Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2024SUPERVISTA OPTICS SLUSUPERVISTA OPTICS SLU was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a user who had previously opted out. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€20,000
25 Sept 2025S.C. PRIMONET RO S.R.L.The company was fined for a data security breach that enabled unauthorized transactions on affected cards. The incident caused financial losses to the data subjects.ROANSPDCPGDPR€20,000
28 Sept 2023SOCIETE AYANT UNE ACTIVITE DE COMMERCE DE DETAIL OPTIQUE (procédure simplifiée)CNIL imposed a fine of EUR 20,000 on SOCIETE AYANT UNE ACTIVITE DE COMMERCE DE DETAIL OPTIQUE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
10 Apr 2025SOCIETE DE COMMERCE DE DETAIL D'ARTICLES DE SPORT EN MAGASIN SPECIALISE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COMMERCE DE DETAIL D'ARTICLES DE SPORT EN MAGASIN SPECIALISE. The case was handled under a simplified procedure.FRCNILGDPR€20,000
05 Aug 2022Cosmopol Security S.p.A.Cosmopol Security S.p.A. was fined EUR 20,000 by the Garante for failing to respond to a data subject's request to exercise GDPR rights. The case also involved not explaining the origin of the personal data after electronic invoices were received without any contractual relationship.ITGaranteGDPR€20,000
07 Jul 2022Intesa Sanpaolo Vita S.p.a.Intesa Sanpaolo Vita S.p.a. was fined by the Garante EUR 20,000 for unlawfully disclosing personal data related to a life insurance policy to unauthorized third parties. The breach resulted from an operational error and raised concerns about personal data protection and access controls.ITGaranteGDPR€20,000
12 Jan 2017Centro Studi Raffaello s.r.l.Centro Studi Raffaello s.r.l. was fined by the Garante for inadequate data protection measures and improper collection of consent for marketing purposes. The case indicates deficiencies in the company's personal data processing controls and compliance framework.ITGaranteGDPR€20,000
29 Mar 2018ARC Informazioni s.r.l.ARC Informazioni s.r.l. was fined 20,000 EUR by the Garante. The authority found that the company failed to notify data processing activities as required by the Italian Privacy Code.ITGaranteGDPR€20,000
28 May 2015Tex97 s.r.l.Tex97 s.r.l. was fined EUR 20,000 by the Italian data protection authority, Garante. The company retained customers' telephone traffic data for more than 24 months, in breach of Article 132 of the Italian Data Protection Code.ITGaranteGDPR€20,000
19 Dec 2024GROUPEMENT REGIONAL D'APPUI AU DEVELOPPEMENT DE LA E-SANTE (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on GROUPEMENT REGIONAL D'APPUI AU DEVELOPPEMENT DE LA E-SANTE under a simplified procedure. The decision concerns a regulatory breach addressed in the administrative proceeding.FRCNILGDPR€20,000
01 Feb 2018Car City Club s.r.l.Car City Club s.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to designate data processors among its employees, which breached data protection rules.ITGaranteGDPR€20,000
29 Jan 2026ÉTABLISSEMENT PUBLIC EXERÇANT UNE ACTIVITÉ DE TRANSPORT URBAIN (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ÉTABLISSEMENT PUBLIC EXERÇANT UNE ACTIVITÉ DE TRANSPORT URBAIN. The case was handled under a simplified procedure.FRCNILGDPR€20,000
23 Oct 2025Multimedia News Società CooperativaThe Garante fined Multimedia News Società Cooperativa EUR 20,000 for failing to provide a privacy notice and contact details for data requests on its website. The authority found this breached transparency obligations and data subject rights.ITGaranteGDPR€20,000
13 Apr 2023Ordine degli Avvocati di AnconaThe Garante fined the Ordine degli Avvocati di Ancona 20,000 EUR for violations related to data processing transparency and security. The authority found incorrect privacy notices and non-compliance with GDPR principles.ITGaranteGDPR€20,000
24 Jun 2011Azienda ospedaliera San Giuseppe Moscati (AOSGM)Azienda ospedaliera San Giuseppe Moscati was fined EUR 20,000 by the Garante. The authority found that the security program document was not updated and that minimum security measures were not adopted for the processing of health data.ITGaranteGDPR€20,000
25 Mar 2021GEDI News Network S.p.a.GEDI News Network S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The case concerned failure to comply with a request to delete personal data from an article about a 1998 legal case, which remained prejudicial because the outcome was not updated.ITGaranteGDPR€20,000
06 Jun 2018MP Tuscolana s.r.l.MP Tuscolana s.r.l. was fined EUR 20,000 by the Garante for the unauthorized activation of two phone cards without the consent of the individuals concerned. The case indicates a failure to obtain valid consent before activating the services.ITGaranteGDPR€20,000
05 Jul 2017Compagnia Generale Trattori S.p.A.Compagnia Generale Trattori S.p.A. was fined by the Garante EUR 20,000 for using a GPS/GPRS system to monitor employee activities without proper notification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
16 Nov 2022Raiffeisen Bank SARaiffeisen Bank SA was fined by ANSPDCP EUR 20,000 for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and security requirements. The decision highlights the need for effective technical and organizational controls.ROANSPDCPGDPR€20,000
25 Jan 2018ATAM S.p.A. – Azienda territoriale Arezzo Mobilità S.p.A.ATAM S.p.A. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned failures to meet notification obligations related to a geolocation system used to track vehicles.ITGaranteGDPR€20,000