BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Feb 2013 | Terme Rosapepe s.a.s.Terme Rosapepe s.a.s. was fined EUR 4,800 by the Garante. The authority found that the company collected personal data through a website registration form without providing the required privacy notice, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 12 Jun 2014 | La Pergola s.r.l.La Pergola s.r.l. was fined EUR 4,800 by the Garante for collecting personal data through its website without the required information notice. This breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 09 Jun 2016 | Montanaro Auto s.r.l.Montanaro Auto s.r.l. was fined by the Garante in the amount of 4,800 EUR for failing to provide data subjects with information about data processing. The breach concerned a video surveillance system and a web form, in violation of the Italian Data Protection Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 17 Mar 2016 | Apcoa Parking Italia spaApcoa Parking Italia spa was fined EUR 4,800 by the Garante for improper use of surveillance images to enforce parking rules and recover debts. The authority also found inadequate data protection information on the company’s website and in its communications with data subjects. | IT | Garante | GDPR | €4,800 | ↗ |
| 08 Dec 2025 | Anonimizirano (IP-RS 0609-112/2025/7)A legal entity was fined 4,800 EUR by IP-RS for failing to provide concise, transparent, and understandable information to individuals when collecting personal data through online forms. The authority found this to be a breach of Article 13 GDPR. | SI | IP-RS | GDPR | €4,800 | ↗ |
| 06 Mar 2014 | Danilo DiscolpaDanilo Discolpa was fined by the Garante 4,800 EUR for processing personal data through video surveillance and recording customer identification documents without providing the required notice. The authority found this to be a breach of the Italian Privacy Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 25 Jul 2013 | Axis Strategic Vision srlAxis Strategic Vision srl was fined by the Garante in the amount of 4,800 EUR for providing inadequate privacy notices on its websites. The authority found that the notices did not meet data protection requirements. | IT | Garante | GDPR | €4,800 | ↗ |
| 30 Jan 2014 | Orovicenza di Picaro CristinaOrovicenza di Picaro Cristina was fined EUR 4,800 by the Garante. The authority found that the website’s contact and registration forms did not provide the required data protection information, in breach of the Italian data protection code. | IT | Garante | GDPR | €4,800 | ↗ |
| 05 Nov 2015 | Romagna Giochi srlRomagna Giochi srl was fined EUR 4,800 by the Italian Garante. The authority found that the company failed to provide adequate notice about video surveillance at its premises, breaching data protection rules. | IT | Garante | GDPR | €4,800 | ↗ |
| 07 Apr 2026 | Dane anonimowe (Wspólnotę Mieszkaniową K.)The UODO imposed an administrative fine on K. Housing Community for failing to report a personal data breach without undue delay, and no later than 72 hours after becoming aware of it. The case concerns the obligation to notify the President of the UODO within the statutory deadline. | PL | UODO | GDPR | €1,135 | ↗ |
| 25 Jul 2021 | CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L.The company was fined by the AEPD for processing personal data without consent, which breaches Article 6 of the GDPR. The case indicates that no valid legal basis was in place for the processing activity. | ES | AEPD | GDPR | €5,000 | ↗ |
| 11 Jun 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 5,000 by the AEPD for failing to provide requested information. The breach concerned the duty to cooperate with the data protection authority during its proceedings. | ES | AEPD | GDPR | €5,000 | ↗ |
| 09 Aug 2022 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined 5,000 EUR by the AEPD for sending commercial SMS messages without the recipient’s consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 17 Apr 2026 | Framos Italia s.r.l. in liquidazioneFramos Italia s.r.l. in liquidation was fined EUR 5,000 by the Garante. The authority found that former employees’ email accounts were not deactivated and that information on data processing was not clear and comprehensive. | IT | Garante | GDPR | €5,000 | ↗ |
| 26 Oct 2022 | FUNDACIÓN CITIZENGOFUNDACIÓN CITIZENGO was fined by the AEPD EUR 5,000 for sending unsolicited emails without recipients’ consent. The authority found a breach of Article 7 GDPR on valid consent. | ES | AEPD | GDPR | €5,000 | ↗ |
| 25 Jul 2022 | MZN HELLAS A.E.The company was fined for sending unsolicited SMS messages for marketing purposes despite the recipient's objection. This conduct breached GDPR rules on personal data processing and direct marketing. | GR | HDPA | GDPR | €5,000 | ↗ |
| 01 Jan 2021 | ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINEThe entity was fined by the AEPD 5,000 EUR for failing to comply with a data deletion request and for sending unsolicited marketing emails without consent. The case indicates non-compliance with data subject rights and rules on direct marketing communications. | ES | AEPD | GDPR | €5,000 | ↗ |
| 04 Aug 2017 | VodafoneVodafone was fined 5,000 EUR by the HDPA for failing to satisfy the complainant’s request to access their personal data. The case concerns a breach of the data subject’s access rights under the controller’s obligations. | GR | HDPA | GDPR | €5,000 | ↗ |
| 01 Jun 2023 | Comune di GuardiagreleComune di Guardiagrele was fined EUR 5,000 by the Garante for failing to provide an adequate response to a data access request. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing. | IT | Garante | GDPR | €5,000 | ↗ |
| 01 Jan 2020 | BANCO DE SABADELL, S.A.Banco de Sabadell was fined for sending a commercial email to a customer who had previously opted out of such communications. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |