Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Mar 2023Banca Cambiano 1884 S.p.A.Banca Cambiano 1884 S.p.A. was fined by the Garante 10,000 EUR for failing to respond within the required timeframe to a data subject's request for access to personal data. The authority found a breach of GDPR Articles 15 and 12.ITGaranteGDPR€10,000
16 May 2018Greco LuigiGreco Luigi, a general practitioner, was fined for failing to implement minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
17 May 2023Azienda ULSS 6 EuganeaThe Garante fined Azienda ULSS 6 Euganea 10,000 EUR for the incorrect handling of health-related documents. The authority found breaches of GDPR Articles 5, 6, and 32.ITGaranteGDPR€10,000
14 Sept 2006Asl VercelliAsl Vercelli was fined by the Garante for processing special-category personal data, including genetic and health data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
11 Feb 2021Arma dei carabinieriArma dei carabinieri was fined by the Garante for improperly handling sensitive and judicial data without adequate safeguards against unauthorized access. The authority found breaches of the GDPR and the Italian Privacy Code.ITGaranteGDPR€10,000
16 Apr 2015Web performance s.r.l.Web performance s.r.l. was fined by the Garante for collecting personal data through website forms without proper consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€10,000
19 Mar 2025XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited SMS advertisements to a number registered on the Robinson List. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€10,000
13 Nov 2024Spinacqua S.r.l.Spinacqua S.r.l. was fined by the Garante €10,000 for making unsolicited promotional calls to a number listed in the Public Opposition Register. The company did not obtain consent and failed to verify the number’s registration status before contacting it.ITGaranteGDPR€10,000
10 Jul 2025Asilo nido “La Combricola Dei Birichini Di Betty”The Garante imposed a 10,000 EUR fine on the nursery for failing to provide parents with the required information about the processing of children's images. It also found that no data protection impact assessment had been carried out for the surveillance system.ITGaranteGDPR€10,000
26 Feb 2021PINTODIS, S.L.PINTODIS, S.L. was fined by the AEPD for installing surveillance cameras that recorded employees in private areas without sufficient justification. The authority found this to be a breach of data protection principles.ESAEPDGDPR€10,000
26 Jun 2020ESLORA PROYECTOS, S.L.ESLORA PROYECTOS, S.L. was fined by the AEPD 10,000 EUR for failing to provide cookie information and for not obtaining user consent before using cookies. The authority cited a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€10,000
23 Apr 2015Comune di AostaComune di Aosta was fined for publishing personal data that revealed health information on its website. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€10,000
26 Sept 2024Comune di VeronaThe Garante fined Comune di Verona €10,000 for violations of GDPR Articles 5, 6 and 9, as well as Article 2-ter of the Italian Privacy Code. The case concerned the processing of personal data in a manner not compliant with legal requirements.ITGaranteGDPR€10,000
23 Oct 2024Profi Rom Food SrlProfi Rom Food Srl was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€10,000
24 Jan 2013Evolution chirurgia estetica s.r.l.Evolution chirurgia estetica s.r.l. was fined 10,000 EUR by the Garante. The authority found that the website contact form required mandatory acceptance of the privacy notice, which breached consent requirements under the Italian privacy code.ITGaranteGDPR€10,000
21 Oct 2022IPM Group NVThe case concerned the use of cookies on the L'Avenir website operated by IPM Group NV. A settlement was reached under which the company agreed to pay 10,000 EUR to the Belgian treasury.BEAPDePrivacy€10,000
18 Mar 2010Alma s.r.l.Alma s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 10,000 EUR. The case concerned the processing of personal data without the notification required under the Italian Data Protection Code.ITGaranteGDPR€10,000
01 Jun 2023Provvedimento del 1° giugno 2023 [9909889]The Garante imposed a 10,000 EUR fine on a healthcare center for incorrectly sending automatic SMS reminders to a patient due to a data misattribution error. The case concerned GDPR provisions on data processing and security.ITGaranteGDPR€10,000
27 Jan 2021Roma CapitaleRoma Capitale was fined EUR 10,000 by the Garante for publishing the personal data of a minor and the minor’s mother on its official website without a proper legal basis. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€10,000
30 Jan 2024HUELLAS AVENTURA, S.L.The company was fined by the AEPD for tying consent for a school trip service to acceptance of data protection policies and commercial communications. The authority also found that users were not given an option to object to the processing of minors' images.ESAEPDGDPR€10,000