Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Aug 2025Linea Stampalibera Società Cooperativa r.l.The Garante imposed a EUR 2,000 fine on Linea Stampalibera Società Cooperativa r.l. for unlawfully disseminating personal data, including health information, on its online news site. The authority found a breach of data protection rules.ITGaranteGDPR€2,000
09 Jun 2016Montanaro Auto s.r.l.Montanaro Auto s.r.l. was fined by the Garante in the amount of 4,800 EUR for failing to provide data subjects with information about data processing. The breach concerned a video surveillance system and a web form, in violation of the Italian Data Protection Code.ITGaranteGDPR€4,800
16 Nov 2017Sarida s.r.l.Sarida s.r.l. was fined by the Italian Garante 10,000 EUR for inadequate security measures in the processing of personal data. The authority specifically noted insufficient password requirements for access to the company’s systems.ITGaranteGDPR€10,000
29 Apr 2026Consiglio Nazionale dei Periti Industriali e dei Periti Industriali LaureatiThe Consiglio Nazionale dei Periti Industriali e dei Periti Industriali Laureati was fined €3,000 by the Garante. The authority found that the organization failed to ensure transparency in data processing, breaching GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€3,000
19 Sept 2013Estav Nordovest ToscanaEstav Nordovest Toscana was fined 10,000 EUR by the Garante. The violation concerned the unlawful publication of candidates' judicial data on its website during a recruitment process.ITGaranteGDPR€10,000
01 Oct 2020Università Campus Bio-medico di RomaThe Garante fined Università Campus Bio-medico di Roma 20,000 EUR for a data protection breach. Online medical reports were accessible to other patients, resulting in unauthorized disclosure of sensitive information.ITGaranteGDPR€20,000
13 May 2015ASL Napoli 2 NordASL Napoli 2 Nord was fined 20,000 EUR by the Garante for publishing personal data on its website. The disclosed information could reveal individuals' health status, which breached privacy rules.ITGaranteGDPR€20,000
26 Feb 2020Comune di AstiComune di Asti was fined EUR 8,000 by the Garante for unlawfully publishing personal data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€8,000
24 Oct 2013Claudio ContiClaudio Conti was fined EUR 26,000 by the Garante for activating 100 phone cards in the name of an unaware third party. Required information was not provided and consent was not obtained, constituting a data protection breach.ITGaranteGDPR€26,000
22 Jul 2021Roma CapitaleRoma Capitale was fined EUR 800,000 by the Garante for failing to adequately protect the personal data of motorists using parking meters. The authority also found improper data retention practices, increasing the risk to data subjects.ITGaranteGDPR€800,000
16 Feb 2011Bioacqua s.r.l.Bioacqua s.r.l. was fined EUR 9,000 by the Garante for using phone numbers for commercial communications without explicit consent and without providing the required information notice. The conduct breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€9,000
21 Mar 2024Estlevante s.r.l.s.The Garante imposed a EUR 2,000 fine on Estlevante s.r.l.s. for failing to provide the required privacy notice for its video surveillance system. The breach concerned Article 13 of the GDPR.ITGaranteGDPR€2,000
11 Jul 2018General Market di E. Barcio & Fratelli s.n.c.General Market di E. Barcio & Fratelli s.n.c. was fined by the Garante 7,200 EUR for failing to provide adequate information to people entering its stores about data processing through video surveillance systems. The authority found that the required notice obligations for monitored individuals were not met.ITGaranteGDPR€7,200
09 Oct 2025Provvedimento del 9 ottobre 2025 [10184697]The Garante imposed a EUR 70,000 fine on a company managing a hospital for violations related to the processing of health data. The case also involved a change in the complainant's treatment path and a failure to notify the authority of a data breach.ITGaranteGDPR€70,000
23 Mar 2023CAAF CGIL Lombardia s.r.l.CAAF CGIL Lombardia s.r.l. was fined EUR 30,000 by the Garante for unlawful processing of personal data. The company sent promotional emails despite a prior request to delete the data.ITGaranteGDPR€30,000
23 Mar 2017Ente Nazionale per L’Aviazione Civile (ENAC)ENAC was fined by the Garante in the amount of 10,000 EUR. The authority found that adequate security measures were not implemented, in breach of Articles 33 and 34 of the Italian Data Protection Code.ITGaranteGDPR€10,000
16 Sept 2021Ordine Provinciale di Roma dei Medici Chirurghi e degli OdontoiatriOrdine Provinciale di Roma dei Medici Chirurghi e degli Odontoiatri was fined by the Garante €5,000 for failing to adequately respond to a data subject’s request for access to personal data. The authority found a breach of GDPR Articles 12 and 15.ITGaranteGDPR€5,000
16 Feb 2017Crabion s.r.l.Crabion s.r.l. was fined by the Garante in the amount of EUR 20,000 for processing genetic data without the required authorization. The case concerns breaches of the rules governing the lawful processing of sensitive personal data.ITGaranteGDPR€20,000
17 Mar 2016Nico MannelliNico Mannelli was fined by the Garante EUR 2,400 for inadequate video surveillance signage and for failing to inform individuals about the purpose of processing and the data controller. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
28 Apr 2022Comune di PartannaComune di Partanna was fined by the Garante for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. The case concerned the improper handling of personal data in a disciplinary procedure.ITGaranteGDPR€2,000