante EUR 20,000 for unlawfully disclosing personal data related to a life insurance policy to unauthorized third parties. The breach resulted from an operational error and raised concerns about personal data protection and access controls. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Jan 2017 | Centro Studi Raffaello s.r.l.Centro Studi Raffaello s.r.l. was fined by the Garante for inadequate data protection measures and improper collection of consent for marketing purposes. The case indicates deficiencies in the company's personal data processing controls and compliance framework. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Mar 2018 | ARC Informazioni s.r.l.ARC Informazioni s.r.l. was fined 20,000 EUR by the Garante. The authority found that the company failed to notify data processing activities as required by the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 28 May 2015 | Tex97 s.r.l.Tex97 s.r.l. was fined EUR 20,000 by the Italian data protection authority, Garante. The company retained customers' telephone traffic data for more than 24 months, in breach of Article 132 of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Dec 2024 | GROUPEMENT REGIONAL D'APPUI AU DEVELOPPEMENT DE LA E-SANTE (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on GROUPEMENT REGIONAL D'APPUI AU DEVELOPPEMENT DE LA E-SANTE under a simplified procedure. The decision concerns a regulatory breach addressed in the administrative proceeding. | FR | CNIL | GDPR | €20,000 | ↗ |
| 01 Feb 2018 | Car City Club s.r.l.Car City Club s.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to designate data processors among its employees, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Jan 2026 | ÉTABLISSEMENT PUBLIC EXERÇANT UNE ACTIVITÉ DE TRANSPORT URBAIN (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ÉTABLISSEMENT PUBLIC EXERÇANT UNE ACTIVITÉ DE TRANSPORT URBAIN. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 23 Oct 2025 | Multimedia News Società CooperativaThe Garante fined Multimedia News Società Cooperativa EUR 20,000 for failing to provide a privacy notice and contact details for data requests on its website. The authority found this breached transparency obligations and data subject rights. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Apr 2023 | Ordine degli Avvocati di AnconaThe Garante fined the Ordine degli Avvocati di Ancona 20,000 EUR for violations related to data processing transparency and security. The authority found incorrect privacy notices and non-compliance with GDPR principles. | IT | Garante | GDPR | €20,000 | ↗ |
| 24 Jun 2011 | Azienda ospedaliera San Giuseppe Moscati (AOSGM)Azienda ospedaliera San Giuseppe Moscati was fined EUR 20,000 by the Garante. The authority found that the security program document was not updated and that minimum security measures were not adopted for the processing of health data. | IT | Garante | GDPR | €20,000 | ↗ |
| 25 Mar 2021 | GEDI News Network S.p.a.GEDI News Network S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The case concerned failure to comply with a request to delete personal data from an article about a 1998 legal case, which remained prejudicial because the outcome was not updated. | IT | Garante | GDPR | €20,000 | ↗ |
| 06 Jun 2018 | MP Tuscolana s.r.l.MP Tuscolana s.r.l. was fined EUR 20,000 by the Garante for the unauthorized activation of two phone cards without the consent of the individuals concerned. The case indicates a failure to obtain valid consent before activating the services. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Jul 2017 | Compagnia Generale Trattori S.p.A.Compagnia Generale Trattori S.p.A. was fined by the Garante EUR 20,000 for using a GPS/GPRS system to monitor employee activities without proper notification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Nov 2022 | Raiffeisen Bank SARaiffeisen Bank SA was fined by ANSPDCP EUR 20,000 for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and security requirements. The decision highlights the need for effective technical and organizational controls. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 25 Jan 2018 | ATAM S.p.A. – Azienda territoriale Arezzo Mobilità S.p.A.ATAM S.p.A. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned failures to meet notification obligations related to a geolocation system used to track vehicles. | IT | Garante | GDPR | €20,000 | ↗ |