Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Dec 2012Studio Immobiliare Conca D'Oro s.r.l.Studio Immobiliare Conca D'Oro s.r.l. was fined by the Garante 6,400 EUR for making promotional phone calls without providing the required information notice and without obtaining consent. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€6,400
05 Dec 2013Associazione culturale KoalaAssociazione culturale Koala was fined 30,000 EUR by the Italian Garante. The case concerned the installation of a fingerprint recognition system for user access without providing the required information to the supervisory authority.ITGaranteGDPR€30,000
21 Mar 2018Ordinanza ingiunzione - 21 marzo 2018 [9004702]The Garante imposed a EUR 92,000 fine on a medical professional for processing the personal data of 23 patients without the required consent. The authority found a breach of privacy and data protection rules.ITGaranteGDPR€92,000
14 Jan 2016Q.12 s.r.l.Q.12 s.r.l. was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice for its video surveillance system. The authority found a breach of the Italian Privacy Code.ITGaranteGDPR€2,400
23 Jan 2008Cubo società consulenza aziendale s.r.l.Cubo società consulenza aziendale s.r.l. was fined by the Garante 10,000 EUR for violating data protection rules. The case concerned the processing of personal data in the context of personnel search and selection activities.ITGaranteGDPR€10,000
11 Jan 2024dott. BagnatoA doctor was fined by the Garante for breaching privacy rules. The case involved improper handling of medical prescriptions outside the office, which could expose sensitive personal data.ITGaranteGDPR€20,000
29 Nov 2012Enterprise Work s.r.l.Enterprise Work s.r.l. was fined by the Garante in the amount of 41,600 EUR. The case concerned the sending of unsolicited promotional faxes without valid recipient consent.ITGaranteGDPR€41,600
10 Jul 2025Istituto Comprensivo 2 C.D.The Garante fined Istituto Comprensivo 2 C.D. EUR 4,000 for breaches of data protection rules. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency in the processing of personal data.ITGaranteGDPR€4,000
01 Feb 2018Provincia di BeneventoProvincia di Benevento was fined by the Garante for unlawfully publishing special-category personal data on its website, including health information and tax codes. The authority found a breach of data protection rules.ITGaranteGDPR€60,000
04 Apr 2007Asl Brindisi 1The Garante fined Asl Brindisi 1 for failing to notify the processing of personal data under the Italian Data Protection Code. Article 37 was violated, and the fine amounted to EUR 20,000.ITGaranteGDPR€20,000
05 Sept 2013Stefano EvangelistaStefano Evangelista was fined by the Garante 2,400 EUR for failing to provide the required privacy notice for a video surveillance system at his business, Pizzeria del Borgo. The case concerned a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
25 Mar 2021Convitto Nazionale Statale "Giordano Bruno"Convitto Nazionale Statale "Giordano Bruno" was fined by the Garante for breaching data protection principles. The authority found that personal data had been made available online for an extended period, contrary to the principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€1,000
24 Jun 2010Enterprise Group s.r.l.Enterprise Group s.r.l. was fined EUR 238,000 by the Garante. The authority found that the company failed to provide timely information to data subjects and sent unsolicited marketing communications without prior consent.ITGaranteGDPR€238,000
18 Jan 2018KRI S.p.A.KRI S.p.A. was fined by the Italian data protection authority, Garante, for failing to notify the cessation of certain personal data processing activities. The case involved geolocation data and profiling, and the required notification was not made under the Italian data protection code.ITGaranteGDPR€180,000
18 Apr 2013Mida S.a.s.Mida S.a.s. was fined by the Italian Garante 2,400 EUR for an inadequate privacy notice relating to its video surveillance system. The notice did not include the data controller’s information, which failed to meet the required transparency obligations.ITGaranteGDPR€2,400
19 May 2011Limbiati oreficeria orologeria ottica s.n.c. di L. Limbiati & C.Limbiati oreficeria orologeria ottica s.n.c. was fined by the Garante for collecting personal data through its website without providing adequate information or obtaining the required consent. The authority found this to be a breach of the Italian Privacy Code.ITGaranteGDPR€9,000
25 Sept 2025Provincia Autonoma di TrentoProvincia Autonoma di Trento was fined for processing personal data without a legal basis, lacking transparency, and failing to conduct a data protection impact assessment. The authority found breaches of several GDPR provisions.ITGaranteGDPR€8,000
14 Sept 2023Azienda Sanitaria dell'Alto Adige - Suedtiroler SanitaetsbetriebThe Garante fined Azienda Sanitaria dell'Alto Adige EUR 10,000 for failing to provide an adequate response to a data subject's rights request. The case also concerned the processing of sensitive data related to vaccination status.ITGaranteGDPR€10,000
13 Mar 2014Puglia Service s.r.l.Puglia Service s.r.l. was fined by the Garante €10,000 for making unsolicited promotional phone calls. The conduct violated the right of opposition of a subscriber registered in the public opt-out list.ITGaranteGDPR€10,000
21 Jun 2018Comune di PozzalloComune di Pozzallo was fined for publishing personal and judicial data online without a valid legal basis. It also failed to respond to information requests from the Garante.ITGaranteGDPR€8,000