Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jun 2021Aeroporto Guglielmo Marconi di Bologna S.p.a.Aeroporto Guglielmo Marconi di Bologna S.p.a. was fined by the Garante EUR 40,000 for violations related to the protection of whistleblower identities. The case indicates insufficient personal data safeguards in the handling of reports.ITGaranteGDPR€40,000
05 Jul 2018Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 800,000 by the Garante for making unsolicited promotional phone calls and sending SMS messages without proper consent. The authority found that these practices breached data protection rules.ITGaranteGDPR€800,000
08 Feb 2007Asl OristanoAsl Oristano was fined EUR 10,000 by the Garante for failing to notify the processing of personal data concerning health and sexual life. The breach concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
15 Dec 2022Eurosanità S.P.A.Eurosanità S.P.A. was fined by the Garante in the amount of 30,000 EUR for violations related to the processing of health data. The authority cited inadequate personal data protection measures.ITGaranteGDPR€30,000
30 Oct 2013Ye BiYe Bi was fined by the Garante EUR 2,400 for operating a video surveillance system at Bar Millennium without the required signage. The authority found a breach of privacy regulations.ITGaranteGDPR€2,400
05 Feb 2015Comune di MontagnarealeThe Garante fined Comune di Montagnareale 10,000 EUR for unlawfully publishing personal data revealing health status on its institutional website. The breach involved disclosure of sensitive data without an adequate legal basis or safeguards.ITGaranteGDPR€10,000
02 Jul 2015Ordinanza ingiunzione - 2 luglio 2015 [4337649]The condominium administrator did not respond to requests for information related to a data protection complaint. Garante imposed a fine of EUR 4,000 for violating data protection rules.ITGaranteGDPR€4,000
11 Jul 2013Slots R Us srlSlots R Us srl was fined EUR 6,000 by the Garante for failing to provide the required information notice for its video surveillance system. The case concerned non-compliance with data protection rules on informing individuals subject to CCTV monitoring.ITGaranteGDPR€6,000
21 Jul 2016Personal club s.r.l.Personal club s.r.l. was fined by the Garante in the amount of EUR 2,400 for failing to provide simplified information about the use of a video surveillance system. The breach concerned the data protection information duties applicable to such processing.ITGaranteGDPR€2,400
12 Nov 2015Capodarco Società Cooperativa Sociale IntegrataCapodarco Società Cooperativa Sociale Integrata was fined EUR 12,000 by the Garante for recording and listening to calls between call center operators and users. The authority found that the required information notice was not provided to worker members, in breach of data protection rules.ITGaranteGDPR€12,000
29 Apr 2026Istituto Comprensivo Statale MontelibrettiIstituto Comprensivo Statale Montelibretti was fined EUR 4,000 by the Garante for breaches of data protection rules in the processing of personal data on its institutional website. The authority cited failures to comply with lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€4,000
23 Feb 2017Sisal S.p.A.Sisal S.p.A. was fined by the Garante in the amount of EUR 20,000 for installing a geolocation system on smartphones provided to employees without proper compliance with data protection rules. The case concerned the processing of location data in an employment context and insufficient legal safeguards.ITGaranteGDPR€20,000
21 Apr 2016Comune di OttavianoComune di Ottaviano was fined for publishing individuals’ personal data on its website without a legal basis. The authority found this breached Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
29 Sept 2021Prefettura - Ufficio Territoriale del Governo di GenovaPrefettura - Ufficio Territoriale del Governo di Genova was fined by the Garante for publishing personal data on its institutional website. The conduct breached GDPR requirements on lawful processing and protection of personal data.ITGaranteGDPR€11,000
01 Jun 2023NH Italia S.p.A.NH Italia S.p.A. was fined EUR 200,000 by the Garante for failing to appoint specific data processors responsible for the installation and maintenance of video surveillance systems. The authority found this breached the GDPR principles of lawful, fair, and transparent processing of personal data.ITGaranteGDPR€200,000
14 Sept 2023Nimbus s.r.l.Nimbus s.r.l. was fined by the Garante 5,000 EUR for using a fingerprint-based attendance system. The authority found that employees were not properly informed and that the required consent was not obtained.ITGaranteGDPR€5,000
12 Feb 2026Anconambiente S.P.A.Anconambiente S.P.A. was fined by the Garante for failing to ensure that personal data processing was lawful, fair, and transparent. The authority also found that the company did not have a proper contract with a data processor, as required by Article 28 GDPR.ITGaranteGDPR€2,500
16 Dec 20211000 Luci Round a BarThe establishment 1000 Luci Round a Bar was fined EUR 1,000 by the Italian authority Garante. The sanction concerned a video surveillance system that did not meet the information requirements of Article 13 GDPR.ITGaranteGDPR€1,000
29 Sept 2021Comune di FormiaComune di Formia was fined for processing personal data linked to parking subscription services without providing adequate information to data subjects. The authority also found excessive data collection and a failure to clearly define the role of the external data processor.ITGaranteGDPR€30,000
18 May 2016Accademia Dante Alighieri s.r.l.Accademia Dante Alighieri s.r.l. was fined by the Garante 2,400 EUR for collecting personal data from users through its websites without providing the required information or obtaining consent. The conduct breached Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€2,400