Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Apr 2013Zhang CanpingZhang Canping was fined by the Garante in the amount of EUR 2,400 for failing to provide the required data protection notice under Article 13 of the Italian Data Protection Code. The violation concerned Hotel Paola.ITGaranteGDPR€2,400
10 Nov 2022Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante. The authority found that promotional contacts were made without the required information and without obtaining the data subject’s consent, in breach of GDPR requirements.ITGaranteGDPR€500,000
09 Oct 2014CISPEL Lombardia Services s.r.l.CISPEL Lombardia Services s.r.l. was fined by the Garante for failing to provide the required data protection information to job applicants. The authority also found that personal data was shared with third parties without the data subjects' consent.ITGaranteGDPR€16,000
11 Feb 2021Azienda Sanitaria Locale n. 2 Lanciano-Vasto-ChietiAzienda Sanitaria Locale n. 2 Lanciano-Vasto-Chieti was fined by the Garante 6,500 EUR for violations related to the processing of health data. The нарушения led to a data breach incident.ITGaranteGDPR€6,500
15 Sept 2022Bper Banca S.p.A.Bper Banca S.p.A. was fined by the Garante for a delayed and inadequate response to requests for deletion of personal data. The authority found breaches of GDPR Articles 12 and 17.ITGaranteGDPR€10,000
10 Jun 2021aiComply S.r.l.aiComply S.r.l. was fined by the Garante in the amount of EUR 20,000 for failing to implement adequate security measures. In particular, it did not use a secure network protocol, which created a risk to the confidentiality and integrity of personal data.ITGaranteGDPR€20,000
23 Mar 2023La Risorsa Umana.it s.r.l.La Risorsa Umana.it s.r.l. was fined EUR 40,000 by the Garante for monitoring employee email communications without providing proper information to employees. The authority found that this conduct breached GDPR requirements on transparency of processing and data security.ITGaranteGDPR€40,000
24 Mar 2022Brav s.r.l.Brav s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate technical and organizational security measures. The issue concerned data processing linked to the management of contraventions by the local police of the Municipality of Genoa.ITGaranteGDPR€10,000
20 Sept 2012Policlinico Sassarese s.p.a.Policlinico Sassarese s.p.a. was fined EUR 64,000 by the Garante for inadequate data protection measures. The authority cited insufficient video surveillance notices and missing consent documentation for the processing of sensitive data.ITGaranteGDPR€64,000
15 Mar 2018Istituto Tecnico Statale Commerciale e per Geometri Masullo ThetiIstituto Tecnico Statale Commerciale e per Geometri Masullo Theti was fined by the Garante €12,000 for operating a video surveillance system without the required authorization. The case concerns a breach of privacy and personal data protection rules.ITGaranteGDPR€12,000
05 Oct 2017Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante for publishing a regional council resolution on its website that contained personal evaluations and information about an employee. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
04 Apr 2019Bill Size s.r.l.Bill Size s.r.l. was fined by the Garante in the amount of EUR 16,000 for registering phone cards to individuals without their consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€16,000
13 Nov 2024Thermogen S.r.l.Thermogen S.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The conduct breached the GDPR and national privacy laws.ITGaranteGDPR€10,000
17 Oct 2015Zhang SuliZhang Suli was fined by the Garante in the amount of EUR 2,400 for operating a video surveillance system at her beauty and massage center without the required privacy notice. The authority found a breach of the Italian Privacy Code.ITGaranteGDPR€2,400
24 Jan 2013Gruppo Finelco s.p.a.Gruppo Finelco s.p.a. was fined EUR 52,000 by the Garante for processing personal data without providing adequate information to data subjects. The company also failed to notify the Garante about profiling activities carried out through its websites.ITGaranteGDPR€52,000
26 Jul 2018Associazione MEVALAUTE ONLUSThe association was fined by the Garante for sending unsolicited PEC communications. The authority found that personal data were processed without consent, in breach of data protection rules.ITGaranteGDPR€26,000
28 Apr 2022Comune di Monte Sant’AngeloThe Municipality of Monte Sant’Angelo was fined 3,000 EUR by the Garante for breaching data protection principles. The authority found that personal data had been made accessible online in violation of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
08 Jun 2023Liguria News S.r.l.Liguria News S.r.l. was fined by Garante EUR 10,000 for publishing an article that breached privacy rules. The article disclosed personal and sensitive information about individuals involved in the reported incident, including a minor.ITGaranteGDPR€10,000
12 Feb 2026Lex Iuris S.r.l.Lex Iuris S.r.l. was fined by the Garante in the amount of 15,000 EUR for sending unsolicited promotional emails. The authority also found that the company failed to respond to data access requests, breaching transparency and data subject rights obligations.ITGaranteGDPR€15,000
22 May 2018De Nittis MicheleDe Nittis Michele, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This deficiency allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000