Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Feb 2026Provvedimento del 12 febbraio 2026 [10225084]The Garante fined a retail business for failing to provide adequate informational signage for its video surveillance system. The authority found a breach of data protection rules because individuals on the premises were not properly informed about the processing of their personal data.ITGaranteGDPR€2,000
15 Sept 2011XY s.r.l.XY s.r.l. was fined by the Garante in the amount of EUR 10,400 for sending an unsolicited promotional fax. The conduct breached data protection and marketing communication rules.ITGaranteGDPR€10,400
07 Apr 2022Rebirth s.r.l.Rebirth s.r.l. was fined by the Garante EUR 15,000 for operating a video surveillance system at “Caffè Antica Roma” in a manner that did not comply with data protection rules. The conduct breached the GDPR and provisions of the Italian Privacy Code.ITGaranteGDPR€15,000
09 Jul 2020Istituto Comprensivo Statale Crucoli TorrettaIstituto Comprensivo Statale Crucoli Torretta was fined EUR 2,000 by the Garante for unlawfully publishing a list of students on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€2,000
12 May 2016Auto 2000 s.p.a.Auto 2000 s.p.a. was fined by the Garante for collecting personal data through its website without providing users with the required information notice. The case concerned a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
26 Mar 2026Provvedimento del 26 marzo 2026 [10246060]The entity was fined for operating a video surveillance system without providing adequate informational signage. The authority found this to be a breach of GDPR Article 13 on the duty to inform data subjects.ITGaranteGDPR€2,000
27 Feb 2025Comune di SciaccaThe Garante fined Comune di Sciacca EUR 2,500 for violations related to the processing of personal data. The case concerned the communication of data to third parties without a proper legal basis.ITGaranteGDPR€2,500
06 Apr 2017Effepì Credit s.r.l.Effepì Credit s.r.l. was fined by the Garante in the amount of EUR 10,000 for inadequate security measures. The authority cited weak and outdated passwords as a breach of data protection rules.ITGaranteGDPR€10,000
27 Apr 2011Iniziative immobiliari s.p.a.Iniziative immobiliari s.p.a. was fined 20,000 EUR by the Garante. The authority found that the company collected personal data through a website form without providing adequate information and failed to appoint data processing personnel or implement minimum security measures.ITGaranteGDPR€20,000
15 Mar 2018Lombardia Informatica S.p.A.Lombardia Informatica S.p.A. was fined EUR 40,000 by the Garante for allowing unauthorized access to personal data through its portal. The case concerned a breach of data protection rules and indicated insufficient access controls.ITGaranteGDPR€40,000
11 Mar 2021Università degli Studi di Napoli Federico IIUniversità degli Studi di Napoli Federico II was fined by the Garante in the amount of 10,000 EUR for breaches of data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization in the processing of personal data.ITGaranteGDPR€10,000
04 Oct 2012Abbanoa s.p.a.Abbanoa s.p.a. was fined EUR 28,000 by the Garante for failing to provide the required privacy notice in its video surveillance systems. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€28,000
13 Feb 2025Thomas FeroDr Thomas Fero was fined by the Garante EUR 10,000 for sending patients electoral campaign emails without their consent. The authority found this to be a breach of GDPR rules on personal data processing.ITGaranteGDPR€10,000
24 Nov 2016Aurora Jonica soc. coop.Aurora Jonica soc. coop. was fined by the Garante 10,000 EUR for making an unsolicited promotional call. The phone number was registered in the public opt-out list, which breached data protection rules.ITGaranteGDPR€10,000
08 Jul 2015Chirco MicheleChirco Michele was fined for processing personal data through a video surveillance system without providing the required information notice to the data subjects. This constituted a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
28 Apr 2022Amiu s.p.a.Amiu s.p.a. was fined EUR 20,000 by the Italian supervisory authority, Garante. The case concerned breaches of lawfulness, fairness, transparency, and purpose limitation in the improper use of surveillance cameras in waste management services.ITGaranteGDPR€20,000
16 May 2018Telecom Italia S.p.A.Telecom Italia S.p.A. was fined by the Garante €800,000 for the unauthorized activation of numerous residential phone lines in a citizen's name. The case involved processing and disclosing personal data without a legal basis, as well as failing to notify data breaches.ITGaranteGDPR€800,000
06 Oct 2022Associazione Rescue Drones Network ODVAssociazione Rescue Drones Network ODV was fined by the Garante in the amount of 3,000 EUR for failing to comply with data access requests. The authority treated this as a breach of GDPR Article 5.ITGaranteGDPR€3,000
10 Jan 2013Consodata S.p.A.Consodata S.p.A. was fined by the Garante 400,000 EUR for violations linked to unsolicited telemarketing. The authority also found that the company failed to provide individuals with proper data protection information.ITGaranteGDPR€400,000
11 Apr 2024Innova Camera – Azienda speciale della Camera di commercio, industria, artigianato e agricoltura di RomaInnova Camera was fined by the Garante EUR 25,000 for inadequate data security measures. The breach resulted in personal data being accessed and published online following an SQL Injection attack.ITGaranteGDPR€25,000