Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 May 2022COMUNIDAD.1The owners’ community installed a video surveillance system in common areas without informed consent from all property owners. The AEPD found this to be a breach of data protection rules.ESAEPDGDPR€1,000
01 Jan 2021COMUNIDAD.1The entity was fined by the AEPD EUR 1,000 for installing a video surveillance system that captured third parties without adequate data protection measures. The authority found breaches of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€1,000
10 Jul 2020COMUNIDAD.1The entity was fined for installing surveillance cameras with audio in common areas without proper notice to affected persons. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,000
25 Jun 2024COMUNIDAD.1The community of property owners disclosed a resident’s personal data, including their DNI, in meeting minutes. AEPD found this breached confidentiality principles and imposed a 300 EUR fine.ESAEPDGDPR€300
18 Jul 2025***COMUNIDAD.1The entity was fined for including personal data in community meeting minutes distributed to residents and for inadequate security measures on its community website. The authority found that these failures breached Article 32 of the GDPR on processing security.ESAEPDGDPR€1,000
09 Dec 2021***COMUNIDAD.1The entity installed surveillance cameras in a community property without proper authorization from all owners. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,500
29 Jan 2015Comunicando di Rizzotto Fabio & C. s.a.s.Comunicando di Rizzotto Fabio & C. s.a.s. was fined €80,000 by the Garante for activating 88 phone cards in the names of 16 individuals without their knowledge. The authority found this to be a breach of data protection rules.ITGaranteGDPR€80,000
22 Oct 2015Comune di ZagariseComune di Zagarise was fined for processing employees’ biometric data without notifying the Garante and without requesting prior verification. The authority found violations of Articles 17 and 37 of the Codice.ITGaranteGDPR€12,000
26 Mar 2026Comune di XXThe Garante fined Comune di XX EUR 5,000 for breaches of lawfulness, fairness, transparency, and data minimization. It also found failures to implement data protection by design and by default.ITGaranteGDPR€5,000
26 Mar 2026Comune di XXThe Garante fined Comune di XX EUR 3,000 for breaches of GDPR Articles 6 and 9 and Article 2-ter of the Italian Privacy Code. The case concerned processing personal data without a proper legal basis.ITGaranteGDPR€3,000
11 Jul 2018Comune di VollaComune di Volla was fined by the Garante EUR 10,000 for allowing all employees access to sensitive and judicial personal data through its electronic protocol system. The authority found that this setup failed to meet required data protection safeguards.ITGaranteGDPR€10,000
04 Jul 2024Comune di VillasimiusComune di Villasimius was fined for failing to respond to a request to remove personal data from its website and for unlawfully publishing personal data. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
10 Nov 2022Comune di Villafranca di VeronaThe Comune di Villafranca di Verona was fined 4,000 EUR by the Garante for breaching data protection principles. The authority found that personal data linked to a sensitive private matter was improperly disclosed online.ITGaranteGDPR€4,000
12 May 2022Comune di VillabateComune di Villabate was fined 6,000 EUR for failing to update the Data Protection Officer’s contact details on its website and in communications with the Authority. The conduct was found to breach the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€6,000
04 Jun 2015Comune di Vico EquenseThe Municipality of Comune di Vico Equense was fined 20,000 EUR by the Garante. The authority found that the security program document was not updated and data processing officers were not appointed, which allowed unauthorized access to sensitive data.ITGaranteGDPR€20,000
15 Dec 2022Comune di VicchioComune di Vicchio was fined by the Garante 8,000 EUR for using fingerprints to monitor employee attendance without appropriate legal basis and safeguards. The authority found that the biometric processing breached GDPR requirements.ITGaranteGDPR€8,000
06 Nov 2014Comune di VeronellaComune di Veronella was fined by the Garante for unlawfully publishing personal data on its online notice board for longer than the legally permitted 15 days. This constituted a breach of data protection rules.ITGaranteGDPR€4,000
26 Sept 2024Comune di VeronaThe Garante fined Comune di Verona €10,000 for violations of GDPR Articles 5, 6 and 9, as well as Article 2-ter of the Italian Privacy Code. The case concerned the processing of personal data in a manner not compliant with legal requirements.ITGaranteGDPR€10,000
11 Sept 2025Comune di VeronaThe Comune di Verona was fined for improperly sharing personal data of TARI taxpayers with a third party for engagement communications. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€6,000
22 Dec 2016Comune di VergatoComune di Vergato was fined by the Garante for retaining surveillance footage beyond the permitted period. The case concerned non-compliance with data protection rules on storage limitation and video retention.ITGaranteGDPR€12,000