Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Apr 2024Libero Consorzio comunale di EnnaThe Garante fined Libero Consorzio comunale di Enna €6,000 for improperly assigning tasks to the Data Protection Officer. Those tasks should have been performed by the data controller or processor, not the DPO.ITGaranteGDPR€6,000
13 Mar 2025Istituto Alberghiero Mediterraneo di Pulsano (TA)Istituto Alberghiero Mediterraneo di Pulsano was fined EUR 2,000 by the Garante. The authority found breaches of the principles of lawfulness, fairness, and transparency in personal data processing.ITGaranteGDPR€2,000
25 Oct 2012Dario Flaccovio Editore s.r.l.Dario Flaccovio Editore s.r.l. was fined by the Garante 8,000 EUR for sending unsolicited promotional faxes without prior explicit consent. The conduct breached data protection rules and the requirement for lawful processing.ITGaranteGDPR€8,000
23 Jan 2020Azienda Ospedaliero Universitaria Integrata di VeronaAzienda Ospedaliero Universitaria Integrata di Verona was fined by the Garante EUR 30,000 for employees' unauthorized access to patient health records. The authority found a breach of GDPR principles on data protection and security measures.ITGaranteGDPR€30,000
09 Mar 2023Stefano MolenaThe Garante imposed a EUR 3,000 fine on Stefano Molena for operating a surveillance camera without the required informational signage. The breach concerned privacy rules and the duty to properly inform individuals subject to monitoring.ITGaranteGDPR€3,000
15 Sept 2022FCA Italy S.p.A.FCA Italy S.p.A. was fined by the Garante for failing to respond to a data subject's request for access to personal data related to employment. The authority found a breach of GDPR Article 15.ITGaranteGDPR€40,000
16 Nov 2023NEW BUY GOLD DI EMANUELE VITA & C. S.A.S.The company was fined EUR 1,000 by the Italian supervisory authority, Garante. The penalty was imposed because it operated a video surveillance system without the required information notice for data subjects, in breach of Article 13 GDPR.ITGaranteGDPR€1,000
15 Sept 2022Sofisticated Luxury Flats s.r.l.Sofisticated Luxury Flats s.r.l. was fined €2,000 by the Garante for using a biometric device to monitor employee attendance without a proper legal basis. The authority found that this practice breached data protection rules.ITGaranteGDPR€2,000
04 Aug 2025Azienda Ospedaliero Universitaria CareggiAzienda Ospedaliero Universitaria Careggi was fined by the Garante EUR 20,000 for violations related to the management of electronic health records. The authority found non-compliance with data protection requirements.ITGaranteGDPR€20,000
03 Apr 2014Torre Marina s.r.l.Torre Marina s.r.l. was fined €2,400 by the Italian Garante. The case concerned the collection of personal data through its websites without the required information notice under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
16 May 2018Ierardi TeresaIerardi Teresa, a general practitioner, was fined by the Garante for failing to adopt minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
18 Apr 2013Tel. Com. s.r.l.Tel. Com. s.r.l. was fined EUR 36,000 by the Garante for registering numerous phone cards to unaware third parties. The company failed to provide the required information on data processing, which breached privacy rules.ITGaranteGDPR€36,000
13 Sept 2007Comune di MoncalieriComune di Moncalieri was fined by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the notification obligation under Article 37 of the Italian Data Protection Code.ITGaranteGDPR€10,000
18 Jun 2015Azienda Ospedaliera Ospedale di Circolo Fondazione MacchiAzienda Ospedaliera Ospedale di Circolo Fondazione Macchi was fined by the Garante 4,000 EUR for processing sensitive personal data without obtaining written consent. This breached the Italian Data Protection Code. The case highlights the need for a valid legal basis before processing special-category data.ITGaranteGDPR€4,000
31 Jan 2019Istituto Statale di Istruzione Superiore “Guglielmo Marconi”Istituto Statale di Istruzione Superiore “Guglielmo Marconi” was fined by the Garante €4,000 for unlawfully processing personal data. The school published teacher rankings on its website that disclosed health information, breaching privacy rules.ITGaranteGDPR€4,000
29 May 2008Circolo privato 'Astoria'The private club “Astoria” was fined 3,000 EUR by the Garante for failing to provide the required data protection notice to individuals identified through its video surveillance system. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
17 Jul 2024Selectra S.p.A.Selectra S.p.A. was fined EUR 80,000 by the Garante for unlawfully accessing and retaining a former employee's email account after the end of the collaboration. The authority found that the company's conduct breached data protection rules.ITGaranteGDPR€80,000
18 Jul 2023Cat s.r.l.The Garante imposed a EUR 10,000 fine on Cat s.r.l. for operating a video surveillance system near waste bins in breach of the principles of lawfulness, fairness, and transparency. The case concerned the data of residents and non-residents of the Comune di Modica.ITGaranteGDPR€10,000
20 Jun 2013Terme di Agnano s.p.a.Terme di Agnano s.p.a. was fined EUR 16,000 by the Garante for processing personal and sensitive data of individuals undergoing thermal treatments without the required notice and consent. The authority also found that personal data of job applicants were processed without providing the mandatory information notice.ITGaranteGDPR€16,000
13 May 2015Comune di LandrianoComune di Landriano was fined for processing personal data of children enrolling in the municipal nursery without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400