Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jul 2025Magna PT S.p.A.Magna PT S.p.A. was fined EUR 50,000 by the Garante for requiring employees to complete a questionnaire after absences due to illness. The authority found that this practice breached GDPR rules on the processing of personal data.ITGaranteGDPR€50,000
27 Apr 2023Benetton Group S.r.l.Benetton Group S.r.l. was fined €240,000 by the Italian data protection authority, Garante. The authority found violations in the processing of personal data for marketing and profiling purposes, including the retention of former customers’ data for more than 10 years without proper justification.ITGaranteGDPR€240,000
01 Dec 2022WoolenWoolen was fined EUR 3,000 by the Garante for a video surveillance system that did not meet transparency requirements. The authority cited a breach of GDPR Article 13 and Article 114 of the Italian Privacy Code.ITGaranteGDPR€3,000
14 Dec 2017Yahoo Italia s.r.l.Yahoo Italia s.r.l. was fined EUR 80,000 by the Garante for violations related to the processing of personal data concerning the geolocation of users connecting to its website. The case concerned irregularities in how these data were collected and processed.ITGaranteGDPR€80,000
12 Mar 2026La7 S.p.A.La7 S.p.A. was fined 40,000 EUR by the Garante for broadcasting personal data, including phone numbers and names, during a news segment. The authority found a breach of GDPR Article 5 on data processing principles.ITGaranteGDPR€40,000
20 Feb 2014Giuseppe IlacquaGiuseppe Ilacqua was fined for inadequate data protection measures related to a video surveillance system. The authority found insufficient employee notification and improper image retention practices.ITGaranteGDPR€6,000
20 Jul 2017Centro Laser s.r.l.Centro Laser s.r.l. was fined EUR 20,400 by the Garante for using inadequate password procedures and failing to provide required information on data processing to users. The case concerns breaches of data protection rules.ITGaranteGDPR€20,400
11 Jun 2015Allevi BortoloAllevi Bortolo was fined EUR 15,000 by the Garante for activating fourteen phone cards in the names of five individuals without their knowledge. The conduct breached data protection rules and led to supervisory enforcement.ITGaranteGDPR€15,000
21 Jul 2022Clio s.r.l.Clio s.r.l. was fined by the Italian Garante in the amount of 10,000 EUR for violations related to personal data processing. The case involved inadequate protection of whistleblower identities, in breach of the GDPR and national privacy code provisions.ITGaranteGDPR€10,000
21 Jan 2010Casa di cura privata Di Lorenzo s.p.a.The private clinic Casa di cura privata Di Lorenzo s.p.a. was fined by the Garante for breaching data protection rules. The authority found that it failed to comply with notification obligations under the Italian Privacy Code.ITGaranteGDPR€20,000
31 Jan 2019Comune di CataniaThe Municipality of Catania was fined EUR 6,000 by the Garante for unlawfully publishing personal data on its institutional website in connection with housing and rental assistance programs. The disclosed information included names, dates of birth, tax codes, and addresses.ITGaranteGDPR€6,000
06 Jul 2016Impresa Individuale Autosalone Ag. Car di Vitale AldoThe company collected personal data, including name and email address, through its website. It did not provide the required privacy notice, which breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
06 Jul 2023Provvedimento del 6 luglio 2023 [9925450The Garante imposed a EUR 2,000 fine on an individual for posting images of other people on social media without their consent. The authority found a breach of GDPR rights, including the rights to erasure and objection.ITGaranteGDPR€2,000
30 Jan 2014impresa individuale Otelma di Belelli Marco AmletoThe sole proprietorship Otelma di Belelli Marco Amleto was fined EUR 6,400 by the Garante for failing to implement minimum security measures when processing sensitive data via its website. The breaches included not appointing a data processor and not preparing a security program document.ITGaranteGDPR€6,400
14 Sept 2023Comune di San SeveroThe Municipality of San Severo was fined EUR 10,000 by the Garante for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€10,000
08 May 2014Concetta VivinoConcetta Vivino was fined by the Garante in the amount of EUR 2,400 for failing to provide adequate simplified information about the use of a video surveillance system. This constituted a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
12 Nov 2014One Italia s.r.l.One Italia s.r.l. was fined €200,000 by the Garante for sending unsolicited promotional messages related to a value-added service. The authority found that proper consent and adequate information were not obtained, in breach of data protection rules.ITGaranteGDPR€200,000
11 Mar 2021dott. Gregorio GrecoDott. Gregorio Greco was fined 6,400 EUR by the Garante for failing to provide information to data subjects and for processing patients' health-related personal data without consent. The case concerns patient data and breaches of transparency and lawful basis requirements.ITGaranteGDPR€6,400
24 Apr 2024Dly S.r.l.Dly S.r.l. was fined by the Garante EUR 5,000 for deploying a non-compliant video surveillance system. The system recorded both customers and employees, in breach of data protection rules.ITGaranteGDPR€5,000
08 Feb 2007Comune di FirenzeGarante imposed a EUR 3,000 fine on Comune di Firenze for failing to provide adequate information to individuals about the processing of personal data through a video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000