Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Oct 2012Azienda sanitaria provinciale di Vibo ValentiaAzienda sanitaria provinciale di Vibo Valentia was fined by the Garante EUR 15,000 for failing to adopt the required minimum security measures. The authority found that the Security Programmatic Document (DPS) was not updated by the deadline required under the Italian Privacy Code.ITGaranteGDPR€15,000
31 May 2018Iqbal QasimIqbal Qasim was fined by the Garante in the amount of EUR 70,000 for registering phone SIM cards to third parties without their consent. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€70,000
09 Jan 2014Ordinanza ingiunzione - 9 gennaio 2014 [4785574]The Garante imposed a fine of EUR 4,000 for sending promotional emails without prior valid consent from recipients. The case concerns a breach of data protection rules and electronic marketing requirements.ITGaranteGDPR€4,000
10 Nov 2011Idea Service S.r.l.Idea Service S.r.l. was fined EUR 20,000 by the Garante for failing to provide information about an unwanted switch of telephone service provider. The authority found a breach of Article 164 of the Italian Data Protection Code.ITGaranteGDPR€20,000
23 Oct 2025Comune di CurtaroloComune di Curtarolo was fined EUR 15,000 by the Garante for using surveillance footage for disciplinary purposes without proper legal justification. The authority also found that adequate privacy information was not provided to the individuals concerned.ITGaranteGDPR€15,000
18 Sept 2008Eutelia S.p.A.Eutelia S.p.A. was fined by the Garante EUR 20,000 for using an automated calling system without obtaining prior consent from the individuals concerned. The case concerned a breach of data protection rules and consent requirements for automated communications.ITGaranteGDPR€20,000
04 Jul 2013OASI AZZURRA di Intravaia Lorenzo & C. S.a.s.OASI AZZURRA di Intravaia Lorenzo & C. S.a.s. was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned inadequate privacy notices for the website contact form and the video surveillance system.ITGaranteGDPR€2,400
12 May 2022Hu XiaoyanThe Garante fined Hu Xiaoyan EUR 20,000 for operating a video surveillance system without proper informational signage and required safeguards. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
19 Jan 2017Bertolotto Michele e Azienda Universitaria Ospedaliera Ospedali Riuniti di TriesteThe Garante imposed a 10,000 EUR fine on Bertolotto Michele and Azienda Universitaria Ospedaliera Ospedali Riuniti di Trieste. The case concerned unauthorized access by two doctors to personal health data, including Bertolotto’s data.ITGaranteGDPR€10,000
23 Feb 2017Avv. Silvana VassalliAvv. Silvana Vassalli was fined by the Garante for unlawful processing of personal data. The breach involved transmitting an email containing personal data without proper authorization.ITGaranteGDPR€8,000
18 Jun 2020Azienda Pluriservizi Macerata S.p.A.Azienda Pluriservizi Macerata S.p.A. was fined EUR 4,000 by the Garante for processing colleagues’ personal data in a manner that did not comply with data protection principles. The authority cited breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
23 Nov 2022Linee Stampalibera Società Cooperativa S.r.l.Linee Stampalibera Società Cooperativa S.r.l. was fined 1,000 EUR by the Garante for publishing personal data on its website without consent. The case also involved the full text of a property purchase contract, which breached data protection rules.ITGaranteGDPR€1,000
22 Jun 2023Spaziani FabrizioThe Garante fined Spaziani Fabrizio EUR 1,000 for non-compliant video surveillance practices. The case involved cameras that were not properly signposted and may have captured public areas.ITGaranteGDPR€1,000
20 Jun 2024Comune di ForlìThe Municipality of Forlì was fined EUR 15,000 by the Garante for failing to embed data protection principles in the design of its video surveillance system. The authority found breaches of transparency and accountability requirements.ITGaranteGDPR€15,000
23 Jul 2015Impresa Edile di Alagna GiuseppeThe company was fined EUR 2,400 by the Garante for failing to provide the required privacy notice on its website. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
28 Apr 2022Direzione Didattica Statale 1° Circolo–EboliDirezione Didattica Statale 1° Circolo–Eboli was fined by the Garante 1,500 EUR for breaching the GDPR principles of lawfulness, fairness, and transparency in data processing. The case concerned improper processing of personal data under the GDPR.ITGaranteGDPR€1,500
20 Nov 2014Impresa costruzioni edili e stradali – dr. Ing. Michele Bianchi & C. - s.r.l.The company was fined by the Garante 2,400 EUR for failing to provide the required privacy notice to data subjects when collecting personal data through a web form on its website. The case concerned a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
10 Apr 2025Azienda Ospedaliera Universitaria Integrata VeronaAzienda Ospedaliera Universitaria Integrata Verona was fined by the Garante for failing to adequately protect personal data. After a ransomware attack, 612 GB of data was published on the dark web, indicating serious security shortcomings.ITGaranteGDPR€10,000
18 Jul 2023Università Telematica E-CampusUniversità Telematica E-Campus was fined EUR 75,000 by the Garante. The authority found that the university sent promotional SMS messages without consent and failed to respond to data deletion requests. These actions breached GDPR requirements.ITGaranteGDPR€75,000
11 Apr 2013Kihria S.r.l.Kihria S.r.l. was fined 2,400 EUR by the Garante for failing to provide adequate information about data collection through a website contact form. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400