BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Jan 2025 | Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements, creating regulatory risk for organizations processing data in Romania. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 12 Dec 2024 | BDM Banca S.p.A.BDM Banca S.p.A. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The sanction concerned the failure to provide a timely response to a data subject’s access request, which constitutes a breach of GDPR Article 15. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jan 2023 | QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined 20,000 EUR by the AEPD for unlawfully obtaining personal data from a website. The data was then used for promotional purposes without the consent of the data subjects. | ES | AEPD | GDPR | €20,000 | ↗ |
| 26 Oct 2017 | Verde Luna s.a.s. di Antonietta Minnicelli & C.Verde Luna s.a.s. was fined EUR 20,000 by the Garante. The sanction concerned the company’s failure to provide information requested by the supervisory authority in a data protection matter. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Dec 2024 | SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 01 Jan 2022 | MUXERS CONCEPT, S.L.MUXERS CONCEPT, S.L. was fined EUR 20,000 by the AEPD for installing an unauthorized audio recording system in employee areas. The authority found this conduct to be in breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 30 Oct 2014 | Planetcall s.r.l.Planetcall s.r.l. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned promotional phone calls made without the individuals’ prior consent, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Jul 2022 | Acqua Novara.VCO S.p.a.Acqua Novara.VCO S.p.a. was fined EUR 20,000 by the Garante for breaches related to the processing of personal data. The case concerned confidentiality and the risks arising from handling sensitive data in a workplace context. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Jul 2017 | Aria S.p.a.Aria S.p.a. was fined 20,000 EUR by the Garante. The authority found a data protection breach for failing to designate employees as data processors. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jun 2023 | AUSL Toscana Sud EstThe Garante fined AUSL Toscana Sud Est 20,000 EUR for the unlawful dissemination of a patient's health data. The authority found a breach of data protection principles. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Nov 2024 | Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 20,000 EUR for publishing employees’ personal data without a legal basis. The disclosure included details on additional payments, sickness absences, and union rights, breaching the GDPR and the national privacy code. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Nov 2025 | GROUPEMENT D'INTERET ECONOMIQUE (GIE) EXERCANT UNE ACTIVITE D'ORGANISATION, DE DEVELOPPEMENT ET DE PROMOTION DE CENTRES COMMERCIAUX (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on a GIE engaged in the organization, development, and promotion of shopping centers. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 08 Mar 2018 | Tekne Progetti s.r.l.Tekne Progetti s.r.l. was fined for failing to respond to an information request from the Garante concerning its data processing activities. The conduct was found to violate Article 164 of the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 11 Apr 2024 | Istituto Nazionale Previdenza Sociale - INPSThe Italian Data Protection Authority fined INPS EUR 20,000 for violating data protection principles. The case concerned the improper handling of candidates’ personal data in a public competition. | IT | Garante | GDPR | €20,000 | ↗ |
| 03 May 2018 | Ordinanza ingiunzione - 3 maggio 2018 [9023941]A fine of EUR 20,000 was imposed for failing to notify the Garante about the processing of geolocation data collected through GPS devices. The case concerns a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Feb 2021 | SERVICIOS LOGÍSTICOS MARTORELL SIGLO XXI, S.L.The company was fined by the AEPD for deploying a biometric fingerprint system for employee attendance control without carrying out a data protection impact assessment. The authority found this to be a breach of Article 35 GDPR because the processing involved biometric data requiring prior risk assessment. | ES | AEPD | GDPR | €20,000 | ↗ |
| 16 May 2018 | Conafi Prestitò s.p.a.Conafi Prestitò s.p.a. was fined by the Garante for failing to notify certain data processing activities related to loan management. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 25 Sept 2025 | Azienda Ospedaliero Universitaria di FerraraAzienda Ospedaliero Universitaria di Ferrara was fined EUR 20,000 by the Garante for irregularities in the handling of personal data in its health dossier system. The authority found that the organization failed to implement adequate measures to protect data privacy. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Nov 2022 | ING Bank NV Amsterdam Sucursala BucureștiANSPDCP completed an investigation into ING Bank NV Amsterdam Bucharest Branch and found a breach of GDPR provisions. The case was opened following a data breach notification submitted by the controller. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 14 Sept 2023 | Shardana Working Soc. Coop. a r.l.Shardana Working Soc. Coop. a r.l. was fined by the Garante 20,000 EUR for failing to fully comply with data access requests. The authority found a breach of Article 15 GDPR. | IT | Garante | GDPR | €20,000 | ↗ |