Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Mar 2018Azienda Sanitaria Locale Napoli 2 NordAzienda Sanitaria Locale Napoli 2 Nord was fined by the Garante for allowing personal data of registered users to be accessed and modified by anyone through its institutional website. The case concerned inadequate protection of personal data and non-compliance with data protection rules.ITGaranteGDPR€20,000
14 Mar 2019Comune di Porto Sant’ElpidioThe Garante fined Comune di Porto Sant’Elpidio EUR 10,000 for publishing documents on its website that contained personal data revealing the health status of individuals with disabilities. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
04 Jun 2025Istituto d’Istruzione Superiore “Carlo e Nello Rosselli”The Garante imposed a EUR 4,000 fine on Istituto d’Istruzione Superiore “Carlo e Nello Rosselli” for failing to appoint a Data Protection Officer and for delaying notification of the DPO’s contact details to the authority. The authority also found that transparency obligations toward data subjects were not met.ITGaranteGDPR€4,000
29 Apr 2021FederpolFederpol was fined 5,000 EUR by the Garante for improperly sharing members’ personal information with other associates. The authority found that this breached data protection rules and required a valid legal basis and appropriate safeguards.ITGaranteGDPR€5,000
30 Jan 2014Comune di Reggio Emilia – Comando Polizia municipaleThe Municipality of Reggio Emilia's Police Command was fined EUR 2,400 by the Garante for operating a video surveillance system without simplified information signage. The authority found a breach of Article 13 of the Privacy Code.ITGaranteGDPR€2,400
10 Mar 2016Ministero della giustizia – Dipartimento dell’amministrazione penitenziariaThe Ministry of Justice's Department of Penitentiary Administration was fined EUR 4,000 by the Garante for unlawful processing of personal data. The breach involved disclosing the names and details of prison police personnel who received overtime compensation.ITGaranteGDPR€4,000
31 May 2017Unit Contact s.r.l.Unit Contact s.r.l. was fined by the Garante EUR 10,000 for making unsolicited promotional calls to a number listed in the public opt-out register. The conduct breached data protection rules and telephone marketing requirements.ITGaranteGDPR€10,000
09 Mar 2017Moto One s.r.l.Moto One s.r.l. was fined by the Garante in the amount of 14,400 EUR for violations related to its video surveillance system. The authority found that recorded images were retained longer than permitted and that required informational signage was missing.ITGaranteGDPR€14,400
08 Jul 2015FNAC Italia s.r.l.FNAC Italia s.r.l. was fined €2,400 by the Garante. The authority found that the company did not provide data subjects with adequate information about the purpose of processing under its video surveillance system.ITGaranteGDPR€2,400
26 Oct 2023A.C. Group S.r.l.s.A.C. Group S.r.l.s. was fined by the Garante 10,000 EUR for making an unsolicited marketing call to a number listed in the Public Register of Objections without prior informed consent. The authority also found that the company failed to adequately respond to a data subject rights request.ITGaranteGDPR€10,000
20 Mar 2008Cid-Centro informazioni didatticoCid-Centro informazioni didattico was fined 3,000 EUR by the Garante for sending advertising material by fax without providing prior and adequate information to recipients. The conduct breached data protection rules.ITGaranteGDPR€3,000
08 Jul 2015Autotrasporti Multipli Arcese SpaAutotrasporti Multipli Arcese Spa was fined 12,000 EUR by the Garante for retaining surveillance footage longer than the period allowed under the authority's guidelines. The case concerns non-compliance with data protection rules on video retention.ITGaranteGDPR€12,000
21 Apr 2016Ditta individuale Fang WeiweiDitta individuale Fang Weiwei was fined 2,400 EUR by the Garante. The authority found that the video surveillance system was used without providing the information required under privacy rules.ITGaranteGDPR€2,400
17 Dec 2020Miropass S.r.l.Miropass S.r.l. was fined EUR 40,000 by the Italian supervisory authority Garante. The case concerned violations related to data processing activities.ITGaranteGDPR€40,000
26 May 2022Kalemci MusaThe sole proprietorship “Turkish City” was fined 2,000 EUR by the Garante. The authority found that its video surveillance system did not meet the information requirements under GDPR Article 13.ITGaranteGDPR€2,000
01 Aug 2012Spazio S s.r.l.Spazio S s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial emails. The authority found that the company failed to provide adequate information and did not obtain valid consent from recipients, breaching privacy rules.ITGaranteGDPR€10,400
26 Jun 2008Contact point s.r.l.Contact point s.r.l. was fined 3,000 EUR by the Garante for violating data protection rules. The case concerned improper handling of personal data during opinion surveys.ITGaranteGDPR€3,000
11 Jul 2013Cowboys' Guest Ranch S.r.l.Cowboys' Guest Ranch S.r.l. was fined EUR 14,400 by the Garante for failing to provide the required privacy notice when collecting personal data through online forms, paper questionnaires, and dance competition registration forms. The breach concerned the obligation to inform data subjects about the processing of their personal data.ITGaranteGDPR€14,400
16 Dec 2009Campolongo Hospital s.p.a.Campolongo Hospital s.p.a. was fined by the Garante for collecting personal data through its website without providing users with the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
05 Oct 2017Qiu JunjieQiu Junjie was fined EUR 10,000 by the Garante for failing to protect video surveillance recordings with a password. The authority found this breached the minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€10,000