Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Feb 2024Sigma s.r.l.Sigma s.r.l. was fined EUR 150,000 by the Garante for unauthorized activation of paid services and devices using customer data without consent. The authority found that the company’s conduct breached GDPR rules on personal data processing.ITGaranteGDPR€150,000
17 Oct 2024ComuneThe Garante fined Comune EUR 8,000 for breaches of GDPR Articles 5, 6 and 9, and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data in the context of public employment and administrative transparency.ITGaranteGDPR€8,000
25 Sept 2025E-Power S.r.l.E-Power S.r.l. was fined EUR 35,000 by the Garante for making promotional calls without a valid legal basis. The authority also found that the company failed to respond to data subject rights requests, which breaches GDPR requirements.ITGaranteGDPR€35,000
27 Nov 2024Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 20,000 EUR for publishing employees’ personal data without a legal basis. The disclosure included details on additional payments, sickness absences, and union rights, breaching the GDPR and the national privacy code.ITGaranteGDPR€20,000
26 Jun 2008Contact point s.r.l.Contact point s.r.l. was fined by the Garante 10,000 EUR for breaching data protection rules. The case concerned improper handling of personal data during opinion surveys.ITGaranteGDPR€10,000
13 Feb 2014Roma CapitaleRoma Capitale was fined for unlawfully publishing personal data related to a disciplinary action on its institutional website. The authority found that this conduct violated Article 19 of the Italian Data Protection Code.ITGaranteGDPR€10,000
29 Apr 2026Azienda Sanitaria Locale di MateraAzienda Sanitaria Locale di Matera was fined by the Garante EUR 8,600 after a data breach caused by a ransomware attack. The incident led to the exfiltration of personal data, and the authority found inadequate technical and organizational measures to protect data security.ITGaranteGDPR€8,600
22 Feb 2018Comune di FiumicinoComune di Fiumicino was fined by the Garante for failing to notify a data breach within the required timeframe. The authority found a violation of the Italian Data Protection Code.ITGaranteGDPR€30,000
14 May 2026FeGi M&A Services s.r.l.FeGi M&A Services s.r.l. was fined EUR 1,000 by the Garante for making promotional phone calls without the required consent. The authority found this conduct breached GDPR principles of fairness and transparency.ITGaranteGDPR€1,000
08 Mar 2018Tekne Progetti s.r.l.Tekne Progetti s.r.l. was fined for failing to respond to an information request from the Garante concerning its data processing activities. The conduct was found to violate Article 164 of the Italian Privacy Code.ITGaranteGDPR€20,000
23 Jan 2008Italmarmo di Rossin EzioItalmarmo di Rossin Ezio was fined EUR 4,000 by the Garante for failing to provide timely access to personal data upon request. The case concerned non-compliance with data protection obligations.ITGaranteGDPR€4,000
22 Feb 2024L’Igiene Urbana Evolution s.r.l.L’Igiene Urbana Evolution s.r.l. was fined €70,000 by the Garante for unlawfully processing biometric data through facial recognition to monitor employee attendance. The authority found that this practice violated GDPR requirements.ITGaranteGDPR€70,000
11 Apr 2024Istituto Nazionale Previdenza Sociale - INPSThe Italian Data Protection Authority fined INPS EUR 20,000 for violating data protection principles. The case concerned the improper handling of candidates’ personal data in a public competition.ITGaranteGDPR€20,000
11 Jan 2023Società Europea di Edizioni S.p.a.The Garante fined Società Europea di Edizioni S.p.a. EUR 10,000 for publishing non-anonymized personal data concerning an individual's health status in an article. This constituted a breach of data protection rules.ITGaranteGDPR€10,000
17 Oct 2013Annamaria FazziniAnnamaria Fazzini was fined EUR 2,400 by the Garante for failing to provide the required privacy notice for a video surveillance system at her business. The case concerns non-compliance with the obligation to inform individuals about the processing of their personal data.ITGaranteGDPR€2,400
26 Oct 2011Smart s.n.c.Smart s.n.c. was fined EUR 12,800 by the Garante. The authority found that the company sent promotional emails without the recipients’ prior explicit consent.ITGaranteGDPR€12,800
05 Feb 2015Comune di MerìComune di Merì was fined EUR 10,000 by the Garante for unlawfully publishing sensitive personal data on its website. The disclosure included information about individuals' health status and mandatory medical treatments, breaching data protection rules.ITGaranteGDPR€10,000
18 Jun 2015Comune di MurosComune di Muros was fined EUR 12,000 by the Garante. The authority found that the municipality failed to provide information and unlawfully published personal data revealing health status on its website.ITGaranteGDPR€12,000
11 Mar 2010Impresa individuale Bellusci MirellaThe company was fined for processing personal data by receiving CVs from aspiring agents without providing the required privacy notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
26 Jul 2012Meeting s.r.l.Meeting s.r.l. was fined by the Garante in the amount of 6,000 EUR for providing inadequate information to clients. The case concerned a breach of Article 13 of the Italian Data Protection Code, which requires proper notice to data subjects.ITGaranteGDPR€6,000