Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Jun 2015Quotidiano Il Tempo s.r.l.Quotidiano Il Tempo s.r.l. was fined by the Garante EUR 8,400 for processing personal data without providing adequate information to subscribers. The authority also found that the company used a video surveillance system without the simplified notice required under privacy rules.ITGaranteGDPR€8,400
08 May 2014Telextra s.r.l.Telextra s.r.l. was fined by the Garante for processing personal data from electronic communication operators' databases without consent. The authority also found non-compliance with previous orders and data protection requirements.ITGaranteGDPR€300,000
09 May 2018Ditta individuale “La Scuola della Salute di Francesco Parisi”The Garante imposed a 15,000 EUR fine on Ditta individuale “La Scuola della Salute di Francesco Parisi” for providing inadequate privacy information to clients and for related consent issues. The conduct was found to violate provisions of the privacy code.ITGaranteGDPR€15,000
27 Apr 2023Provvedimento del 27 aprile 2023 [9896468]A fine of EUR 400 was imposed for improper use of a video surveillance system that captured images of a public street without the required authorization. The case concerned a breach of personal data processing rules in the context of video monitoring.ITGaranteGDPR€400
23 May 2024Ordine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di MateraOrdine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di Matera was fined 3,500 EUR by the Garante. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization, in the handling of personal data.ITGaranteGDPR€3,500
17 Jul 2025Juna S.r.l.Juna S.r.l. was fined €25,000 by the Garante for making repeated unwanted and fraudulent promotional calls to individuals. The conduct breached data protection principles, including lawful and fair processing requirements.ITGaranteGDPR€25,000
13 Feb 2007Asl Alto MoliseAsl Alto Molise was fined 10,000 EUR by the Garante for failing to notify data processing activities related to health diagnosis, treatment, and prevention within the required timeframe. The breach violated the Italian Data Protection Code.ITGaranteGDPR€10,000
09 Oct 2025Ordine delle Professioni Infermieristiche di PisaOrdine delle Professioni Infermieristiche di Pisa was fined by the Garante 16,000 EUR for breaches of data protection principles. The authority cited non-compliance with lawfulness, fairness, transparency, and data minimization requirements.ITGaranteGDPR€16,000
27 Jun 2013REY2MOND S.n.c. di Reymond Luciano & C.REY2MOND S.n.c. was fined EUR 4,800 by the Garante for collecting personal data through online forms without providing the required privacy notice. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€4,800
31 Jan 2013Edizioni associative srlEdizioni associative srl was fined EUR 16,000 by the Garante. The authority found that the company sent unsolicited promotional emails without proper consent, breaching data protection rules.ITGaranteGDPR€16,000
15 Apr 2021Società triveneta di chirurgiaSocietà triveneta di chirurgia was fined EUR 2,000 by the Garante for processing personal data without meeting the requirements of lawfulness, fairness, and transparency. The authority also found a breach of the data minimization principle.ITGaranteGDPR€2,000
15 Jun 2017Azienda Policlinico Umberto IAzienda Policlinico Umberto I was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate data processing officers and provide them with the necessary instructions, breaching minimum security measures under the Italian Data Protection Code.ITGaranteGDPR€10,000
22 Jun 2023Autostrade per l’Italia S.p.A.Autostrade per l’Italia S.p.A. was fined by the Garante EUR 1,000,000 for violations linked to an application that processed users’ personal data. The app was used to handle refunds of highway ticket costs for delays caused by construction works.ITGaranteGDPR€1,000,000
13 May 2021Artemisia s.p.a.Artemisia s.p.a. was fined EUR 100,000 by the Garante for GDPR breaches in data processing. The violations concerned consent, information notices, and the handling of health data.ITGaranteGDPR€100,000
09 Oct 2025AD Media S.r.l.AD Media S.r.l. was fined EUR 5,000 by the Garante for sending promotional emails without proper consent. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing.ITGaranteGDPR€5,000
22 Feb 2024Camera di Commercio Industria Artigianato e Agricoltura di XXCamera di Commercio was fined for violating data protection principles by improperly disclosing personal data. The disclosure could have allowed third parties to learn the content of a judicial decision and infringed the privacy of the individual concerned.ITGaranteGDPR€2,000
17 Mar 2016Giuseppe VesceraGiuseppe Vescera was fined by the Garante in the amount of 2,400 EUR for failing to provide adequate information to data subjects about video surveillance. The authority found a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
29 Apr 2026Ministero della GiustiziaThe Ministry of Justice was fined EUR 12,000 by the Garante for violations related to personal data processing. The case concerned the absence of an appropriate legal basis and the processing of special categories of data.ITGaranteGDPR€12,000
02 Jul 2015Lu JiruLu Jiru was fined EUR 2,400 by the Garante. The authority found that personal data were processed through a video surveillance system without providing the required information to data subjects, in breach of the Italian Privacy Code.ITGaranteGDPR€2,400
07 Nov 2018Comune di Castel MaggioreComune di Castel Maggiore was fined by the Garante for publishing personal data on its institutional website without a legal basis. The case concerned a breach of data protection rules and unauthorized disclosure of information.ITGaranteGDPR€4,000