Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Mar 2024Estlevante s.r.l.s.The Garante imposed a EUR 2,000 fine on Estlevante s.r.l.s. for failing to provide the required privacy notice for its video surveillance system. The breach concerned Article 13 of the GDPR.ITGaranteGDPR€2,000
11 Jul 2018General Market di E. Barcio & Fratelli s.n.c.General Market di E. Barcio & Fratelli s.n.c. was fined by the Garante 7,200 EUR for failing to provide adequate information to people entering its stores about data processing through video surveillance systems. The authority found that the required notice obligations for monitored individuals were not met.ITGaranteGDPR€7,200
09 Oct 2025Provvedimento del 9 ottobre 2025 [10184697]The Garante imposed a EUR 70,000 fine on a company managing a hospital for violations related to the processing of health data. The case also involved a change in the complainant's treatment path and a failure to notify the authority of a data breach.ITGaranteGDPR€70,000
23 Mar 2023CAAF CGIL Lombardia s.r.l.CAAF CGIL Lombardia s.r.l. was fined EUR 30,000 by the Garante for unlawful processing of personal data. The company sent promotional emails despite a prior request to delete the data.ITGaranteGDPR€30,000
23 Mar 2017Ente Nazionale per L’Aviazione Civile (ENAC)ENAC was fined by the Garante in the amount of 10,000 EUR. The authority found that adequate security measures were not implemented, in breach of Articles 33 and 34 of the Italian Data Protection Code.ITGaranteGDPR€10,000
16 Sept 2021Ordine Provinciale di Roma dei Medici Chirurghi e degli OdontoiatriOrdine Provinciale di Roma dei Medici Chirurghi e degli Odontoiatri was fined by the Garante €5,000 for failing to adequately respond to a data subject’s request for access to personal data. The authority found a breach of GDPR Articles 12 and 15.ITGaranteGDPR€5,000
16 Feb 2017Crabion s.r.l.Crabion s.r.l. was fined by the Garante in the amount of EUR 20,000 for processing genetic data without the required authorization. The case concerns breaches of the rules governing the lawful processing of sensitive personal data.ITGaranteGDPR€20,000
17 Mar 2016Nico MannelliNico Mannelli was fined by the Garante EUR 2,400 for inadequate video surveillance signage and for failing to inform individuals about the purpose of processing and the data controller. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
28 Apr 2022Comune di PartannaComune di Partanna was fined by the Garante for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. The case concerned the improper handling of personal data in a disciplinary procedure.ITGaranteGDPR€2,000
12 Feb 2026Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di MacerataOrdine dei Medici Chirurghi e degli Odontoiatri della Provincia di Macerata was fined EUR 4,000 by the Garante. The authority found breaches of the principles of lawfulness, fairness, transparency, and data minimization. The case indicates non-compliance with core GDPR processing requirements.ITGaranteGDPR€4,000
10 Apr 2025Vogliocasa Holding & Servizi S.r.l.Vogliocasa Holding & Servizi S.r.l. was fined by the Garante EUR 5,000 for making unsolicited telemarketing calls promoting real estate brokerage services without valid consent. The company also failed to respond to the authority's information requests, which hindered the supervisory process.ITGaranteGDPR€5,000
15 May 2013HU YonghuHU Yonghu was fined EUR 6,000 by the Garante for failing to provide the required privacy notice for the restaurant surveillance system. The case concerned non-compliance with the Italian Data Protection Code.ITGaranteGDPR€6,000
22 Feb 2024Comune di Civita CastellanaComune di Civita Castellana was fined EUR 3,000 by the Garante for improper handling of personal data during COVID-19 data transmission. The authority found that GDPR formalities were not properly complied with.ITGaranteGDPR€3,000
12 Dec 2024Start To Fly S.r.l.Start To Fly S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited emails and SMS messages to a complainant. The complainant was unable to unsubscribe from the mailing list despite multiple attempts.ITGaranteGDPR€10,000
23 May 2024Azienda Socio-sanitaria Territoriale RhodenseAzienda Socio-sanitaria Territoriale Rhodense was fined EUR 4,500 by the Garante for breaching GDPR Article 16. The case concerned data processing in the health sector, where strict compliance controls are required.ITGaranteGDPR€4,500
10 Nov 2022Comune di Cisterna di LatinaComune di Cisterna di Latina was fined 5,000 EUR by the Garante for violating data protection principles, including data minimization. Improper handling of personal data led to unauthorized access by third parties.ITGaranteGDPR€5,000
12 Feb 2026Based s.r.l.Based s.r.l. was fined by the Garante EUR 12,000 for providing an inadequate response to a data subject’s request for access to and deletion of email account data. The authority found that the company failed to comply with GDPR requirements on data subject rights.ITGaranteGDPR€12,000
13 Nov 2025Comune di OrteComune di Orte was fined EUR 6,000 by the Garante for installing surveillance cameras without ensuring the required transparency in data processing. The authority found breaches of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€6,000
28 Apr 2022Istituto Nazionale Assicurazione Infortuni sul LavoroIstituto Nazionale Assicurazione Infortuni sul Lavoro was fined by the Garante EUR 20,000. The authority found that inadequate technical and organizational measures led to a data breach.ITGaranteGDPR€20,000
01 Feb 2018Transpe S.p.A.Transpe S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to notify the installation of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations.ITGaranteGDPR€20,000