Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Feb 2014Oreiade s.r.l.Oreiade s.r.l. was fined by the Garante for installing a video surveillance system at Hotel Blu Inn without adequate safeguards. The authority found a breach of data protection rules.ITGaranteGDPR€24,400
09 Jan 2014Giallooro s.r.lGiallooro s.r.l was fined EUR 2,400 by the Garante for collecting personal data through a website contact form without providing the required privacy notice. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
03 May 2018Pace MarinaPace Marina, a general practitioner, was fined by the Garante for failing to implement minimum security measures to protect patients’ personal and sensitive data. This failure allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
29 Apr 2025Regione Emilia RomagnaThe Garante fined Regione Emilia Romagna EUR 15,000 for violations related to the processing of personal data for official statistical purposes. The authority found incorrect application of data protection principles and measures.ITGaranteGDPR€15,000
17 Apr 2026Provvedimento del 17 aprile 2026 [10254325]The supervisory authority found that a video surveillance system with 25 cameras operated without the required informational signage. The breach concerned GDPR information obligations.ITGaranteGDPR€3,000
31 Jan 2019Azienda Sanitaria Locale di AlessandriaAzienda Sanitaria Locale di Alessandria was fined by the Garante 16,000 EUR for processing personal data through the health dossier without full compliance with data protection rules. The case concerned improper handling of sensitive data in a medical system.ITGaranteGDPR€16,000
09 Mar 2023Aesse S.r.l.s.Aesse S.r.l.s. was fined by the Italian Garante in the amount of €3,000. The case concerned unsolicited telemarketing calls made without consent and insufficient information provided about the source of personal data.ITGaranteGDPR€3,000
16 Sept 2021Istituto Comprensivo - IC Cosenza III “V. Negroni”Istituto Comprensivo - IC Cosenza III “V. Negroni” was fined by the Garante 2,000 EUR for unlawful processing of personal data and inadequate data protection. The authority also noted that personal data were made accessible online, increasing the risk to affected individuals.ITGaranteGDPR€2,000
18 Apr 2018Marigliano GianpaoloMarigliano Gianpaolo was fined by the Garante 50,000 EUR for unlawfully using personal data to activate 15 phone cards without the consent of the individuals concerned. The case indicates a breach of lawful processing requirements and consent rules.ITGaranteGDPR€50,000
16 Feb 2017Momax s.r.l.Momax s.r.l. was fined by the Garante for improper handling of telephone traffic data. The authority found failures to implement appropriate safeguards, including strong authentication and biometric recognition measures, and retention of data beyond the permitted period for billing and crime prevention purposes.ITGaranteGDPR€60,000
17 Jul 2025Associazione Il Cavallo Rosa/ChangeTheGame ODVThe Garante fined Associazione Il Cavallo Rosa/ChangeTheGame ODV 10,000 EUR for publishing a minor’s personal data on its Facebook page without anonymization. The authority found a breach of the data subject’s rights under the GDPR.ITGaranteGDPR€10,000
11 Apr 2024Libero Consorzio comunale di EnnaThe Garante fined Libero Consorzio comunale di Enna €6,000 for improperly assigning tasks to the Data Protection Officer. Those tasks should have been performed by the data controller or processor, not the DPO.ITGaranteGDPR€6,000
13 Mar 2025Istituto Alberghiero Mediterraneo di Pulsano (TA)Istituto Alberghiero Mediterraneo di Pulsano was fined EUR 2,000 by the Garante. The authority found breaches of the principles of lawfulness, fairness, and transparency in personal data processing.ITGaranteGDPR€2,000
25 Oct 2012Dario Flaccovio Editore s.r.l.Dario Flaccovio Editore s.r.l. was fined by the Garante 8,000 EUR for sending unsolicited promotional faxes without prior explicit consent. The conduct breached data protection rules and the requirement for lawful processing.ITGaranteGDPR€8,000
23 Jan 2020Azienda Ospedaliero Universitaria Integrata di VeronaAzienda Ospedaliero Universitaria Integrata di Verona was fined by the Garante EUR 30,000 for employees' unauthorized access to patient health records. The authority found a breach of GDPR principles on data protection and security measures.ITGaranteGDPR€30,000
09 Mar 2023Stefano MolenaThe Garante imposed a EUR 3,000 fine on Stefano Molena for operating a surveillance camera without the required informational signage. The breach concerned privacy rules and the duty to properly inform individuals subject to monitoring.ITGaranteGDPR€3,000
15 Sept 2022FCA Italy S.p.A.FCA Italy S.p.A. was fined by the Garante for failing to respond to a data subject's request for access to personal data related to employment. The authority found a breach of GDPR Article 15.ITGaranteGDPR€40,000
16 Nov 2023NEW BUY GOLD DI EMANUELE VITA & C. S.A.S.The company was fined EUR 1,000 by the Italian supervisory authority, Garante. The penalty was imposed because it operated a video surveillance system without the required information notice for data subjects, in breach of Article 13 GDPR.ITGaranteGDPR€1,000
15 Sept 2022Sofisticated Luxury Flats s.r.l.Sofisticated Luxury Flats s.r.l. was fined €2,000 by the Garante for using a biometric device to monitor employee attendance without a proper legal basis. The authority found that this practice breached data protection rules.ITGaranteGDPR€2,000
04 Aug 2025Azienda Ospedaliero Universitaria CareggiAzienda Ospedaliero Universitaria Careggi was fined by the Garante EUR 20,000 for violations related to the management of electronic health records. The authority found non-compliance with data protection requirements.ITGaranteGDPR€20,000