Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Apr 2025Agenzia Mobilità Ambiente e Territorio S.r.l.The Garante fined Agenzia Mobilità Ambiente e Territorio S.r.l. 9,000 EUR for failing to provide sufficient transparency to data subjects. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€9,000
21 Mar 2013HU YunteHU Yunte was fined by the Garante for failing to provide the required data protection notice in connection with a video surveillance system. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
11 Feb 2021Fondazione di religione e di culto “Casa sollievo della sofferenza” Opera di San Pio da PietrelcinaThe foundation was fined by the Garante 5,000 EUR for processing personal data in breach of the principles of lawfulness, fairness, transparency, integrity, and confidentiality. The case concerned in particular the handling of health data.ITGaranteGDPR€5,000
23 May 2019Comune di FerraraComune di Ferrara was fined 2,400 EUR by the Garante for violations linked to its online registry service. The system allowed citizens to obtain personal and civil status certificates at municipal pharmacies without adequate data protection measures.ITGaranteGDPR€2,400
28 Sept 2023Azienda Usl Toscana centroThe Garante imposed a fine of EUR 50,000 on Azienda Usl Toscana centro for data protection violations related to the former Sanatorio Guido Banti premises. The case concerned irregularities in the processing of personal data in that context.ITGaranteGDPR€50,000
08 May 2013Società Cooperativa Frantoio Oleario SanviteseThe company was fined 2,400 EUR by the Garante for providing inadequate data protection information on its website. The case concerned a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
08 Feb 2007Asl Vibo ValentiaThe health authority Asl Vibo Valentia was fined by Garante for improperly handling sensitive personal data, including genetic and biometric data, without proper authorization. The case concerns a breach of data protection rules and the legal basis required for processing such data.ITGaranteGDPR€10,000
28 Sept 2023Axpo Italia S.p.A.Axpo Italia S.p.A. was fined by the Garante 10,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the conclusion of unsolicited contracts for electricity and gas supply.ITGaranteGDPR€10,000,000
13 Jan 2022A.S.L. Napoli 1 CentroA.S.L. Napoli 1 Centro was fined EUR 6,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data in violation of lawfulness, fairness, transparency, and data minimization requirements.ITGaranteGDPR€6,000
16 Apr 2015avv. Pasquale GiordanoAvv. Pasquale Giordano was fined EUR 4,000 by the Italian data protection authority, Garante. The sanction concerned the disclosure of a client's personal data to the opposing party's lawyer in a divorce proceeding without the client's consent, in breach of Article 23 of the Italian Privacy Code.ITGaranteGDPR€4,000
26 Jul 2018MEVALUATE ITALIA S.R.L.MEVALUATE ITALIA S.R.L. was fined by the Garante 26,000 EUR for sending promotional emails without obtaining specific consent. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€26,000
05 Sept 2013Leon d'oro Shi e Shi di Shi Deshao e C. S.n.cThe company was fined by the Garante 2,400 EUR for operating a video surveillance system without the required privacy notice. This breached the Italian Privacy Code because individuals under surveillance were not properly informed.ITGaranteGDPR€2,400
06 Jul 2023Ristorante Francesco s.r.l.Ristorante Francesco s.r.l. was fined by the Garante in the amount of 5,000 EUR for operating surveillance cameras without the required notices to affected individuals. The authority treated this as a breach of privacy rules.ITGaranteGDPR€5,000
17 Jan 2008Aesculapius s.r.l.Aesculapius s.r.l. was fined by the Garante for missing the deadline to notify personal data processing activities. The breach concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
05 Oct 2017Italprest di Luca Bosimini & C. s.a.s.Italprest di Luca Bosimini & C. s.a.s. was fined €10,000 by the Garante. The authority found that the company failed to implement minimum security measures, including the use of passwords shorter than eight characters, in breach of Article 33 of the Italian Data Protection Code.ITGaranteGDPR€10,000
21 Dec 2023MediafondMediafond was fined EUR 10,000 by the Garante for continuing to use a former employee’s email account after the employment ended. The company also forwarded emails without proper notice, which breached GDPR requirements.ITGaranteGDPR€10,000
06 Jun 2018SECCHI Elettroservice S.r.l.SECCHI Elettroservice S.r.l. was fined by the Garante 8,000 EUR for failing to properly notify employees about the use of a geolocation system on company vehicles. The authority found a breach of data protection rules.ITGaranteGDPR€8,000
22 Jun 2017Adsalsa Italia Publicidad SucursalAdsalsa Italia Publicidad Sucursal was fined EUR 20,000 by the Garante. The authority found that personal data were processed without obtaining separate consent for each purpose, in breach of data protection rules.ITGaranteGDPR€20,000
14 Dec 2017SEMS – Servizi per la mobilità sostenibile S.r.l.SEMS – Servizi per la mobilità sostenibile S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to meet notification obligations linked to the installation of satellite tracking devices in its vehicle fleet, in breach of data protection rules.ITGaranteGDPR€20,000
21 Mar 2013Giant s.r.l.Giant s.r.l. was fined 114,000 EUR by the Garante for the unauthorized registration of numerous phone cards to third parties without their knowledge. The authority found this conduct to be in breach of data protection rules.ITGaranteGDPR€114,000