Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Jul 2010Comune di VentimigliaComune di Ventimiglia was fined by the Garante for processing employees’ biometric data without the required notification. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
14 May 2026Comune di VentassoComune di Ventasso was fined EUR 8,000 by the Garante. The authority found breaches of the principles of lawful, fair and transparent processing of personal data, as well as data minimization.ITGaranteGDPR€8,000
17 Apr 2026Comune di VeneziaThe Municipality of Venice was fined €3,000 by the Garante for failing to ensure the required transparency in data processing. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€3,000
11 Nov 2021Comune di Varano BorghiComune di Varano Borghi was fined EUR 1,000 by the Garante for unlawfully publishing personal data online. The authority found a breach of GDPR principles of data minimization and transparency.ITGaranteGDPR€1,000
13 Feb 2020Comune di Urago d'OglioComune di Urago d'Oglio was fined EUR 4,000 by the Garante for improper processing and online publication of special-category personal data, including health data. The authority found insufficient legal basis and inadequate transparency toward the data subjects.ITGaranteGDPR€4,000
13 Nov 2024Comune di UgentoThe Garante fined Comune di Ugento 2,400 EUR for publishing data on its website that could reveal individuals' health status. The case involved the improper disclosure of sensitive information in a public online setting.ITGaranteGDPR€2,400
09 Oct 2014Comune di UdineThe Municipality of Udine was fined 14,000 EUR by the Garante. The authority found that the Security Policy Document (DPS) had not been updated from 2005 to 2011, which breached data protection rules.ITGaranteGDPR€14,000
13 Feb 2025Comune di TuscaniaThe Garante imposed a 4,000 EUR fine on Comune di Tuscania for violating data protection rules. The authority took into account the limited financial resources of the small municipality when setting the sanction.ITGaranteGDPR€4,000
04 Dec 2025Comune di TuscaniaThe Garante fined Comune di Tuscania 12,000 EUR for failing to provide timely and complete responses to information requests. It also found breaches of lawfulness, fairness, and transparency, as well as inadequate data protection impact assessments for video surveillance.ITGaranteGDPR€12,000
22 Jan 2015Comune di TroinaComune di Troina was fined 4,000 EUR by the Garante for unlawfully disclosing personal data to the complainant’s sister without a legal basis. The authority found a breach of data protection rules.ITGaranteGDPR€4,000
29 Apr 2021Comune di TriesteComune di Trieste was fined for the unauthorized disclosure of personal data relating to individuals involved in accidents, including names, damage details, and compensation amounts. The data was improperly accessible, constituting a breach of GDPR requirements.ITGaranteGDPR€45,000
04 Jul 2024Comune di TrevisoThe Garante fined Comune di Treviso EUR 7,000 for failing to adopt internal measures governing data processing in connection with the TrevisoSicura application. The authority also found that the municipality incorrectly assumed the role of data processor instead of properly defining its data protection responsibilities.ITGaranteGDPR€7,000
11 Jan 2024Comune di TrentoThe Garante fined Comune di Trento EUR 50,000 for conducting two research projects using cameras, microphones, and social networks in breach of data protection rules. The case concerns improper processing of personal data in the context of research activities.ITGaranteGDPR€50,000
27 Nov 2024Comune di TorrenovaThe Garante fined Comune di Torrenova 4,000 EUR for breaches of GDPR principles, including lawfulness, fairness, and transparency in data processing. The case indicates failures to meet basic data protection requirements in the public authority's processing activities.ITGaranteGDPR€4,000
24 Oct 2013Comune di Torre CajetaniComune di Torre Cajetani was fined by the Garante for unlawfully publishing an individual's health data on a public notice board. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€10,000
14 Nov 2024Comune di Torre AnnunziataThe Garante imposed a EUR 2,000 fine on Comune di Torre Annunziata for failing to communicate the contact details of its Data Protection Officer. This obligation arises under Article 37(7) GDPR and is intended to ensure the supervisory authority can reach the DPO.ITGaranteGDPR€2,000
12 Mar 2015Comune di TorittoComune di Toritto was fined by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its website. The conduct breached privacy rules and triggered enforcement action by the supervisory authority.ITGaranteGDPR€10,000
17 Jul 2025Comune di Tocco da CasauriaComune di Tocco da Casauria was fined EUR 2,000 by the Garante for publishing personal data on its institutional website. The authority found that the processing did not comply with the principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€2,000
07 Nov 2019Comune di TivoliThe Municipality of Tivoli was fined by the Italian data protection authority, Garante, for unlawfully publishing personal data on its institutional website. The publication also included information about a pending criminal proceeding, breaching the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€6,000
15 Sept 2022Comune di ThieneComune di Thiene was fined EUR 3,000 by the Garante for violating data protection principles. The authority found that personal data related to a disciplinary dismissal case was improperly disclosed online.ITGaranteGDPR€3,000