Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Dec 2016Planetel s.r.l.Planetel s.r.l. was fined by the Garante in the amount of EUR 30,000 for using inadequate authentication procedures to access telecommunication traffic data. The authority also found that required security measures for data storage were not implemented.ITGaranteGDPR€30,000
18 Dec 2025Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi s.r.l. was fined by the Garante 120,000 EUR for installing telematic devices in company vehicles to monitor employees' driving behavior. The authority found that the processing lacked proper data protection safeguards and privacy information.ITGaranteGDPR€120,000
13 Sept 2007Azienda sanitaria locale di Lanciano/VastoAzienda sanitaria locale di Lanciano/Vasto was fined by the Garante 10,000 EUR for improper handling of sensitive personal data. The case involved genetic and biometric data processed without proper authorization.ITGaranteGDPR€10,000
04 Jul 2013Comune di CiampinoThe Municipality of Ciampino was fined EUR 4,000 by the Garante for publishing on its website a list containing personal data of individuals eligible to serve as polling station scrutineers. The publication was made without an appropriate legal basis.ITGaranteGDPR€4,000
17 Oct 2024Immobiliare Pianezza S.r.l.s.Immobiliare Pianezza S.r.l.s. was fined €5,000 by the Garante for making unsolicited marketing calls without consent. The authority also noted a failure to respond to requests for deletion of personal data.ITGaranteGDPR€5,000
14 May 2026Energia Sostenibile S.r.l.Energia Sostenibile S.r.l. was fined EUR 100,000 by the Garante for making unsolicited calls to numbers listed in the Public Opposition Register. The authority also found that the company did not adequately respond to data subjects’ requests to exercise their rights.ITGaranteGDPR€100,000
15 Nov 2012Gruppo Ro.Ri s.r.l.Gruppo Ro.Ri s.r.l. was fined by the Garante for failing to notify the cessation of data processing after the merger of Casa di cura S. Teresa del Bambin Gesù s.r.l. The authority found a breach of Article 38 of the Italian Data Protection Code.ITGaranteGDPR€25,000
07 Mar 2019Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined for unlawfully processing judicial data by communicating information about an ongoing criminal proceeding without a legal basis. The case concerned a breach of the rules governing the lawful processing of sensitive data.ITGaranteGDPR€10,000
06 Jul 2023Ad Maiora Distribuzioni S.a.s. di Editrice Ad Maiora S.r.l.s. & C.Ad Maiora Distribuzioni was fined EUR 15,000 by the Garante. The authority found that the company made unsolicited promotional calls and failed to respond to requests for access to and deletion of personal data.ITGaranteGDPR€15,000
20 Jul 2017Aria S.p.a.Aria S.p.a. was fined 20,000 EUR by the Garante. The authority found a data protection breach for failing to designate employees as data processors.ITGaranteGDPR€20,000
23 Jul 2015Art Sposa s.r.l.Art Sposa s.r.l. was fined by the Garante in the amount of EUR 2,400 for failing to provide the required privacy notice to users submitting personal data through its website contact form. The conduct breached Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
05 Feb 2015Azienda Regionale per il diritto allo studio universitario della ToscanaAzienda Regionale per il diritto allo studio universitario della Toscana was fined EUR 10,000 by the Garante. The authority found that its website unlawfully disclosed personal data revealing the health status of students with disabilities.ITGaranteGDPR€10,000
06 Dec 2011Tiscali Italia SpATiscali Italia SpA was fined €420,000 by the Garante for retaining customer traffic data beyond the legal retention period. The authority also found that Amdocs accessed the data without being properly designated as a data processor or obtaining customer consent.ITGaranteGDPR€420,000
26 Oct 2023Provvedimento del 26 ottobre 2023 [9960920]The Garante imposed a EUR 1,000 fine on a condominium administrator for installing a video surveillance system without a proper legal basis or assembly resolution. The conduct was found to breach GDPR rules on lawful processing.ITGaranteGDPR€1,000
29 Apr 2025Regione LombardiaThe Garante fined Regione Lombardia 50,000 EUR for violations related to the processing of personal data. The authority cited inadequate technical and organizational measures to protect data, as well as improper handling of employee metadata and internet navigation logs.ITGaranteGDPR€50,000
26 Oct 2011Remida srlRemida srl was fined EUR 22,400 by the Garante for installing a surveillance camera in a condominium without providing adequate information. The authority found this to be a breach of data protection rules.ITGaranteGDPR€22,400
21 Mar 2018Società agricola Medici Claudio s.r.l.The company was fined for failing to comply with data protection obligations. The breach concerned not providing personal data and information related to employment management when requested by the Garante.ITGaranteGDPR€10,000
27 Apr 2023Università degli studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined EUR 4,000 by the Garante for improperly disclosing a complainant’s personal data to all Italian universities. The disclosure also included data relating to criminal offenses, breaching GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
29 Apr 2025Ordine professionale degli psicologi della LombardiaOn 2025-04-29, the Italian Data Protection Authority fined the Ordine professionale degli psicologi della Lombardia EUR 30,000. The sanction concerned breaches of Articles 5(1)(f) and 32 GDPR following a data breach and the failure to implement adequate security measures.ITGarante per la protezione dei dati personaliGDPR€30,000
24 Nov 2022Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di CagliariOrdine dei Medici Chirurghi e degli Odontoiatri della Provincia di Cagliari was fined €3,000 by the Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization in the handling of personal data related to an individual's employment.ITGaranteGDPR€3,000