BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Jun 2010 | ICTS Italia s.r.l.ICTS Italia s.r.l. was fined by the Garante for using a biometric system for employee access control and attendance without adequate notice, consent, or minimum security measures. The company also failed to notify the Garante. | IT | Garante | GDPR | €18,400 | ↗ |
| 25 Jan 2023 | Dane anonimowe (S. Sp. z o.o. z siedzibą w R. przy ul.)The President of UODO imposed an administrative fine of PLN 18,279 on the company. The sanction was issued for failing to cooperate with the authority and for not providing information necessary for the performance of its duties. | PL | UODO | GDPR | €3,876 | ↗ |
| 31 Dec 2021 | Dane anonimowe (S. Spółka z o.o. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 18,192 on the company. The sanction resulted from failing to provide access to personal data and other information necessary for the authority to perform its duties. | PL | UODO | GDPR | €3,957 | ↗ |
| 01 Dec 2021 | Dane anonimowe (P. Sp. z o.o. z siedzibą we W. przy ul.)The UODO imposed an administrative fine of PLN 18,192 on P. Sp. z o.o. The case concerned a breach of applicable rules that resulted in an administrative sanction. | PL | UODO | GDPR | €3,931 | ↗ |
| 20 Jun 2013 | ASL di SalernoASL di Salerno was fined EUR 18,000 by the Garante for failing to implement minimum security measures. The authority cited, among other issues, the absence of designated data processing managers and the use of common, outdated passwords for electronic systems. | IT | Garante | GDPR | €18,000 | ↗ |
| 08 Nov 2012 | Enterprise Service s.r.l.Enterprise Service s.r.l. was fined by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The authority also found that the required information notice was not provided, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €18,000 | ↗ |
| 26 Jul 2018 | Mercati s.p.aMercati s.p.a was fined 18,000 EUR by the Garante for failing to provide adequate information to users about data collection through a reservation form. The authority also found that the company used a video surveillance system without proper notice, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €18,000 | ↗ |
| 24 May 2024 | G&F&S SECURITY GROUP, S.L.G&F&S SECURITY GROUP, S.L. was fined by the AEPD €18,000 for failing to properly handle a data subject access request. The authority found a breach of Article 15 GDPR and non-compliance with a data protection authority resolution. | ES | AEPD | GDPR | €18,000 | ↗ |
| 26 Dec 2024 | SOCIETE EXPLOITANT DES SUPERMARCHES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 18,000 on SOCIETE EXPLOITANT DES SUPERMARCHES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €18,000 | ↗ |
| 21 Dec 2023 | Azienda socio-sanitaria localeThe Garante imposed a fine on a local health authority for violations related to the handling of sensitive personal data. The case concerned improper processing of special-category data, which breached data protection rules. | IT | Garante | GDPR | €18,000 | ↗ |
| 24 Jun 2025 | BirthlinkThe UK Information Commissioner’s Office (ICO) fined Scottish charity Birthlink GBP 18,000. The case involved the destruction of about 4,800 personal records, up to 10% of which may have been irreplaceable. | GB | ICO | GDPR | €21,109 | ↗ |
| 18 May 2023 | AUTOMOBILE BAVARIA SRLThe fine was imposed for the unauthorized disclosure of personal data of 290 clients and potential clients, which were publicly accessible on the operator's website. The case concerns a breach of data protection rules through disclosure without an appropriate legal basis or safeguards. | RO | ANSPDCP | GDPR | €18,000 | ↗ |
| 16 Sept 2021 | Azienda sanitaria provinciale di CosenzaAzienda sanitaria provinciale di Cosenza was fined by the Garante for unlawfully publishing health data on its institutional website. The case involved breaches of data protection principles and required security measures for sensitive data. | IT | Garante | GDPR | €18,000 | ↗ |
| 10 Apr 2025 | Provvedimento del 10 aprile 2025 [10144184]A healthcare organization was fined after an employee accessed a patient's health dossier without authorization. The case highlights a breach of data protection rules in the healthcare sector. | IT | Garante | GDPR | €18,000 | ↗ |
| 14 Jan 2021 | Azienda Usl di BolognaAzienda Usl di Bologna was fined by the Garante 18,000 EUR for violations related to personal data protection in the healthcare sector. The case concerned irregularities in the processing of patient data, which breached data protection requirements. | IT | Garante | GDPR | €18,000 | ↗ |
| 11 Sept 2025 | Comune di NichelinoComune di Nichelino was fined EUR 18,000 by the Garante for failing to provide an adequate response to a data subject's request to exercise their rights. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €18,000 | ↗ |
| 16 Nov 2023 | Provvedimento del 16 novembre 2023 [9960948]The Garante imposed an EUR 18,000 fine on a training company for the unauthorized online publication of personal data relating to health. The case concerned breaches of GDPR Articles 5 and 32 on data processing principles and security. | IT | Garante | GDPR | €18,000 | ↗ |
| 12 Dec 2024 | SOCIETE DE VENTE AU DETAIL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 18,000 on SOCIETE DE VENTE AU DETAIL under a simplified procedure. The decision concerns a breach of rules within the CNIL's remit. | FR | CNIL | GDPR | €18,000 | ↗ |
| 04 Aug 2021 | Anonymisé (CNPD decision-29-fr-2021)The CNPD found that the organization did not appoint a Data Protection Officer based on the required professional qualities, did not provide the necessary resources, and did not ensure the DPO's autonomy. This constituted breaches of GDPR Articles 37, 38, and 39. | LU | CNPD | GDPR | €17,700 | ↗ |
| 01 Aug 2025 | društvo XThe company failed to implement appropriate organizational and technical security measures, which led to the unauthorized disclosure of personal data of clients involved in credit financing. AZOP imposed a fine of 17,500 EUR. | HR | AZOP | GDPR | €17,500 | ↗ |