Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Oct 2018Vodafone-PanafonVodafone-Panafon was fined by the HDPA for making unsolicited marketing calls to subscribers who had opted out of such contact. The authority found that the conduct breached privacy and data protection rules.GRHDPAePrivacy€12,000
18 Jul 2023Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest MilaneseThe Garante fined Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest Milanese 12,000 EUR for a data breach. Personal data was accessed without negative consequences for the data subjects. The organization took measures to prevent similar violations in the future.ITGaranteGDPR€12,000
20 Oct 2022Comune di SalentoComune di Salento was fined for unlawful processing of personal data through video surveillance systems. The authority found that retention periods for surveillance images were not set and that free access to personal data was not ensured, breaching GDPR transparency and access rights.ITGaranteGDPR€12,000
10 Jul 2025Comune di LanghiranoThe Municipality of Langhirano was fined by the Garante for the unauthorized disclosure of personal data on its institutional website. The data was removed, but the authority imposed a monetary penalty of EUR 12,000.ITGaranteGDPR€12,000
10 Jun 2021orthodontiepraktijkThe entity failed to implement appropriate technical and organizational measures to secure personal data, which constitutes a breach of Article 32 GDPR. Sensitive data on the website was not transmitted over encrypted connections, increasing the risk of disclosure.NLAPGDPR€12,000
27 Jun 2024SOCIETE SPECIALISEE EN GESTION IMMOBILIERE ET EN EXPLOITATION COMMERCIALE SOCIETE DIFFUSANT DES CONTENUS JOURNALISTIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 12,000 on SOCIETE SPECIALISEE EN GESTION IMMOBILIERE ET EN EXPLOITATION COMMERCIALE SOCIETE DIFFUSANT DES CONTENUS JOURNALISTIQUES under a simplified procedure. The case concerned a breach of rules supervised by the CNIL.FRCNILGDPR€12,000
29 Apr 2026Ministero della GiustiziaThe Ministry of Justice was fined EUR 12,000 by the Garante for violations related to personal data processing. The case concerned the absence of an appropriate legal basis and the processing of special categories of data.ITGaranteGDPR€12,000
17 Dec 2015Caaf Cgil Sardegna srlCaaf Cgil Sardegna srl was fined by the Garante 12,000 EUR for failing to provide the required privacy notice on its website. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€12,000
02 Mar 2011Santa Caterina Impianti S.p.A.Santa Caterina Impianti S.p.A. was fined 12,000 EUR by the Garante. The authority found a breach for failing to provide the required data protection information under the Italian Data Protection Code.ITGaranteGDPR€12,000
02 Mar 2011Skiarea Valchiavenna S.p.A.Skiarea Valchiavenna S.p.A. was fined EUR 12,000 by the Garante. The authority found that the company failed to provide the required data protection information to skiers using its facilities, in breach of Articles 13 and 161 of the Italian Data Protection Code.ITGaranteGDPR€12,000
26 Jun 2014Sudmetal s.r.l.Sudmetal s.r.l. was fined for using an integrated video surveillance system that allowed images from workplaces to be viewed without the required safeguards. The authority found this to be a breach of privacy regulations.ITGaranteGDPR€12,000
10 Oct 2023ComuneThe Italian data protection authority fined a municipality EUR 12,000 for unlawfully publishing personal data online in access request registers. Documents in the transparency section of the municipal website exposed names, protocol numbers, and other sensitive details of hundreds of citizens.ITGarante per la protezione dei dati personaliGDPR€12,000
13 May 2015Ottodue s.r.l.Ottodue s.r.l. was fined EUR 12,000 by the Garante for retaining surveillance footage for 98 days. This exceeded the 7-day retention limit set out in the video surveillance guidelines.ITGaranteGDPR€12,000
22 Oct 2015Comune di ZagariseComune di Zagarise was fined for processing employees’ biometric data without notifying the Garante and without requesting prior verification. The authority found violations of Articles 17 and 37 of the Codice.ITGaranteGDPR€12,000
26 Jun 2014Mitomet s.r.l.Mitomet s.r.l. was fined 12,000 EUR by the Garante for using an integrated video surveillance system. The system allowed viewing images from workplaces without implementing the required privacy safeguards.ITGaranteGDPR€12,000
15 Mar 2018Istituto Tecnico Statale Commerciale e per Geometri Masullo ThetiIstituto Tecnico Statale Commerciale e per Geometri Masullo Theti was fined by the Garante €12,000 for operating a video surveillance system without the required authorization. The case concerns a breach of privacy and personal data protection rules.ITGaranteGDPR€12,000
07 May 2015Lucchese FrancoLucchese Franco was fined by the Garante EUR 12,000 for retaining surveillance footage beyond the legally prescribed period. The case concerned non-compliance with data protection retention rules.ITGaranteGDPR€12,000
12 Feb 2026Based s.r.l.Based s.r.l. was fined by the Garante EUR 12,000 for providing an inadequate response to a data subject’s request for access to and deletion of email account data. The authority found that the company failed to comply with GDPR requirements on data subject rights.ITGaranteGDPR€12,000
26 Feb 2026Ministero dell’Economia e delle FinanzeThe Ministry of Economy and Finance was fined 12,000 EUR by Garante for inadequate control measures over the data processor. The authority found breaches of GDPR Articles 3, 5 and 6, as well as Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€12,000
14 Apr 2011Mansutti S.p.A.Mansutti S.p.A. was fined EUR 12,000 by the Garante for failing to provide the required data protection notice on its website forms. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€12,000