Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Oct 2013Compagnia Assicuratrice Linear s.p.a.Compagnia Assicuratrice Linear s.p.a. was fined by the Garante 80,000 EUR for collecting personal data without specific consent for purposes beyond registration services. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€80,000
27 Jan 2022Azienda socio sanitaria territoriale Nord di MilanoAzienda socio sanitaria territoriale Nord di Milano was fined by the Garante 20,000 EUR for failing to implement adequate security measures to protect personal data. The authority found a breach of GDPR provisions on data protection and security.ITGaranteGDPR€20,000
12 Dec 2024BDM Banca S.p.A.BDM Banca S.p.A. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The sanction concerned the failure to provide a timely response to a data subject’s access request, which constitutes a breach of GDPR Article 15.ITGaranteGDPR€20,000
22 May 2018Wind Tre s.p.a.Wind Tre s.p.a. was fined by the Garante EUR 600,000 for conducting marketing campaigns without obtaining the required user consent. The conduct breached data protection rules.ITGaranteGDPR€600,000
13 Jun 2013Vito GiacoiaVito Giacoia was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned the failure to provide the required privacy notice for a video surveillance system at the “Fratelli Venaria” club, in breach of the Italian Privacy Code.ITGaranteGDPR€2,400
13 May 2015Barbirato Danilo s.a.s. di Barbirato Marco e c.Barbirato Danilo s.a.s. was fined by the Garante 16,800 EUR for failing to provide the required privacy notice on its data collection form. The authority also found breaches of CCTV rules, including inadequate signage and excessive retention of recorded images.ITGaranteGDPR€16,800
05 Feb 2015Comune di San Giuseppe JatoComune di San Giuseppe Jato was fined by the Garante for unlawfully publishing sensitive personal data revealing health status on its website. The conduct breached privacy rules governing the processing and disclosure of sensitive data.ITGaranteGDPR€10,000
05 Sept 2013Maria Vita PezzellaMaria Vita Pezzella was fined EUR 6,000 by Garante for failing to provide the required privacy notice in a video surveillance system. The case concerned a breach of the Italian Privacy Code and the duty to inform individuals subject to monitoring.ITGaranteGDPR€6,000
12 Sept 2013Azienda USL ViterboAzienda USL Viterbo was fined for failing to implement minimum security measures and for not appointing data processing officers. The authority also noted that the security program document was not updated between 2006 and 2010.ITGaranteGDPR€10,000
21 Jul 2022Azienda Socio Sanitaria Territoriale RhodenseAzienda Socio Sanitaria Territoriale Rhodense was fined by the Garante EUR 3,000 for violations of data protection rules. The case concerned data breaches and inadequate security measures.ITGaranteGDPR€3,000
09 Feb 2011Istituto Ninetta Rosano s.r.lIstituto Ninetta Rosano s.r.l was fined EUR 30,000 by the Garante for violating data protection rules. The authority found non-compliance with the requirements of Article 37 of the Italian Data Protection Code.ITGaranteGDPR€30,000
22 Feb 2024Trasporto Passeggeri Emilia-Romagna S.p.A.The Garante fined Trasporto Passeggeri Emilia-Romagna S.p.A. 50,000 EUR for improper data processing and a lack of transparency in collecting consent for marketing purposes. The case concerned failures to properly inform data subjects and to meet consent requirements.ITGaranteGDPR€50,000
10 Jul 2025dottoressa Monica Maria FerrariThe doctor was fined for recording conversations with a patient during a specialist visit without proper consent. The authority also found a failure to provide required information, breaching transparency and information obligations.ITGaranteGDPR€7,000
11 Sept 2025Giada FM S.r.l.Giada FM S.r.l. was fined EUR 1,000 by the Garante for failing to respond to an employee’s request to access personal data. The request covered training certificates and medical visit documentation, which is a breach of the GDPR access rights.ITGaranteGDPR€1,000
22 May 2013Margiotta Pietro Antonio e ASL TA 1 – Azienda Sanitaria Locale di TarantoThe Garante fined Margiotta Pietro Antonio and ASL TA 1 10,000 EUR for failing to implement minimum security measures. In some departments, unauthorized personnel accessed patient data and shared authentication credentials were used.ITGaranteGDPR€10,000
25 Nov 2021Ordinanza ingiunzione - 25 novembre 2021 [9733002]A healthcare professional was fined by the Garante EUR 30,000 for unlawfully disclosing a patient's personal data, including unpaid medical bills and health information, to third parties. The authority found that the processing lacked a legal basis and breached the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€30,000
11 Apr 2013Sound station s.a.s.Sound station s.a.s. was fined 30,000 EUR by the Garante for registering numerous phone SIM cards to unaware third parties. The conduct breached data protection requirements.ITGaranteGDPR€30,000
27 Mar 2025Istituto di Istruzione Superiore “P. 96012510796The Garante imposed a fine on an educational institution for breaches of GDPR Articles 5, 6, and 9 in connection with data processing activities. The case concerned deficiencies in the lawful basis and principles of processing, including special-category data.ITGaranteGDPR€4,000
07 Apr 2016CityFan s.r.l.CityFan s.r.l. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned the failure to formally designate employees and collaborators as data processors under Article 33 of the Italian Data Protection Code.ITGaranteGDPR€4,000
22 Feb 2024Ordine dei Medici Chirurghi e Odontoiatri di PadovaOrdine dei Medici Chirurghi e Odontoiatri di Padova was fined 5,000 EUR by the Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization in the handling of personal data.ITGaranteGDPR€5,000