Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Oct 2022Promofarma Sviluppo s.r.l.Promofarma Sviluppo s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate data security measures and for lacking transparency in the authentication process on vaccine booking portals. These shortcomings made the system vulnerable to fraudulent access and misuse.ITGaranteGDPR€10,000
20 Oct 2022Azienda Ospedaliero-Universitaria Careggi di FirenzeAzienda Ospedaliero-Universitaria Careggi di Firenze was fined by the Garante 9,000 EUR for violations involving the processing of sensitive health data. The authority cited inadequate safeguards in the handling of histological examinations.ITGaranteGDPR€9,000
20 Oct 2022Fondazione Teatro Regio di TorinoFondazione Teatro Regio di Torino was fined EUR 5,000 by the Garante for publishing an individual's personal data on its website. The authority found a breach of the GDPR principles of lawful, fair, and transparent processing.ITGaranteGDPR€5,000
20 Oct 2022Comune di SalentoComune di Salento was fined for unlawful processing of personal data through video surveillance systems. The authority found that retention periods for surveillance images were not set and that free access to personal data was not ensured, breaching GDPR transparency and access rights.ITGaranteGDPR€12,000
20 Oct 2022Occhiali24.it S.r.l.Occhiali24.it S.r.l. was fined by the Garante 20,000 EUR for sending unsolicited marketing communications without prior consent. The authority also found that the company failed to respond to data subject rights requests, indicating non-compliance with data protection obligations.ITGaranteGDPR€20,000
20 Oct 2022Comune di Calvi RisortaThe Municipality of Comune di Calvi Risorta was fined 2,000 EUR by the Garante. The sanction resulted from a delayed response to the supervisory authority's request for information, which breached data protection rules.ITGaranteGDPR€2,000
20 Oct 2022Istituto di Istruzione Superiore “G. Renda” di Polistena, Reggio CalabriaIstituto di Istruzione Superiore “G. Renda” was fined EUR 900 by the Garante for unlawfully processing personal data. The school published sensitive information about an employee’s contract termination without a legal basis, breaching GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€900
20 Oct 2022Associazione Covid-Healer ODVThe Garante fined Associazione Covid-Healer ODV 500 EUR for breaches linked to the processing of health data through its app, which was active for a short period. The authority cited inadequate transparency and deficiencies in the data protection impact assessment.ITGaranteGDPR€500
20 Oct 2022Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined by the Garante €40,000 for failing to provide a data subject with access to personal data relating to derivative transactions. The authority found a breach of the principles of lawful, fair, and transparent processing.ITGaranteGDPR€40,000
20 Oct 2022Douglas Italia S.p.A.Douglas Italia S.p.A. was fined by the Italian Garante in the amount of €1,400,000. The authority found inadequate responses to data subject requests and a lack of clear separation between the privacy policy and cookie policy in the app. The conduct breached multiple GDPR provisions.ITGaranteGDPR€1,400,000
20 Oct 2022Policlinico Casilino di RomaPoliclinico Casilino di Roma was fined by the Garante for violations related to the handling of personal data in the healthcare sector. The case concerned improper processing of patient data and privacy compliance requirements.ITGaranteGDPR€15,000
18 Oct 2022a natural personA natural person was fined EUR 150 by ANSPDCP for violating the General Data Protection Regulation. The case concerned a breach of GDPR requirements.ROANSPDCPGDPR€150
18 Oct 2022SC Materiale Constructii Online SRLSC Materiale Constructii Online SRL was fined by ANSPDCP in the amount of EUR 2,000 for violating the General Data Protection Regulation (GDPR). The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
17 Oct 2022SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALECNIL imposed a EUR 20 million fine on SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALE and issued an injunction subject to a penalty. The case concerned identified data protection breaches.FRCNILGDPR€20,000,000
14 Oct 2022VODAFONE ONO, S.A.U.The AEPD fined VODAFONE ONO, S.A.U. 50,000 EUR for consulting a credit information system without the individual's consent. The company had no contractual relationship with the person, so there was no valid basis for the inquiry.ESAEPDGDPR€50,000
13 Oct 2022B.B.B.A tenant complained that the landlord installed a surveillance camera in the kitchen of the rented property without consent. The AEPD found a breach of data protection rules and imposed a EUR 4,000 fine.ESAEPDGDPR€4,000
10 Oct 2022EKO ABEEThe fine was imposed for a violation of Article 15 GDPR because the controller failed to provide the data subject with access to their personal data. The case concerns non-compliance with the obligation to ensure the right of access within the required scope.GRHDPAGDPR€10,000
06 Oct 2022Poste Italiane S.p.a.Poste Italiane S.p.a. was fined 10,000 EUR by the Garante. The authority found a breach of Article 15 GDPR due to failure to respond to a data access request.ITGaranteGDPR€10,000
06 Oct 2022Codess Sociale, Soc. Coop. socialeCodess Sociale, Soc. Coop. sociale was fined EUR 10,000 by the Garante. The authority found that the company failed to respond to a data subject's request to exercise GDPR rights.ITGaranteGDPR€10,000
06 Oct 2022Servizio Idrico Integrato S.c.p.a.Servizio Idrico Integrato S.c.p.a. was fined by the Garante EUR 15,000 for failing to implement adequate security measures to protect the personal data of users registered on its website. The case concerned insufficient safeguards for data processed online.ITGaranteGDPR€15,000