Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Dec 2019Eni Gas e Luce S.p.A.Eni Gas e Luce S.p.A. was fined EUR 8,500,000 by the Garante for making unsolicited telemarketing calls without consent. The conduct also affected individuals who had opted out or were listed in the public opposition register.ITGaranteGDPR€8,500,000
12 Sept 2024Sky Italia S.r.l.Sky Italia S.r.l. was fined EUR 842,062 by the Garante for telemarketing violations. The authority found that the company contacted individuals without proper consent and failed to consult the Public Register of Objections before promotional campaigns.ITGaranteGDPR€842,000
02 Nov 2024Intesa SanpaoloThe Italian Data Protection Authority fined Intesa Sanpaolo €31.8 million for a data breach involving unauthorized access to banking information of more than 3,500 clients. The authority also found that the bank detected the activity late and filed an incomplete and delayed breach notification.ITGarante per la protezione dei dati personaliGDPR€31,800
15 Dec 2016Stireria Rosa di HU XINStireria Rosa di HU XIN was fined 2,400 EUR by the Garante. The authority found that the company failed to inform data subjects about the processing of personal data through a video surveillance system covering public areas.ITGaranteGDPR€2,400
18 Feb 2016Europa Investigazioni s.r.lEuropa Investigazioni s.r.l was fined EUR 8,000 by the Garante. The authority found that the company failed to notify the processing of data indicating the geographical position of individuals or objects via an electronic communications network.ITGaranteGDPR€8,000
13 Feb 2025D.e.c. soc. coop.The Garante imposed a EUR 20,000 fine on D.e.c. soc. coop. for failing to deactivate an ex-employee's email account after the employment ended. The authority found this conduct breached GDPR principles of fair and transparent processing of personal data.ITGaranteGDPR€20,000
22 Jun 2016Società Territorio Turismo & Sport s.r.l.Società Territorio Turismo & Sport s.r.l. was fined by the Garante 2,400 EUR. The case concerned collecting personal data, including name and email, via its website without providing users with the required information notice.ITGaranteGDPR€2,400
01 Dec 2016L'ABBONDANZA s.r.l.L'ABBONDANZA s.r.l. was fined 2,400 EUR by the Garante. The authority found that the company failed to provide data subjects with information about the processing of personal data through a video surveillance system.ITGaranteGDPR€2,400
05 Jun 2014Ing. Claudio ZiniThe individual enterprise of Ing. Claudio Zini was fined for sending unsolicited promotional emails. The authority also found that the required information notice under Article 13 of the Italian Privacy Code was not provided.ITGaranteGDPR€2,400
21 Apr 2016Estracom s.p.a.Estracom s.p.a. was fined EUR 20,000 by the Garante for retaining customers’ call data for more than thirty days. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
20 Oct 2022Policlinico Casilino di RomaPoliclinico Casilino di Roma was fined by the Garante for violations related to the handling of personal data in the healthcare sector. The case concerned improper processing of patient data and privacy compliance requirements.ITGaranteGDPR€15,000
02 Dec 2021Omnia 24 S.r.l.Omnia 24 S.r.l. was fined EUR 100,000 by the Garante for sending unsolicited promotional SMS messages without proper consent. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€100,000
05 Nov 2015Romagna Giochi srlRomagna Giochi srl was fined EUR 4,800 by the Italian Garante. The authority found that the company failed to provide adequate notice about video surveillance at its premises, breaching data protection rules.ITGaranteGDPR€4,800
15 Mar 2018S.P. Selezione Personale s.r.l.S.P. Selezione Personale s.r.l. was fined by the Garante in the amount of EUR 20,000 for violations related to the processing of personal data in head hunting and recruitment activities. The case concerned irregularities in the handling of candidate data.ITGaranteGDPR€20,000
10 Jul 2025Outly di Veneziani & Co s.r.l.The Garante fined Outly di Veneziani & Co s.r.l. EUR 15,000 for insufficient transparency when obtaining consent and for inadequate information on data retention periods. The issues affected all interested parties and potential customers.ITGaranteGDPR€15,000
22 Feb 2024Comune di MonterotondoThe Garante imposed a EUR 3,000 fine on Comune di Monterotondo for breaches involving data processing agreements and security measures. The case also involved improper use of video surveillance. The authority found that the controller did not meet data protection requirements.ITGaranteGDPR€3,000
11 Feb 2021Ministero dello Sviluppo EconomicoThe Ministry of Economic Development was fined by the Garante for publishing personal data, including managers' CVs, on its institutional website without a proper legal basis. The authority found this conduct to be in breach of GDPR requirements.ITGaranteGDPR€75,000
01 Mar 2018Comune di San Mango PiemonteComune di San Mango Piemonte was fined for unlawfully using a biometric system based on fingerprint processing to record employee attendance. The authority found that this processing breached data protection rules.ITGaranteGDPR€30,000
02 Apr 2015Provincia di TriesteProvincia di Trieste was fined for publishing personal data on its institutional website without a legal basis. This breached Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
31 Aug 2023Ordine degli Avvocati di XXThe Garante fined the Ordine degli Avvocati di XX EUR 8,000 for unlawfully disclosing personal data without a legal basis. The authority found breaches of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€8,000