Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Feb 2023It's OK LimitedBetween 1 July 2019 and 1 June 2020, It's OK Limited made 1,752,149 unsolicited direct marketing calls to subscribers who had been registered with the TPS for at least 28 days. The company had no evidence that the recipients had not objected to receiving such calls, breaching regulation 21 of PECR.GBICOePrivacy€225,000
18 Apr 2013Itel s.r.l. UnipersonaleItel s.r.l. Unipersonale was fined EUR 102,000 by the Garante for improper processing of personal data. The case involved registering phone cards to third parties without their knowledge, in breach of privacy rules.ITGaranteGDPR€102,000
05 Apr 2018I Tel s.r.l.I Tel s.r.l. was fined EUR 230,000 by the Italian data protection authority, Garante. The case concerned the registration of phone cards to 23 individuals without their consent, in breach of data protection rules.ITGaranteGDPR€230,000
05 May 2021Ítélet a NAIH-3644-9/2021. sz. ügyben (Fővárosi Törvényszék 105.K.704.512/2021/21)The supervisory authority found that the controller had not implemented adequate technical and organizational measures to protect personal data. Employees were also not properly informed about processing related to email accounts and devices, and personal email was accessed without proper justification.HUNAIHGDPR€5,560
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Kúria végzése Kpk.III.39.352/2022/3)The controller processed personal data without a legal basis and did not provide adequate information about the processing. The authority found violations of several GDPR provisions and imposed a fine.HUNAIHGDPR€2,820
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Kúria Kfv. II.37.001/2021/6)The controller processed personal data without a legal basis for a political campaign. It also failed to provide adequate information about the processing, resulting in breaches of several GDPR provisions.HUNAIHGDPR€2,820
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Alkotmánybíróság 3110/2022. (III. 23.) AB határozata)The controller processed personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The authority imposed a fine of HUF 1,000,000 for breaches of GDPR principles.HUNAIHGDPR€2,820
10 Dec 2020Ítélet a NAIH/2020/54/H. sz. ügyben (Fővárosi Törvényszék 105.K.707.432/2020/17.)The entity was fined for processing scholarship applicants' personal data without a legal basis, including sensitive data. The authority also found that the data subjects were not adequately informed about the processing.HUNAIHGDPR€22,480
09 Dec 2020Ítélet a NAIH/2019/3633/10 sz. ügyben (Fővárosi Törvényszék 106.K.700.561/2019/16) - 2020. december 9.The case concerned a HUF 800,000 fine imposed by the NAIH for unlawful camera surveillance. The authority found that the processing breached GDPR principles of lawfulness, fairness, transparency, purpose limitation, and data minimization.HUNAIHGDPR€2,240
23 May 2019Ítélet a NAIH/2019/1189/11 sz. ügyben (Fővárosi Törvényszék 105.K.700.364/2019/11)The controller did not provide the requested personal data or information beyond a 2012 lease agreement. This breached the data subject’s access rights under the GDPR.HUNAIHGDPR€918
06 Oct 2023Ítélet a NAIH-19-18-2024 sz. ügyben (Kúria Kfv.IV.37.804/2025/2)The entity was fined for improper processing of personal data in a nationwide energy efficiency program. The authority found inadequate transparency and consent procedures, as well as insufficient data security measures.HUNAIHGDPR€194,000
12 Mar 2026ITAS MutuaITAS Mutua was fined EUR 50,000 by the Garante for failing to adequately respond to a former employee’s request for access to personal data. The authority found a breach of GDPR Article 15.ITGaranteGDPR€50,000
05 Oct 2017Italprest di Luca Bosimini & C. s.a.s.Italprest di Luca Bosimini & C. s.a.s. was fined €10,000 by the Garante. The authority found that the company failed to implement minimum security measures, including the use of passwords shorter than eight characters, in breach of Article 33 of the Italian Data Protection Code.ITGaranteGDPR€10,000
23 Jan 2008Italmarmo di Rossin EzioItalmarmo di Rossin Ezio was fined EUR 4,000 by the Garante for failing to provide timely access to personal data upon request. The case concerned non-compliance with data protection obligations.ITGaranteGDPR€4,000
15 Nov 2012Italiasalute s.r.l.Italiasalute s.r.l. was fined by the Garante EUR 10,400 for processing personal data on its website without providing data subjects with adequate information. The authority also found that consent was obtained in a non-compliant manner, particularly for profiling and marketing purposes.ITGaranteGDPR€10,400
22 Feb 2024Italiaonline S.p.A.Italiaonline S.p.A. was fined by the Garante 100,000 EUR for conducting direct email marketing campaigns without proper consent. The authority also found inadequate information about data processing activities shared with Google LLC.ITGaranteGDPR€100,000
13 Jul 2016Italian Lab s.r.l.Italian Lab s.r.l. was fined EUR 4,000 by the Garante. The case concerned the processing of personal data for a mailing list and newsletter without obtaining user consent.ITGaranteGDPR€4,000
18 Jan 2018Italia Consulenza e Formazione s.r.l.Italia Consulenza e Formazione s.r.l. was fined EUR 32,000 by the Garante for sending promotional emails without proper consent. The case concerns a breach of data protection rules governing direct marketing.ITGaranteGDPR€32,000
04 Dec 2014Itala s.p.aItala s.p.a was fined EUR 4,000 by the Garante for processing personal data related to job applications without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€4,000
07 Apr 2022ISWEB S.p.A.ISWEB S.p.A. was fined EUR 40,000 by the Italian supervisory authority, Garante. The authority found that the company failed to properly regulate its relationship with the hosting service provider in relation to data processing for Azienda ospedaliera di Perugia, in breach of Article 28 GDPR.ITGaranteGDPR€40,000