Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Oct 2013Comune di BolzanoComune di Bolzano was fined 10,000 EUR by the Garante for publishing sensitive health-related information about an employee’s absence on its institutional website. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
29 Apr 2025Comune di BolognaThe Garante imposed a fine of 40,000 EUR on Comune di Bologna for breaches of data protection principles. The case concerned non-compliance with requirements on lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€40,000
05 Feb 2015Comune di BellizziComune di Bellizzi was fined for unlawfully publishing sensitive personal data revealing health information on its institutional website. The conduct breached privacy rules governing the processing and disclosure of sensitive data.ITGaranteGDPR€10,000
12 Mar 2015Comune di BasicòComune di Basicò was fined for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of data protection rules and the confidentiality of sensitive data.ITGaranteGDPR€10,000
29 Jan 2015Comune di BarzagoComune di Barzago was fined for failing to provide the required information notice to individuals whose personal data were processed for sending informational SMS messages. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
09 Jul 2020Comune di BaronissiComune di Baronissi was fined by the Garante for publishing personal data online without a proper legal basis. The authority found a breach of the data minimization principle.ITGaranteGDPR€2,000
31 Jan 2019Comune di BardolinoThe Municipality of Bardolino was fined EUR 8,000 by the Garante for publishing personal data on its institutional website without an appropriate legal basis. The disclosure included names and tax codes of beneficiaries of economic contributions, as well as personal information of two municipal employees.ITGaranteGDPR€8,000
07 May 2015Comune di BagnoregioComune di Bagnoregio was fined by the Garante for unlawfully publishing personal data on its website. The conduct breached the conditions set out in the Italian data protection code.ITGaranteGDPR€4,000
23 Oct 2025Comune di AvolaThe Garante fined Comune di Avola 2,000 EUR for failing to provide the Authority with the Data Protection Officer’s contact details. The breach concerned the obligation under Article 37(7) GDPR.ITGaranteGDPR€2,000
05 Mar 2015Comune di AvolaComune di Avola was fined 10,000 EUR by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its website. The case involved a breach of privacy rules and the unlawful processing of special-category data.ITGaranteGDPR€10,000
06 Jul 2023Comune di AvianoThe Garante fined Comune di Aviano EUR 3,000 for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found a breach of data minimization and transparency principles.ITGaranteGDPR€3,000
12 Feb 2026Comune di AversaThe Garante fined Comune di Aversa 3,000 EUR for failing to communicate the contact details of the Data Protection Officer. The case concerns Article 37 GDPR and the obligation to make DPO contact information available.ITGaranteGDPR€3,000
06 Jul 2006Comune di AugustaThe Municipality of Augusta was fined by the Garante for failing to make a required notification under data protection law. The breach concerned Article 163 of the Codice Privacy.ITGaranteGDPR€5,164
26 Feb 2020Comune di AstiComune di Asti was fined EUR 8,000 by the Garante for unlawfully publishing personal data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€8,000
23 Oct 2025Comune di Arcinazzo RomanoThe Garante fined Comune di Arcinazzo Romano 4,500 EUR for unlawfully processing personal data through a video system. The system was used to verify tax compliance for waste disposal, in breach of the principles of lawfulness, fairness, transparency, and purpose limitation.ITGaranteGDPR€4,500
23 Apr 2015Comune di AostaComune di Aosta was fined for publishing personal data that revealed health information on its website. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€10,000
12 Feb 2026Comune di AnconaThe Garante fined Comune di Ancona EUR 3,000 for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found that no proper contract was in place with a data processor, in breach of GDPR Articles 5 and 28.ITGaranteGDPR€3,000
12 Mar 2015Comune di Alì TermeComune di Alì Terme was fined for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy rules and the protection of sensitive personal data.ITGaranteGDPR€10,000
26 May 2022Comune di AfragolaComune di Afragola was fined EUR 10,000 by the Garante for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. The authority found that personal data had been handled improperly.ITGaranteGDPR€10,000
27 Apr 2011Comune di AdroThe Municipality of Adro was fined 15,000 EUR by the Italian supervisory authority Garante. The case concerned the publication of employees’ personal data, including health information, in a periodical.ITGaranteGDPR€15,000