Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Apr 2025Comune di San Francesco al CampoThe Garante imposed a fine of 1,200 EUR on Comune di San Francesco al Campo for violations related to the publication of personal data on its institutional website. The data were subsequently removed.ITGaranteGDPR€1,200
05 Dec 2013Comune di San Felice CirceoThe Garante fined Comune di San Felice Circeo EUR 6,000 for failing to provide the information required under Art. 13 and for not updating the security program document under Art. 33. The authority also found non-compliance with a prior order.ITGaranteGDPR€6,000
20 Oct 2022Comune di SalentoComune di Salento was fined for unlawful processing of personal data through video surveillance systems. The authority found that retention periods for surveillance images were not set and that free access to personal data was not ensured, breaching GDPR transparency and access rights.ITGaranteGDPR€12,000
26 Jan 2017Comune di Roma CapitaleComune di Roma Capitale was fined EUR 10,000 by the Garante for unlawfully publishing personal data of disabled individuals on its website. The case concerned a breach of data protection rules and required removal of the disclosed information.ITGaranteGDPR€10,000
13 Mar 2025Comune di RoccarasoThe Garante fined Comune di Roccaraso EUR 2,000 for publishing personal data on a public notice board. The authority found breaches of GDPR Articles 5, 6 and 12, as well as Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€2,000
04 Jun 2025Comune di RoccaforzataComune di Roccaforzata was fined EUR 8,000 by the Garante for publishing sensitive health data, including an employee’s disability percentage, in a council resolution. The authority found a breach of the GDPR and national privacy code provisions.ITGaranteGDPR€8,000
30 Jan 2014Comune di Reggio Emilia – Comando Polizia municipaleThe Municipality of Reggio Emilia's Police Command was fined EUR 2,400 by the Garante for operating a video surveillance system without simplified information signage. The authority found a breach of Article 13 of the Privacy Code.ITGaranteGDPR€2,400
01 Dec 2022Comune di Reggio EmiliaThe Municipality of Reggio Emilia was fined 8,000 EUR by the Garante for unlawfully publishing personal data, including health information, of a former employee on its website. The case concerned an unauthorized disclosure of sensitive information in breach of data protection rules.ITGaranteGDPR€8,000
04 Jun 2025Comune di ReccoThe Garante fined Comune di Recco EUR 5,000 for inadequate data protection measures linked to video surveillance used to monitor waste disposal. The authority found breaches of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€5,000
18 Nov 2015Comune di RecaleComune di Recale was fined EUR 4,000 by the Garante for publishing an individual's personal data on its institutional website without proper legal basis. The case concerned violations of privacy and personal data processing rules.ITGaranteGDPR€4,000
22 Jan 2015Comune di RealmonteComune di Realmonte was fined by the Garante for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy and data protection rules.ITGaranteGDPR€10,000
29 Apr 2021Comune di PutifigariComune di Putifigari was fined EUR 3,000 by the Garante for publishing special-category personal data online. The disclosed information could reveal individuals' health status, which breached GDPR requirements on data protection and privacy.ITGaranteGDPR€3,000
23 Mar 2023Comune di PulsanoComune di Pulsano was fined by the Garante for unlawfully publishing personal data related to an employee’s disciplinary proceedings on its institutional website. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€3,000
21 Apr 2016Comune di PozzuoliComune di Pozzuoli was fined EUR 10,000 by the Garante for publishing a minor’s personal data, including health information, on its institutional website. The conduct breached privacy and data protection rules.ITGaranteGDPR€10,000
21 Jun 2018Comune di PozzalloComune di Pozzallo was fined for publishing personal and judicial data online without a valid legal basis. It also failed to respond to information requests from the Garante.ITGaranteGDPR€8,000
14 Mar 2019Comune di Porto Sant’ElpidioThe Garante fined Comune di Porto Sant’Elpidio EUR 10,000 for publishing documents on its website that contained personal data revealing the health status of individuals with disabilities. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
12 Dec 2024Comune di PorticiThe Garante fined Comune di Portici EUR 6,000 for breaches of data protection principles, including lawfulness, fairness, and transparency. The authority also found that the municipality failed to carry out a data protection impact assessment before processing personal data through video surveillance.ITGaranteGDPR€6,000
11 Dec 2008Comune di PontenureComune di Pontenure was fined EUR 3,000 by the Garante for failing to provide the required data protection notice when sending a questionnaire about waste management tariffs. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
10 Apr 2025Comune di Ponte nelle AlpiThe Garante fined Comune di Ponte nelle Alpi 4,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Codice. The case concerned improper personal data processing activities.ITGaranteGDPR€4,000
04 Jun 2025Comune di PompeiThe Garante fined Comune di Pompei EUR 5,000 for failing to provide the Authority with the contact details of its Data Protection Officer. The breach concerned the notification duty under Article 37 GDPR.ITGaranteGDPR€5,000