BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Jul 2022 | SIA "DEPO DIY"DVI imposed a fine of 17,495 EUR on SIA "DEPO DIY". The decision concerns a breach of obligations and has entered into force. | LV | DVI | GDPR | €17,495 | ↗ |
| 26 Sept 2024 | Azienda Sanitaria Territoriale di Ascoli PicenoThe Garante fined Azienda Sanitaria Territoriale di Ascoli Piceno EUR 17,000 for failing to implement procedures that would prevent unauthorized linkage between individuals and health departments. The issue could reveal information about a person's health status. | IT | Garante | GDPR | €17,000 | ↗ |
| 12 Jan 2024 | Alior Bank SA Varșovia Sucursala BucureștiAlior Bank SA, through its Romanian branch, was fined EUR 17,000 by ANSPDCP. The sanction followed an investigation that identified GDPR violations. | RO | ANSPDCP | GDPR | €17,000 | ↗ |
| 25 Oct 2017 | TICKETMASTER SPAIN S.A.Ticketmaster Spain S.A. was fined 17,000 EUR by the AEPD for failing to provide adequate information and obtain valid consent for the use of cookies on its website. The authority found that this conduct breached data protection and privacy rules. | ES | AEPD | ePrivacy | €17,000 | ↗ |
| 29 Jun 2021 | Anonymisé (CNPD decision-24-fr-2021)The company was fined EUR 17,000 by the CNPD for breaching the data minimization principle and for failing to provide adequate information to data subjects. The deficiencies concerned employees and third parties in relation to processing activities. | LU | CNPD | GDPR | €17,000 | ↗ |
| 04 Sept 2025 | SOCIETE COLLECTANT DES DONNEES DE PROSPECTS A PARTIR DE PLUSIEURS SOURCES, NOTAMMENT DES FORMULAIRES DE PARTICIPATION A DES JEUX CONCOURS EN LIGNE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 17,000 on SOCIETE COLLECTANT DES DONNEES DE PROSPECTS A PARTIR DE PLUSIEURS SOURCES, NOTAMMENT DES FORMULAIRES DE PARTICIPATION A DES JEUX CONCOURS EN LIGNE under the simplified procedure. The case concerned the processing of prospect data collected from multiple sources, including online contest entry forms. | FR | CNIL | GDPR | €17,000 | ↗ |
| 05 Feb 2026 | Dane anonimowe (pana H. G., prowadzącego działalność gospodarczą pod firmą H.)The President of the Polish DPA (UODO) imposed a fine of PLN 16,804 on an anonymous sole proprietor. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for the performance of its duties. | PL | UODO | GDPR | €3,982 | ↗ |
| 13 May 2015 | Barbirato Danilo s.a.s.Barbirato Danilo s.a.s. was fined by the Garante EUR 16,800 for failing to provide the required privacy notice on its website and for improper use of a video surveillance system. The authority cited inadequate CCTV signage and excessive retention of recorded images. | IT | Garante | GDPR | €16,800 | ↗ |
| 24 Jan 2013 | Saverio ProcopioSaverio Procopio was fined €16,800 by the Garante for sending unsolicited promotional emails without obtaining explicit consent from recipients. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €16,800 | ↗ |
| 20 Feb 2014 | Società Editrice Sud s.p.a.Società Editrice Sud s.p.a. was fined by the Garante in the amount of 16,800 EUR for using inadequate information notices on data collection forms. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €16,800 | ↗ |
| 13 May 2015 | Barbirato Danilo s.a.s. di Barbirato Marco e c.Barbirato Danilo s.a.s. was fined by the Garante 16,800 EUR for failing to provide the required privacy notice on its data collection form. The authority also found breaches of CCTV rules, including inadequate signage and excessive retention of recorded images. | IT | Garante | GDPR | €16,800 | ↗ |
| 20 Apr 2017 | Hotel Savoia Genova s.r.l.Hotel Savoia Genova s.r.l. was fined €16,800 by the Garante. The authority found that the company failed to provide the required information to individuals about its video surveillance system and kept surveillance footage longer than permitted. | IT | Garante | GDPR | €16,800 | ↗ |
| 11 Sept 2014 | Happy Fit s.r.l.Happy Fit s.r.l. was fined by the Garante in the amount of EUR 16,400 for making an unsolicited promotional phone call. The company did not provide the required information or obtain consent, breaching data protection rules. | IT | Garante | GDPR | €16,400 | ↗ |
| 21 Nov 2025 | Anonimizirano (IP-RS 0609-114/2025/9)A legal entity was fined by IP-RS for failing to implement adequate organizational and technical measures to secure personal data processing on a publicly accessible web server. This led to unauthorized access to the personal data of 12 individuals. | SI | IP-RS | GDPR | €16,250 | ↗ |
| 24 Apr 2013 | ModenaFiere S.r.l.ModenaFiere S.r.l. was fined EUR 16,000 by the Garante for processing personal data without adequate notice and consent. The violations covered promotional communications, statistical activities, and the dissemination of data on its website and in publications. | IT | Garante | GDPR | €16,000 | ↗ |
| 20 Nov 2014 | Asl Napoli 2 nordThe Garante imposed a 16,000 EUR fine on Asl Napoli 2 nord for failing to designate data protection officers and for keeping surveillance footage longer than permitted without prior authorization. The case concerned organizational compliance failures and unlawful data retention. | IT | Garante | GDPR | €16,000 | ↗ |
| 26 May 2022 | Regione ToscanaThe Garante fined Regione Toscana EUR 16,000 for publishing unnecessary personal data on the web. The data were later removed, but the authority still found a sanctionable breach. | IT | Garante | GDPR | €16,000 | ↗ |
| 12 Oct 2016 | Lorenzo RiccitelliLorenzo Riccitelli was fined 16,000 EUR by the Italian data protection authority, Garante. The case concerned unsolicited emails and SMS messages used for electoral propaganda without the required information or consent from recipients. | IT | Garante | GDPR | €16,000 | ↗ |
| 12 Apr 2018 | Emanuele CollaEmanuele Colla was fined by the Garante for activating seven phone cards without the consent of the person whose data was used. The case concerns a breach of data protection rules and the unauthorized use of personal data. | IT | Garante | GDPR | €16,000 | ↗ |
| 20 Mar 2014 | Liguria Radiologia s.r.lLiguria Radiologia s.r.l was fined by the Garante EUR 16,000 for breaching data protection rules. The company improperly communicated patient data to third parties without adequate consent. | IT | Garante | GDPR | €16,000 | ↗ |