Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Nov 2024Comune di Motta Sant'AnastasiaThe Garante imposed a EUR 10,000 fine on Comune di Motta Sant'Anastasia for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper processing of personal data.ITGaranteGDPR€10,000
19 Mar 2015Comune di MorinoComune di Morino was fined EUR 4,000 by the Garante for unlawfully disclosing the personal data of an individual applying for public housing to private entities without a legal basis. The authority found a breach of data protection rules.ITGaranteGDPR€4,000
18 Dec 2013Comune di MonticianoThe Municipality of Monticiano was fined 8,000 EUR by the Garante. The authority found a privacy violation after the municipality failed to provide requested information about the publication of personal data on its institutional website.ITGaranteGDPR€8,000
10 Jun 2020Comune di MontevagoComune di Montevago was fined by the Garante 2,000 EUR for the unlawful online publication of personal data without an appropriate legal basis. The case concerned a breach of the principles of lawful processing and data protection in the public disclosure of information online.ITGaranteGDPR€2,000
28 Apr 2022Comune di Monte Sant’AngeloThe Municipality of Monte Sant’Angelo was fined 3,000 EUR by the Garante for breaching data protection principles. The authority found that personal data had been made accessible online in violation of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
22 Feb 2024Comune di MonterotondoThe Garante imposed a EUR 3,000 fine on Comune di Monterotondo for breaches involving data processing agreements and security measures. The case also involved improper use of video surveillance. The authority found that the controller did not meet data protection requirements.ITGaranteGDPR€3,000
22 Oct 2015Comune di Montelupo FiorentinoThe Municipality of Comune di Montelupo Fiorentino was fined 4,000 EUR by the Garante for unlawfully publishing personal data online. The case concerned the results of participants in a competitive examination disclosed without a proper legal basis.ITGaranteGDPR€4,000
25 Mar 2021Comune di MonteiasiComune di Monteiasi was fined by the Garante €4,000 for breaching the data minimization principle. The municipality published personal data on its website, including names and IBANs, that were not necessary for transparency purposes.ITGaranteGDPR€4,000
02 Apr 2015Comune di MontefrancoComune di Montefranco was fined EUR 4,000 by the Garante. The authority found that the role of Mercurio service s.r.l. was not properly regulated, although it processed personal data relating to traffic violations without proper authorization.ITGaranteGDPR€4,000
30 Jul 2015Comune di MontallegroComune di Montallegro was fined for publishing documents on its website that contained sensitive personal data revealing individuals' health conditions. This constituted a breach of data protection law.ITGaranteGDPR€10,000
16 Sept 2021Comune di Montalbano JonicoThe Garante fined Comune di Montalbano Jonico 5,000 EUR for breaching the data minimization principle. The municipality published excessive personal data on its website, including health-related information.ITGaranteGDPR€5,000
05 Feb 2015Comune di MontagnarealeThe Garante fined Comune di Montagnareale 10,000 EUR for unlawfully publishing personal data revealing health status on its institutional website. The breach involved disclosure of sensitive data without an adequate legal basis or safeguards.ITGaranteGDPR€10,000
13 Sept 2007Comune di MoncalieriComune di Moncalieri was fined by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the notification obligation under Article 37 of the Italian Data Protection Code.ITGaranteGDPR€10,000
18 Jul 2023Comune di ModicaThe Garante fined Comune di Modica EUR 45,000 for inadequate data protection measures linked to video surveillance in public areas. The issues affected a large number of individuals over an extended period, and those recorded were not properly informed.ITGaranteGDPR€45,000
28 Feb 2019Comune di MisterbiancoComune di Misterbianco was fined by the Garante 4,000 EUR for unlawful processing of personal data. The breach involved publishing personal information on its website beyond the legally permitted period.ITGaranteGDPR€4,000
14 May 2026Comune di Mirabella ImbaccariComune di Mirabella Imbaccari was fined for disclosing personal data online without a legal basis and for violating the data minimization principle. The authority also found that the municipality had failed to appoint a Data Protection Officer and to communicate the DPO’s contact details to the supervisory authority.ITGaranteGDPR€1,800
27 Mar 2025Comune di MilazzoThe Garante fined the Comune di Milazzo €3,600 for failing to provide adequate data protection information on its website. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€3,600
26 Jul 2012Comune di MilanoThe Garante fined Comune di Milano EUR 20,000 for failing to implement minimum security measures on two computer stations at a primary school. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€20,000
19 Feb 2015Comune di MesoracaComune di Mesoraca was fined by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its institutional website. The case involved unauthorized disclosure of medical information made publicly accessible.ITGaranteGDPR€10,000
05 Feb 2015Comune di MerìComune di Merì was fined EUR 10,000 by the Garante for unlawfully publishing sensitive personal data on its website. The disclosure included information about individuals' health status and mandatory medical treatments, breaching data protection rules.ITGaranteGDPR€10,000