Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Apr 2026Azienda USL ModenaAzienda USL Modena was fined by the Garante in the amount of 10,000 EUR for a data breach caused by a ransomware attack. The authority found a breach of GDPR data security obligations.ITGaranteGDPR€10,000
04 Dec 2014Enrico TecchioThe Garante fined Enrico Tecchio EUR 2,400 for failing to provide data subjects with information about the processing of personal data through a video surveillance system at a dental practice. The case concerned the duty to inform individuals subject to monitoring.ITGaranteGDPR€2,400
06 Jul 2023Regione SicilianaThe Garante fined Regione Siciliana EUR 7,000 for publishing personal data of numerous individuals, including sensitive employment-related information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€7,000
23 Jun 2025Ordine delle Professioni Infermieristiche di ViterboThe Garante imposed a fine of EUR 10,000 on the Ordine delle Professioni Infermieristiche di Viterbo for breaches of data protection rules. The case concerned non-compliance with requirements governing the processing of personal data.ITGaranteGDPR€10,000
03 Mar 2016Comune di Ischia di CastroThe Municipality of Comune di Ischia di Castro was fined 4,000 EUR by the Garante for unlawfully publishing personal data of jury members on its online notice board for longer than the legally permitted period. The case concerned a breach of data protection rules and retention limits.ITGaranteGDPR€4,000
22 Jun 2017Bookingshow s.p.a.Bookingshow s.p.a. was fined EUR 62,000 by the Garante for unlawfully processing personal data. The company required mandatory consent for promotional purposes during online ticket purchases, which breached data processing rules.ITGaranteGDPR€62,000
08 Feb 2024Medtronic Italia S.p.a.Medtronic Italia S.p.a. was fined by the Garante in the amount of €300,000 for a data protection breach. The authority found inadequate technical and organizational measures that led to unauthorized disclosure of data.ITGaranteGDPR€300,000
10 Apr 2025Stefanelli FedericaThe Garante imposed a 45,000 EUR fine on Stefanelli Federica for processing personal data without proper consent in unauthorized call-center operations. The case also involved sensitive data, including payment method information, which could have led to unauthorized contract activations.ITGaranteGDPR€45,000
16 Jan 2026Associazione Turistica Pro Loco di CittarealeThe association unlawfully disclosed the personal data of 23 members by publishing it in a public notice and online. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€600
06 Feb 2014Oreiade s.r.l.Oreiade s.r.l. was fined by the Garante for installing a video surveillance system at Hotel Blu Inn without adequate safeguards. The authority found a breach of data protection rules.ITGaranteGDPR€24,400
09 Jan 2014Giallooro s.r.lGiallooro s.r.l was fined EUR 2,400 by the Garante for collecting personal data through a website contact form without providing the required privacy notice. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
03 May 2018Pace MarinaPace Marina, a general practitioner, was fined by the Garante for failing to implement minimum security measures to protect patients’ personal and sensitive data. This failure allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
29 Apr 2025Regione Emilia RomagnaThe Garante fined Regione Emilia Romagna EUR 15,000 for violations related to the processing of personal data for official statistical purposes. The authority found incorrect application of data protection principles and measures.ITGaranteGDPR€15,000
17 Apr 2026Provvedimento del 17 aprile 2026 [10254325]The supervisory authority found that a video surveillance system with 25 cameras operated without the required informational signage. The breach concerned GDPR information obligations.ITGaranteGDPR€3,000
31 Jan 2019Azienda Sanitaria Locale di AlessandriaAzienda Sanitaria Locale di Alessandria was fined by the Garante 16,000 EUR for processing personal data through the health dossier without full compliance with data protection rules. The case concerned improper handling of sensitive data in a medical system.ITGaranteGDPR€16,000
09 Mar 2023Aesse S.r.l.s.Aesse S.r.l.s. was fined by the Italian Garante in the amount of €3,000. The case concerned unsolicited telemarketing calls made without consent and insufficient information provided about the source of personal data.ITGaranteGDPR€3,000
16 Sept 2021Istituto Comprensivo - IC Cosenza III “V. Negroni”Istituto Comprensivo - IC Cosenza III “V. Negroni” was fined by the Garante 2,000 EUR for unlawful processing of personal data and inadequate data protection. The authority also noted that personal data were made accessible online, increasing the risk to affected individuals.ITGaranteGDPR€2,000
18 Apr 2018Marigliano GianpaoloMarigliano Gianpaolo was fined by the Garante 50,000 EUR for unlawfully using personal data to activate 15 phone cards without the consent of the individuals concerned. The case indicates a breach of lawful processing requirements and consent rules.ITGaranteGDPR€50,000
16 Feb 2017Momax s.r.l.Momax s.r.l. was fined by the Garante for improper handling of telephone traffic data. The authority found failures to implement appropriate safeguards, including strong authentication and biometric recognition measures, and retention of data beyond the permitted period for billing and crime prevention purposes.ITGaranteGDPR€60,000
17 Jul 2025Associazione Il Cavallo Rosa/ChangeTheGame ODVThe Garante fined Associazione Il Cavallo Rosa/ChangeTheGame ODV 10,000 EUR for publishing a minor’s personal data on its Facebook page without anonymization. The authority found a breach of the data subject’s rights under the GDPR.ITGaranteGDPR€10,000