Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Mar 2019Enel Energia s.p.a.Enel Energia s.p.a. was fined by the Garante EUR 80,000 for failing to implement adequate security measures. This allowed unauthorized access and massive data downloads by a third-party company using credentials of former employees.ITGaranteGDPR€80,000
30 Oct 2014Giacomo Michele Maria GrassoGiacomo Michele Maria Grasso was fined for failing to provide data subjects with the required information about video surveillance at his establishment. The conduct breached Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
22 Jan 2015Comune di TroinaComune di Troina was fined 4,000 EUR by the Garante for unlawfully disclosing personal data to the complainant’s sister without a legal basis. The authority found a breach of data protection rules.ITGaranteGDPR€4,000
11 Sept 2014Liliana ImbrogianoLiliana Imbrogiano was fined by the Italian Garante for failing to provide adequate simplified information about the use of a video surveillance system. The authority found a breach of privacy regulations.ITGaranteGDPR€2,400
11 Apr 2013PLD srlPLD srl was fined €100,000 by the Italian Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information.ITGaranteGDPR€100,000
29 Sept 2021Solera Italia s.r.l.Solera Italia s.r.l. was fined EUR 10,000 by the Garante for continuing to use an employee's email account after the employment ended. The authority found that the company did not provide proper information about this processing.ITGaranteGDPR€10,000
19 May 2010Roadhouse Grill Italia s.r.l.Roadhouse Grill Italia s.r.l. was fined 6,000 EUR by the Garante for failing to provide proper data protection notices to individuals through signage for its video surveillance system. The authority found a breach of data protection rules.ITGaranteGDPR€6,000
16 May 2018Paesano FrancescoPaesano Francesco was fined EUR 60,000 by the Garante for activating six phone cards without the consent of the individuals concerned. The case concerns a breach of data protection rules and the absence of a valid legal basis for processing.ITGaranteGDPR€60,000
08 Mar 2018Yahoo! Emea Limited oggi Oath (Emea) LimitedYahoo! Emea Limited, now Oath (Emea) Limited, was fined 160,000 EUR by the Garante. The authority found that the company failed to comply with a request to remove specific URLs containing personal information from Yahoo! Search.ITGaranteGDPR€160,000
09 Nov 2017Società Alberghi Circeo s.r.l.Società Alberghi Circeo s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company failed to appoint data processing officers for employees handling personal data, in breach of Article 33 of the Italian Data Protection Code.ITGaranteGDPR€10,000
16 Feb 2011Athena Research s.r.l.Athena Research s.r.l. was fined 6,000 EUR by the Garante for sending unsolicited commercial faxes without the recipients' explicit consent. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code.ITGaranteGDPR€6,000
23 Mar 2023Azienda 1 di SassariThe Garante imposed a fine of 4,000 EUR on Azienda 1 di Sassari for violations related to the processing of personal data, including health data. The authority found that adequate security measures were not in place for this processing.ITGaranteGDPR€4,000
10 Apr 2025Unione Montana Appennino Parma EstUnione Montana Appennino Parma Est was fined by the Italian supervisory authority, Garante, in the amount of EUR 8,000. The authority found a lack of required transparency in data processing and failure to carry out a data protection impact assessment for workplace video surveillance.ITGaranteGDPR€8,000
05 Mar 2015Comune di Acquarica del CapoThe Municipality of Acquarica del Capo was fined 10,000 EUR by the Garante for unlawfully publishing personal data revealing health information on its website. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€10,000
28 Apr 2022Società Ospedale San Raffaele s.r.l.The Garante fined Società Ospedale San Raffaele s.r.l. EUR 70,000 for making online medical reports accessible to other patients. The case involved a breach of personal data protection and confidentiality of health information.ITGaranteGDPR€70,000
19 Nov 2017Superbeton S.p.a.Superbeton S.p.a. was fined 20,000 EUR by the Garante for failing to properly notify the use of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations.ITGaranteGDPR€20,000
17 Nov 2010Azienda trasporti di MessinaAzienda trasporti di Messina was fined 20,000 EUR by the Garante for processing sensitive personal data without providing the required information notice and without obtaining consent from the data subjects. The case concerns breaches of core transparency and lawful-processing obligations.ITGaranteGDPR€20,000
07 May 2015Provincia di FrosinoneProvincia di Frosinone was fined for failing to update the Security Policy Document (DPS) for several years. The authority found this to be a breach of security measures required under the Italian Data Protection Code.ITGaranteGDPR€10,000
06 Apr 2017Regione AbruzzoThe Garante fined Regione Abruzzo EUR 20,000 for unlawfully publishing lists on its website that revealed candidates' health status. The case involved the disclosure of sensitive personal data relating to individuals with disabilities.ITGaranteGDPR€20,000
26 Apr 2018Comune di DerutaThe Municipality of Deruta was fined 10,000 EUR for unlawfully providing lists of personal data of residents born in 1994–1996 to a private educational institution. The recipient was not entitled to receive the data under public utility exceptions.ITGaranteGDPR€10,000