Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Apr 2011Trentino Trasporti Esercizio S.p.A.Trentino Trasporti Esercizio S.p.A. was fined by the Garante 25,000 EUR for collecting personal data through web forms without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€25,000
11 Apr 2024Comune di MadignanoThe Garante fined Comune di Madignano EUR 3,000 for unlawfully using surveillance data in a disciplinary proceeding against an employee. The authority found breaches of data protection and transparency principles.ITGaranteGDPR€3,000
10 Jun 2020Istituto autonomo per le case popolari della provincia di IserniaIstituto autonomo per le case popolari della provincia di Isernia was fined EUR 2,000 by the Garante. The authority found that personal data, including health information, had been published on the institutional website without a proper legal basis.ITGaranteGDPR€2,000
26 Feb 2026Dedalus Italia S.p.A.Dedalus Italia S.p.A. was fined EUR 32,000 by the Garante for inadequate security measures that led to a data breach. The company implemented corrective actions promptly, but prior violations were taken into account when setting the penalty.ITGaranteGDPR€32,000
19 Sept 2013dott. Luigi Ventronedott. Luigi Ventrone was fined for failing to respond to requests for information concerning the processing of personal data in connection with a complaint by Ms. Ilaria Corsale. The authority found a breach of Article 157 of the Italian Data Protection Code.ITGaranteGDPR€4,000
01 Dec 2022Amazon Italia Logistica s.r.l.Amazon Italia Logistica s.r.l. was fined by the Garante for delaying its response to a data subject’s request to access professional certificates. The authority found a breach of Article 15 GDPR.ITGaranteGDPR€20,000
24 Feb 2011Federconsorzi Dolomiti SuperskiFederconsorzi Dolomiti Superski was fined EUR 12,000 by the Italian Garante. The authority found that the company failed to provide the required data protection information to individuals, in breach of Articles 13 and 161 of the Italian Data Protection Code.ITGaranteGDPR€12,000
28 Jul 2016Jurica PavicJurica Pavic was fined by the Garante for failing to provide adequate information to data subjects about video surveillance. The authority found this to be a breach of privacy regulations.ITGaranteGDPR€2,400
11 Sept 2025Casa di Cura Città di RomaCasa di Cura Città di Roma was fined EUR 12,000 by the Garante for allowing unauthorized access to patient medical records. The case concerns a breach of data protection rules and indicates a need for stronger access controls.ITGaranteGDPR€12,000
06 Jul 2006Comune di AugustaThe Municipality of Augusta was fined by the Garante for failing to make a required notification under data protection law. The breach concerned Article 163 of the Codice Privacy.ITGaranteGDPR€5,164
18 Dec 2013Comune di MonticianoThe Municipality of Monticiano was fined 8,000 EUR by the Garante. The authority found a privacy violation after the municipality failed to provide requested information about the publication of personal data on its institutional website.ITGaranteGDPR€8,000
23 Oct 2025Provvedimento del 23 ottobre 2025 [10210718]The Garante imposed a EUR 10,000 fine on an individual tobacco shop owner for suspicious financial transactions involving the misuse of a third party’s identification data with a prepaid card. The case concerns unauthorized use of personal data in the context of payment operations.ITGaranteGDPR€10,000
13 Apr 2023Retimedia S.r.l.Retimedia S.r.l. was fined 2,500 EUR by the Garante for publishing detailed health data of an individual without consent. The conduct breached GDPR Article 9 on special categories of personal data.ITGaranteGDPR€2,500
03 May 2018Omis s.p.a.Omis s.p.a. was fined by the Garante 8,000 EUR for failing to notify the processing of geolocation data from vehicles. This notification was required under privacy regulations.ITGaranteGDPR€8,000
18 Nov 2015Zsa Zsa srlZsa Zsa srl was fined EUR 2,400 by the Italian Garante. The violation concerned the failure to provide the required privacy notice on the website’s data collection form, in breach of the Italian data protection code.ITGaranteGDPR€2,400
15 Jun 2011Azienda Multiservizi e Igiene Urbana S.p.A.Azienda Multiservizi e Igiene Urbana S.p.A. was fined for collecting personal data through a web form without providing users with the required privacy notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€9,000
30 Oct 2013Compagnia Assicuratrice Linear s.p.a.Compagnia Assicuratrice Linear s.p.a. was fined by the Garante 80,000 EUR for collecting personal data without specific consent for purposes beyond registration services. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€80,000
27 Jan 2022Azienda socio sanitaria territoriale Nord di MilanoAzienda socio sanitaria territoriale Nord di Milano was fined by the Garante 20,000 EUR for failing to implement adequate security measures to protect personal data. The authority found a breach of GDPR provisions on data protection and security.ITGaranteGDPR€20,000
12 Dec 2024BDM Banca S.p.A.BDM Banca S.p.A. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The sanction concerned the failure to provide a timely response to a data subject’s access request, which constitutes a breach of GDPR Article 15.ITGaranteGDPR€20,000
22 May 2018Wind Tre s.p.a.Wind Tre s.p.a. was fined by the Garante EUR 600,000 for conducting marketing campaigns without obtaining the required user consent. The conduct breached data protection rules.ITGaranteGDPR€600,000