Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Apr 2016Lin ShaochunLin Shaochun was fined EUR 2,400 by the Italian data protection authority, Garante. The authority found that the company failed to provide data subjects with adequate information about video surveillance, in breach of privacy rules.ITGaranteGDPR€2,400
17 Dec 2015Maurizio De AngelisMaurizio De Angelis was fined for providing inadequate data protection information in a video surveillance system. The authority found a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
26 Oct 2017Verde Luna s.a.s. di Antonietta Minnicelli & C.Verde Luna s.a.s. was fined EUR 20,000 by the Garante. The sanction concerned the company’s failure to provide information requested by the supervisory authority in a data protection matter.ITGaranteGDPR€20,000
16 Jan 2026Azienda Ospedaliera S. Pio di BeneventoAzienda Ospedaliera S. Pio di Benevento was fined by the Garante EUR 6,000 for violations related to the processing of personal data. The case concerned special categories of data and disclosure to third parties.ITGaranteGDPR€6,000
26 Nov 2020Charly Mike s.r.l.Charly Mike s.r.l. was fined by the Garante EUR 3,000 for improper use of a video surveillance system at Hotel Olimpo. The system was used for continuous monitoring and remote viewing of employees, in breach of data protection rules.ITGaranteGDPR€3,000
05 Jul 2017Vodafone Omnitel N.V.Vodafone Omnitel N.V. was fined by the Italian data protection authority, Garante, in the amount of 40,000 EUR. The sanction concerned the use of a group authentication credential to access personal data, which breached the security measures required under the Italian Data Protection Code.ITGaranteGDPR€40,000
09 Jul 2020Merlini s.r.l.Merlini s.r.l. was fined 200,000 EUR by the Garante. The authority found that the collection of potential clients' personal data did not comply with GDPR consent requirements and that call-center activities were carried out outside the telemarketing procedures established by Wind Tre.ITGaranteGDPR€200,000
31 Aug 2023Robin S.r.l.The Garante fined Robin S.r.l. 25,000 EUR for publishing a photograph of minors with insufficient anonymization. The case concerns a breach of personal data protection rules applicable to children.ITGaranteGDPR€25,000
12 Feb 2015Enel Energia S.p.a.Enel Energia S.p.a. was fined by the Garante 200,000 EUR for failing to provide information and obtain consent for processing personal data for promotional purposes. The breach affected a large database of approximately 43.1 million contacts.ITGaranteGDPR€200,000
02 Dec 2021Azienda USL di ParmaAzienda USL di Parma was fined by the Garante for a data breach involving the unauthorized disclosure of health data. The incident affected one individual and did not result in significant harm, but it was still treated as a GDPR violation.ITGaranteGDPR€5,000
15 Dec 2022Comune di VicchioComune di Vicchio was fined by the Garante 8,000 EUR for using fingerprints to monitor employee attendance without appropriate legal basis and safeguards. The authority found that the biometric processing breached GDPR requirements.ITGaranteGDPR€8,000
26 Oct 2023Azienda Sanitaria Locale TO3Azienda Sanitaria Locale TO3 was fined by the Garante for a health data breach affecting four individuals. The incident lasted nine days and was deemed negligent.ITGaranteGDPR€6,000
12 Dec 2024Comune di PorticiThe Garante fined Comune di Portici EUR 6,000 for breaches of data protection principles, including lawfulness, fairness, and transparency. The authority also found that the municipality failed to carry out a data protection impact assessment before processing personal data through video surveillance.ITGaranteGDPR€6,000
23 May 2024Associazione Medica Chirone s.c.r.l.The Garante fined Associazione Medica Chirone s.c.r.l. 5,000 EUR for improperly accessing and using an employee's vaccination status data. The authority found that the data were not properly anonymized, resulting in a breach of data protection rules.ITGaranteGDPR€5,000
20 Jun 2024TS Food Processing S.r.l.TS Food Processing S.r.l. was fined by the Garante for refusing an employee's request to access personal data related to employment. The authority found a breach of GDPR Article 15.ITGaranteGDPR€10,000
13 Mar 2025Casatua S.r.l.Casatua S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited communications via WhatsApp without obtaining proper recipient consent. The company also failed to implement adequate procedures to ensure compliance with data protection rules.ITGaranteGDPR€10,000
27 Jun 2013Comune di PadovaComune di Padova was fined by the Garante 10,000 EUR for unlawfully publishing personal data online beyond the legally permitted period. The authority found this to be a breach of data protection rules.ITGaranteGDPR€10,000
04 Jun 2025Comune di RoccaforzataComune di Roccaforzata was fined EUR 8,000 by the Garante for publishing sensitive health data, including an employee’s disability percentage, in a council resolution. The authority found a breach of the GDPR and national privacy code provisions.ITGaranteGDPR€8,000
22 May 2014Colligo s.r.lColligo s.r.l was fined EUR 40,000 by the Garante for making promotional phone calls while disguising or hiding the caller's identity. The authority found this conduct breached the Italian Data Protection Code.ITGaranteGDPR€40,000
13 Apr 2023Comune di Cogollo del CengioThe Garante fined Comune di Cogollo del Cengio EUR 3,000 for breaches of GDPR Articles 5, 6 and 9, as well as Articles 2-ter and 2-septies of the Italian Privacy Code. The case concerned the processing of an employee’s personal data without an adequate legal basis and in breach of data protection rules.ITGaranteGDPR€3,000