BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Apr 2023 | Roma CapitaleRoma Capitale was fined EUR 176,000 by the Garante for the unlawful processing and dissemination of personal health data relating to women who had terminated pregnancies. The sensitive information was displayed on crosses at a cemetery, creating a serious data protection breach. | IT | Garante | GDPR | €176,000 | ↗ |
| 27 Apr 2023 | Provvedimento del 27 aprile 2023 [9896468]A fine of EUR 400 was imposed for improper use of a video surveillance system that captured images of a public street without the required authorization. The case concerned a breach of personal data processing rules in the context of video monitoring. | IT | Garante | GDPR | €400 | ↗ |
| 27 Apr 2023 | Checcoro di Nigro FrancescoThe company was fined EUR 2,000 by the Italian data protection authority, Garante. The sanction concerned the use of surveillance cameras without appropriate informational signage, in breach of GDPR requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Apr 2023 | B.B.B.The entity installed a surveillance camera without informing tenants or obtaining their consent. The camera captured shared areas, which constituted a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 27 Apr 2023 | Geico S.p.A.Geico S.p.A. was fined 40,000 EUR by the Garante for keeping former employees' email accounts active after the employment relationship ended. The authority found that the company accessed the contents of those accounts in breach of GDPR requirements. | IT | Garante | GDPR | €40,000 | ↗ |
| 27 Apr 2023 | Comune di AdelfiaThe Garante fined Comune di Adelfia EUR 8,000 for violations related to the publication of personal data on its institutional website. The data were later removed. | IT | Garante | GDPR | €8,000 | ↗ |
| 27 Apr 2023 | Benetton Group S.r.l.Benetton Group S.r.l. was fined €240,000 by the Italian data protection authority, Garante. The authority found violations in the processing of personal data for marketing and profiling purposes, including the retention of former customers’ data for more than 10 years without proper justification. | IT | Garante | GDPR | €240,000 | ↗ |
| 27 Apr 2023 | Università degli studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined EUR 4,000 by the Garante for improperly disclosing a complainant’s personal data to all Italian universities. The disclosure also included data relating to criminal offenses, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Apr 2023 | Tiziana Life Science LimitedTiziana Life Science Limited was fined by the Italian Garante in the amount of EUR 30,000. The case concerned failure to provide information and obtain consent for processing personal and genetic data acquired from the bankrupt company Shar.Dna S.p.A. for scientific research purposes. | IT | Garante | GDPR | €30,000 | ↗ |
| 27 Apr 2023 | B.B.B.The entity was fined by the AEPD in the amount of EUR 1,000 for installing surveillance cameras without proper signage and justification. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 26 Apr 2023 | CARTONAJES BAÑERES, S.A.CARTONAJES BAÑERES, S.A. was fined by the AEPD 220,000 EUR for processing biometric data without the required data protection impact assessment. The authority also found a failure to comply with data subjects’ access rights. | ES | AEPD | GDPR | €220,000 | ↗ |
| 26 Apr 2023 | Regionstyrelsen i Region SkåneRegionstyrelsen i Region Skåne was fined by IMY for storing unencrypted sensitive patient data on a USB drive that was lost. The authority found this to be a breach of Article 32 GDPR, which requires appropriate technical and organisational security measures. | SE | IMY | GDPR | €17,566 | ↗ |
| 24 Apr 2023 | B.B.B.B.B.B. published the complainant’s image and name on its website without consent. AEPD found this to be a breach of data protection rules and imposed a EUR 1,000 fine. | ES | AEPD | GDPR | €1,000 | ↗ |
| 24 Apr 2023 | Tensa Art Design SAThe National Supervisory Authority completed an investigation in March 2023 at Tensa Art Design SA and found violations of GDPR provisions. As a result, the company was fined 1,000 EUR. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 23 Apr 2023 | GRIMEY WEAR, S.L.GRIMEY WEAR, S.L. did not delete the complainant’s personal data after a request and continued sending promotional emails. The AEPD found this to be a breach of Article 17 GDPR and imposed a fine of 10,000 EUR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Apr 2023 | COYARE SLUCOYARE SLU was fined by the AEPD EUR 2,000 for a data protection breach linked to mass email sending. Using CC instead of BCC exposed recipients’ email addresses and could have compromised their identities. | ES | AEPD | GDPR | €2,000 | ↗ |
| 21 Apr 2023 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. EUR 70,000 for allowing a SIM card swap without the user's consent. The incident enabled unauthorized access to the customer's bank information and resulted in a fraudulent bank transfer. | ES | AEPD | GDPR | €70,000 | ↗ |
| 20 Apr 2023 | Dane anonimowe (Rzecznika Dyscyplinarnego Izby Adwokackiej w X.)UODO imposed a fine of PLN 23,580 on an anonymous entity for failing to implement appropriate technical and organizational measures. The authority also found a lack of regular testing, measuring, and evaluation of the effectiveness of those measures in relation to processing data using external storage media. | PL | UODO | GDPR | €5,114 | ↗ |
| 20 Apr 2023 | HOLALUZ-CLIDOM, S.A.HOLALUZ-CLIDOM, S.A. was fined EUR 70,000 by the AEPD for processing personal data without consent. The company registered energy supplies for properties without the owner's consent, which breached Article 6(1) GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 19 Apr 2023 | MULTIGAS ASESORES S.L.MULTIGAS ASESORES S.L. was fined EUR 500 by the AEPD. The company failed to provide access required under Article 58(1) GDPR, obstructing the data protection authority’s inspection function. | ES | AEPD | GDPR | €500 | ↗ |