Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Mar 2016Comune di Ischia di CastroThe Municipality of Comune di Ischia di Castro was fined 4,000 EUR by the Garante for unlawfully publishing personal data of jury members on its online notice board for longer than the legally permitted period. The case concerned a breach of data protection rules and retention limits.ITGaranteGDPR€4,000
10 Feb 2022Comune di GuidizzoloComune di Guidizzolo was fined for publishing a complainant’s personal data, including name and professional qualification, in a public document without proper justification. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€2,000
01 Jun 2023Comune di GuardiagreleComune di Guardiagrele was fined EUR 5,000 by the Garante for failing to provide an adequate response to a data access request. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing.ITGaranteGDPR€5,000
02 Jul 2020Comune di Greve in ChiantiComune di Greve in Chianti was fined by the Garante for unlawfully disclosing personal data relating to criminal convictions and proceedings. The conduct breached the principles of lawfulness, fairness, and transparency in data processing.ITGaranteGDPR€4,000
05 Jun 2014Comune di GraffignanoComune di Graffignano was fined EUR 4,000 by the Garante. The authority found that personal data remained published on the institutional website for longer than the legally allowed 15 days.ITGaranteGDPR€4,000
21 Jul 2022Comune di GinosaComune di Ginosa was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the whistleblowing context. The authority found that an adequately high level of confidentiality and protection for the data subjects was not ensured.ITGaranteGDPR€5,000
06 Nov 2014Comune di GerenzanoThe Municipality of Gerenzano was fined 4,000 EUR by the Garante for failing to appoint a socially useful worker as a data processor. The authority found this breached the minimum security measures required under the data protection code.ITGaranteGDPR€4,000
07 May 2015Comune di GenovaThe Municipality of Genoa was fined by the Garante for unlawfully keeping personal and judicial data on its institutional website beyond the legally permitted period. The authority found this to be a breach of data protection rules.ITGaranteGDPR€4,000
28 Mar 2019Comune di GenovaComune di Genova was fined for unlawfully communicating personal data to third-party companies without a proper legal basis. The authority found a breach of data protection rules.ITGaranteGDPR€8,000
30 Jul 2015Comune di GallipoliThe Municipality of Gallipoli was fined by the Garante for unlawfully publishing personal data revealing health status on its institutional website. The conduct breached data protection rules.ITGaranteGDPR€10,000
06 Oct 2016Comune di FurnariThe Municipality of Furnari was fined 4,000 EUR by the Garante. The authority found that personal data remained published on the institutional website beyond the legally permitted period.ITGaranteGDPR€4,000
06 Oct 2016Comune di FurnariComune di Furnari was fined for publishing personal data on its institutional website. It also failed to respond to information requests from the Garante.ITGaranteGDPR€4,000
15 Jan 2020Comune di Francavilla FontanaThe Municipality of Francavilla Fontana was fined 10,000 EUR by the Garante for publishing personal data on its institutional website. The conduct breached data protection rules and triggered supervisory action.ITGaranteGDPR€10,000
29 Sept 2021Comune di FormiaComune di Formia was fined for processing personal data linked to parking subscription services without providing adequate information to data subjects. The authority also found excessive data collection and a failure to clearly define the role of the external data processor.ITGaranteGDPR€30,000
20 Jun 2024Comune di ForlìThe Municipality of Forlì was fined EUR 15,000 by the Garante for failing to embed data protection principles in the design of its video surveillance system. The authority found breaches of transparency and accountability requirements.ITGaranteGDPR€15,000
02 Apr 2015Comune di FolloComune di Follo was fined for unlawfully communicating personal data of children under three years old to a private company. The authority found this breached Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
26 Feb 2020Comune di Fogliano RedipugliaThe Municipality of Comune di Fogliano Redipuglia was fined by the Garante for unlawfully publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€6,000
22 Feb 2018Comune di FiumicinoComune di Fiumicino was fined by the Garante for failing to notify a data breach within the required timeframe. The authority found a violation of the Italian Data Protection Code.ITGaranteGDPR€30,000
24 Jun 2021Comune di FiscianoComune di Fisciano was fined EUR 1,000 by the Garante for improper handling of personal data. The data were removed after the complaint, and the case concerned transparency and data protection obligations.ITGaranteGDPR€1,000
08 Feb 2007Comune di FirenzeGarante imposed a EUR 3,000 fine on Comune di Firenze for failing to provide adequate information to individuals about the processing of personal data through a video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000