Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 May 2015Lucchese FrancoLucchese Franco was fined by the Garante EUR 12,000 for retaining surveillance footage beyond the legally prescribed period. The case concerned non-compliance with data protection retention rules.ITGaranteGDPR€12,000
12 Feb 2026Based s.r.l.Based s.r.l. was fined by the Garante EUR 12,000 for providing an inadequate response to a data subject’s request for access to and deletion of email account data. The authority found that the company failed to comply with GDPR requirements on data subject rights.ITGaranteGDPR€12,000
26 Feb 2026Ministero dell’Economia e delle FinanzeThe Ministry of Economy and Finance was fined 12,000 EUR by Garante for inadequate control measures over the data processor. The authority found breaches of GDPR Articles 3, 5 and 6, as well as Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€12,000
14 Apr 2011Mansutti S.p.A.Mansutti S.p.A. was fined EUR 12,000 by the Garante for failing to provide the required data protection notice on its website forms. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€12,000
29 Jan 2026Provincia della Congregazione dei Fratelli delle Suore CristianeThe entity was fined for failing to ensure sufficient transparency in data processing and for not carrying out a data protection impact assessment for workplace surveillance systems. The authority found breaches of the GDPR and the national privacy code.ITGaranteGDPR€12,000
24 Feb 2011Federconsorzi Dolomiti SuperskiFederconsorzi Dolomiti Superski was fined EUR 12,000 by the Italian Garante. The authority found that the company failed to provide the required data protection information to individuals, in breach of Articles 13 and 161 of the Italian Data Protection Code.ITGaranteGDPR€12,000
11 Sept 2025Casa di Cura Città di RomaCasa di Cura Città di Roma was fined EUR 12,000 by the Garante for allowing unauthorized access to patient medical records. The case concerns a breach of data protection rules and indicates a need for stronger access controls.ITGaranteGDPR€12,000
21 Oct 2010Palmeto s.r.l.Palmeto s.r.l. was fined EUR 12,000 by the Italian supervisory authority, Garante. The case concerned failure to provide the required data protection information to individuals in connection with video surveillance and personal data collection via the company website.ITGaranteGDPR€12,000
31 Jan 2019CT BARCT BAR was fined by the Garante for unlawful processing of personal data through its video surveillance system. The recordings were retained for 15 days without proper compliance with applicable rules.ITGaranteGDPR€12,000
18 Jun 2015Comune di MurosComune di Muros was fined EUR 12,000 by the Garante. The authority found that the municipality failed to provide information and unlawfully published personal data revealing health status on its website.ITGaranteGDPR€12,000
12 Feb 2015Visini FabioVisini Fabio was fined EUR 12,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection requirements.ITGaranteGDPR€12,000
15 Jan 2015Barta s.r.l.Barta s.r.l. was fined by the Garante EUR 12,000 for operating a video surveillance system without prior authorization. Footage was retained for 15 days, exceeding the permitted one-week period.ITGaranteGDPR€12,000
30 Oct 2013Regione LazioRegione Lazio was fined EUR 12,000 by the Garante for collecting personal data through web forms without providing adequate information to data subjects. The authority found this to be a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€12,000
12 Nov 2015Capodarco Società Cooperativa Sociale IntegrataCapodarco Società Cooperativa Sociale Integrata was fined EUR 12,000 by the Garante for recording and listening to calls between call center operators and users. The authority found that the required information notice was not provided to worker members, in breach of data protection rules.ITGaranteGDPR€12,000
08 Jul 2015Autotrasporti Multipli Arcese SpaAutotrasporti Multipli Arcese Spa was fined 12,000 EUR by the Garante for retaining surveillance footage longer than the period allowed under the authority's guidelines. The case concerns non-compliance with data protection rules on video retention.ITGaranteGDPR€12,000
16 Dec 2025Anonymisé (CNPD decision-07-fr-2025)The entity did not maintain a complete and accurate record of processing activities, as required by Article 30 GDPR. CNPD imposed an administrative fine of EUR 12,010.LUCNPDGDPR€12,010
12 Nov 2015Supermercato Centro Storico srlSupermercato Centro Storico srl was fined €12,400 by the Garante for inadequate data protection measures linked to its video surveillance system. The authority found that the required informational signage was missing, in breach of data protection rules.ITGaranteGDPR€12,400
12 Jun 2014Poligrafici Editoriale s.p.a.Poligrafici Editoriale s.p.a. was fined by the Garante 12,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority also found improper collection of personal data through subscription coupons.ITGaranteGDPR€12,400
30 Oct 2013Continental Terme srlContinental Terme srl was fined EUR 12,400 by the Garante for providing inadequate privacy notices and obtaining a single consent for multiple data processing activities. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€12,400
11 Jul 2018CAA Liberi professionisti s.r.l.CAA Liberi professionisti s.r.l. was fined by the Garante in the amount of 12,400 EUR for failing to properly designate and instruct personnel involved in data processing. The authority found this to be a breach of data protection rules.ITGaranteGDPR€12,400