BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Aug 2025 | Azienda Ospedaliero Universitaria CareggiAzienda Ospedaliero Universitaria Careggi was fined by the Garante EUR 20,000 for violations related to the management of electronic health records. The authority found non-compliance with data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 May 2021 | ATS di Bergamo, Agenzia di Tutela della saluteATS di Bergamo was fined by the Garante 20,000 EUR for violations involving the improper handling of sensitive health data. The case concerned the use of email to transmit data, which did not provide an adequate level of protection. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Apr 2025 | EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.The AEPD fined EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A. 20,000 EUR for publishing unnecessary personal data in a news article. A video in the article revealed the identity of a minor, which was considered disproportionate and unnecessary for the informational purpose. | ES | AEPD | GDPR | €20,000 | ↗ |
| 08 Mar 2018 | Riacetech S.r.l.Riacetech S.r.l. was fined for failing to notify the Garante about the installation of a biometric data processing system for employees. The case concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 03 Nov 2015 | VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD EUR 20,000 for continuing to send marketing emails to a user who had repeatedly requested to unsubscribe. The authority found this to be a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 28 Jun 2018 | Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined by the Garante €20,000 for sharing access credentials among employees. The authority found this to be a breach of data protection rules and access control requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jan 2016 | PROCTER & GAMBLE ESPAÑAProcter & Gamble España was fined 20,000 EUR by the AEPD for continuing to send marketing emails to a complainant after unsubscribe requests. The authority found this conduct breached the LSSI rules on electronic communications. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 18 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE DE COLLECTE DE DONNEES PROVENANT DE JEUX CONCOURS, DE PROSPECTION COMMERCIALE ET DE TRANSMISSION DE DONNEES A SES CLIENTS (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on a company engaged in collecting data from prize contests, commercial prospecting, and data transmission to clients. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 16 Oct 2025 | SOCIETE EXERCANT UNE ACTIVITE DE GESTION DE CENTRES DE SPORTS ET DE LOISIRS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE EXERCANT UNE ACTIVITE DE GESTION DE CENTRES DE SPORTS ET DE LOISIRS. The authority also issued an injunction to remedy the identified deficiencies. | FR | CNIL | GDPR | €20,000 | ↗ |
| 30 Nov 2017 | CAR SHARING TRENTINO Società CooperativaCAR SHARING TRENTINO Società Cooperativa was fined by the Garante 20,000 EUR. The authority found failures to comply with notification obligations related to vehicle geolocation, constituting a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 28 Apr 2026 | CROWD ENTERTAINMENT LIMITEDCROWD ENTERTAINMENT LIMITED was fined EUR 20,000 by the Romanian authority ANSPDCP. The sanction concerned violations of GDPR requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 16 Sept 2010 | Provincia di FoggiaProvincia di Foggia was fined by the Garante for making health-related personal data publicly accessible through Google and its website. The case involved improper disclosure of sensitive data, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jul 2022 | RCI BANQUE, S.A. SUCURSAL EN ESPAÑARCI Banque, S.A. Sucursal en España was fined by the AEPD for failing to properly handle a request for erasure under Article 17 GDPR. As a result, the data subject received unwanted communications about a debt they did not owe. | ES | AEPD | GDPR | €20,000 | ↗ |
| 12 Dec 2024 | Provvedimento del 12 dicembre 2024 [10095836]A doctor was fined EUR 20,000 for breaching core data protection principles. The authority cited failures relating to lawfulness, fairness, transparency, purpose limitation, data minimization, and integrity and confidentiality. | IT | Garante | GDPR | €20,000 | ↗ |
| 25 Sept 2023 | OASAThe Athens Urban Transport Organization (OASA) was fined for failing to timely conduct a Data Protection Impact Assessment (DPIA) for its Automatic Fare Collection System. The authority found this to be a breach of data protection principles in connection with the system's processing activities. | GR | HDPA | GDPR | €20,000 | ↗ |
| 27 Jun 2025 | YDAIL CONSTRUCT SRLANSPDCP completed an investigation at YDAIL CONSTRUCT SRL in June 2025 and found a violation of applicable legal provisions. As a result, the company was fined 20,000 RON. | RO | ANSPDCP | GDPR | €3,936 | ↗ |
| 01 Dec 2022 | Amazon Italia Logistica s.r.l.Amazon Italia Logistica s.r.l. was fined by the Garante for delaying its response to a data subject’s request to access professional certificates. The authority found a breach of Article 15 GDPR. | IT | Garante | GDPR | €20,000 | ↗ |
| 18 Apr 2024 | MOURO PRODUCCIONES, S.R.L.MOURO PRODUCCIONES, S.R.L. was fined by the AEPD 20,000 EUR for collecting copies of identity documents and personal data of minors and their guardians without proper data protection information. The authority found breaches of the data minimization and transparency principles. | ES | AEPD | GDPR | €20,000 | ↗ |
| 05 Dec 2024 | SOCIETE SPECIALISEE DANS L'ELABORATION ET ORGANISATION DE CAMPAGNES PUBLICITAIRES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE SPECIALISEE DANS L'ELABORATION ET ORGANISATION DE CAMPAGNES PUBLICITAIRES under a simplified procedure. The case concerns a data protection breach identified by the authority. | FR | CNIL | GDPR | €20,000 | ↗ |
| 27 Jan 2022 | Azienda socio sanitaria territoriale Nord di MilanoAzienda socio sanitaria territoriale Nord di Milano was fined by the Garante 20,000 EUR for failing to implement adequate security measures to protect personal data. The authority found a breach of GDPR provisions on data protection and security. | IT | Garante | GDPR | €20,000 | ↗ |