Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Jan 2026Provincia della Congregazione dei Fratelli delle Suore CristianeThe entity was fined for failing to ensure sufficient transparency in data processing and for not carrying out a data protection impact assessment for workplace surveillance systems. The authority found breaches of the GDPR and the national privacy code.ITGaranteGDPR€12,000
24 Feb 2011Federconsorzi Dolomiti SuperskiFederconsorzi Dolomiti Superski was fined EUR 12,000 by the Italian Garante. The authority found that the company failed to provide the required data protection information to individuals, in breach of Articles 13 and 161 of the Italian Data Protection Code.ITGaranteGDPR€12,000
11 Sept 2025Casa di Cura Città di RomaCasa di Cura Città di Roma was fined EUR 12,000 by the Garante for allowing unauthorized access to patient medical records. The case concerns a breach of data protection rules and indicates a need for stronger access controls.ITGaranteGDPR€12,000
21 Oct 2010Palmeto s.r.l.Palmeto s.r.l. was fined EUR 12,000 by the Italian supervisory authority, Garante. The case concerned failure to provide the required data protection information to individuals in connection with video surveillance and personal data collection via the company website.ITGaranteGDPR€12,000
31 Jan 2019CT BARCT BAR was fined by the Garante for unlawful processing of personal data through its video surveillance system. The recordings were retained for 15 days without proper compliance with applicable rules.ITGaranteGDPR€12,000
18 Jun 2015Comune di MurosComune di Muros was fined EUR 12,000 by the Garante. The authority found that the municipality failed to provide information and unlawfully published personal data revealing health status on its website.ITGaranteGDPR€12,000
12 Feb 2015Visini FabioVisini Fabio was fined EUR 12,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection requirements.ITGaranteGDPR€12,000
15 Jan 2015Barta s.r.l.Barta s.r.l. was fined by the Garante EUR 12,000 for operating a video surveillance system without prior authorization. Footage was retained for 15 days, exceeding the permitted one-week period.ITGaranteGDPR€12,000
30 Oct 2013Regione LazioRegione Lazio was fined EUR 12,000 by the Garante for collecting personal data through web forms without providing adequate information to data subjects. The authority found this to be a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€12,000
12 Nov 2015Capodarco Società Cooperativa Sociale IntegrataCapodarco Società Cooperativa Sociale Integrata was fined EUR 12,000 by the Garante for recording and listening to calls between call center operators and users. The authority found that the required information notice was not provided to worker members, in breach of data protection rules.ITGaranteGDPR€12,000
08 Jul 2015Autotrasporti Multipli Arcese SpaAutotrasporti Multipli Arcese Spa was fined 12,000 EUR by the Garante for retaining surveillance footage longer than the period allowed under the authority's guidelines. The case concerns non-compliance with data protection rules on video retention.ITGaranteGDPR€12,000
30 Apr 2025Anonymisé (CNPD decision-03-fr-2025)The company did not maintain a complete record of processing activities as required by Article 30 GDPR. CNPD imposed an administrative fine of €11,964.LUCNPDGDPR€11,964
02 Feb 2019Ordinanza ingiunzione - 2 febbraio 2019 [9100784]The Garante imposed an administrative fine for violating data protection rules. The case concerned retaining surveillance footage for longer than the permitted 7 days.ITGaranteGDPR€11,940
07 Dec 2023Dane anonimowe (N. Sp. z o.o. z siedzibą w W. przy ul.)The President of UODO imposed a PLN 11,790 administrative fine on N. Sp. z o.o. The company failed to cooperate with the authority in the performance of its duties and did not provide access to personal data and information necessary for those duties.PLUODOGDPR€2,722
12 Jul 2023Dane anonimowe (Panią K.W. prowadzącą działalność gospodarczą pod nazwą W. z miejscem wykonywania działalności w O. przy ul.)UODO imposed an administrative fine on the business for failing to report a personal data breach to the supervisory authority within 72 hours. The authority also found that the affected individuals were not notified without undue delay.PLUODOGDPR€2,651
15 Dec 2021Anonymisé (CNPD decision-48-fr-2021)The company did not comply with GDPR requirements on data minimization and on providing information to data subjects, including employees and third parties, in connection with its video surveillance system. CNPD imposed a fine of 11,600 EUR.LUCNPDGDPR€11,600
12 Sept 2025Dane anonimowe (Q. Sp. z o.o.)The Polish DPA (UODO) imposed an administrative fine of PLN 11,365 on Q. Sp. z o.o. The authority found a breach of Article 38(6) GDPR because the data protection officer role was performed by the company’s president.PLUODOGDPR€2,669
04 Jan 2024N*** -FußballvereinigungThe football association failed to implement appropriate technical and organizational measures for handling data deletion requests. The authority found breaches of Articles 25 and 17 GDPR and imposed a fine of EUR 11,000.ATDSBGDPR€11,000
29 Sept 2021Prefettura - Ufficio Territoriale del Governo di GenovaPrefettura - Ufficio Territoriale del Governo di Genova was fined by the Garante for publishing personal data on its institutional website. The conduct breached GDPR requirements on lawful processing and protection of personal data.ITGaranteGDPR€11,000
24 Apr 2024Dane anonimowe (Komitet Inicjatywy Ustawodawczej W. na rzecz ustawy o zmianie ustawy z dn. 24 lipca 2015 r. Prawo o zgromadzeniach oraz niektórych innych ustaw)UODO imposed an administrative fine on the entity responsible for a list of citizens supporting a legislative initiative. The authority found inadequate technical and organisational measures for the risk, a failure to regularly test security controls, and delays in reporting and notifying the personal data breach.PLUODOGDPR€2,527