Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Oct 2019Partito Democratico, Coordinamento Metropolitano di FirenzePartito Democratico, Coordinamento Metropolitano di Firenze was fined by the Garante €4,000 for a data protection breach. The incident resulted from a cyber attack on its website that exposed personal data of party members.ITGaranteGDPR€4,000
05 Jun 2014Ministero della GiustiziaThe Ministry of Justice was fined for unlawfully publishing personal data on its institutional website without a legal basis. The disclosure included names, dates of birth, and tax codes, in breach of data protection rules.ITGaranteGDPR€4,000
25 Jan 2018ATAM S.p.A. – Azienda territoriale Arezzo Mobilità S.p.A.ATAM S.p.A. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned failures to meet notification obligations related to a geolocation system used to track vehicles.ITGaranteGDPR€20,000
05 May 2016Polo scolastico paritario Scuola Domani s.r.l.The private school Polo scolastico paritario Scuola Domani s.r.l. was fined EUR 2,400 by the Garante. The authority found that the website did not provide the required privacy information to users submitting inquiries or job applications.ITGaranteGDPR€2,400
08 Oct 2015Amministrazione provinciale di PordenoneAmministrazione provinciale di Pordenone was fined 4,000 EUR by the Garante. The authority found that the annual Security Programmatic Document was not updated by the required deadline, breaching data protection rules.ITGaranteGDPR€4,000
11 Nov 2021Comune di Varano BorghiComune di Varano Borghi was fined EUR 1,000 by the Garante for unlawfully publishing personal data online. The authority found a breach of GDPR principles of data minimization and transparency.ITGaranteGDPR€1,000
04 Nov 2010Casa di Cura Tortorella S.p.aCasa di Cura Tortorella S.p.a was fined by the Garante for failing to notify certain data processing activities and for providing inadequate information to data subjects. The case concerns breaches of the Italian Data Protection Code and points to deficiencies in basic notification and transparency obligations.ITGaranteGDPR€20,000
18 Dec 2025LTL S.p.A.LTL S.p.A. was fined 40,000 EUR by the Garante for unlawfully maintaining access to an ex-employee’s email account after termination. The authority found this to be a breach of data protection rules.ITGaranteGDPR€40,000
29 Apr 2025Energia Pulita S.r.l.Energia Pulita S.r.l. was fined by the Garante for improper handling of personal data in telemarketing activities. The authority also noted failure to cooperate with the supervisory authority and incorrect identification of roles in data processing.ITGaranteGDPR€10,000
22 Jul 2021Regione CalabriaThe Garante imposed a 10,000 EUR fine on Regione Calabria for publishing personal data on its website. The conduct breached GDPR rules on lawful processing and protection of personal data.ITGaranteGDPR€10,000
28 Oct 2021TPER Trasporto Passeggeri Emilia Romagna S.p.A.TPER Trasporto Passeggeri Emilia Romagna S.p.A. was fined by the Garante EUR 30,000 for violations related to the processing of personal data of call center employees. The case involved potential unauthorized monitoring and insufficient data protection measures.ITGaranteGDPR€30,000
02 Apr 2015Schioppetti RaffaellaSchioppetti Raffaella was fined by the Italian data protection authority, Garante, in the amount of 15,000 EUR. The sanction concerned activating phone cards in individuals' names without their knowledge, which breached data protection rules.ITGaranteGDPR€15,000
23 May 2024Green Land African MinimarketThe Garante fined Green Land African Minimarket EUR 1,000 for improper use of a video surveillance system. The system captured areas beyond the company's premises and recorded employees without meeting the required legal conditions.ITGaranteGDPR€1,000
10 Apr 2025Provvedimento del 10 aprile 2025 [10144184]A healthcare organization was fined after an employee accessed a patient's health dossier without authorization. The case highlights a breach of data protection rules in the healthcare sector.ITGaranteGDPR€18,000
16 Mar 2017Cigno d’Argento s.r.l.Cigno d’Argento s.r.l. was fined by the Garante 36,000 EUR for data protection violations. The case concerned the improper use of video surveillance systems without the required authorization.ITGaranteGDPR€36,000
07 May 2015Comune di GenovaThe Municipality of Genoa was fined by the Garante for unlawfully keeping personal and judicial data on its institutional website beyond the legally permitted period. The authority found this to be a breach of data protection rules.ITGaranteGDPR€4,000
30 Nov 2023Limit Call S.r.l.s.Limit Call S.r.l.s. was fined by the Italian supervisory authority, Garante, in the amount of €60,000. The case concerned a failure to respond to an information request linked to unsolicited phone calls made without consent, which breached data protection rules.ITGaranteGDPR€60,000
08 May 2013Profile 2100 srlProfile 2100 srl was fined EUR 10,400 by the Garante for sending unsolicited promotional communications by fax without valid consent. The case concerned a breach of data protection rules and direct marketing requirements.ITGaranteGDPR€10,400
12 Feb 2026Provvedimento del 12 febbraio 2026 [10226120]The Garante imposed a fine of EUR 1,500 for unlawful processing of personal data through a video surveillance system at a commercial establishment. The cameras captured public streets and private residences, and the data subjects were not properly notified.ITGaranteGDPR€1,500
16 Sept 2021Università Commerciale “Luigi Bocconi” di MilanoUniversità Commerciale “Luigi Bocconi” di Milano was fined EUR 150,000 by the Garante for data protection breaches during remote exams. The authority found an insufficient legal basis, inadequate transparency, and weak security measures for transfers of data to the USA.ITGaranteGDPR€150,000