Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Mar 2025Comune di Palma di MontechiaroThe Municipality of Comune di Palma di Montechiaro was fined EUR 3,000 by the Italian data protection authority, Garante. The sanction concerned the failure to communicate the contact details of its Data Protection Officer to the authority, as required by Article 37 GDPR.ITGaranteGDPR€3,000
14 Jan 2021Comune di Falconara MarittimaComune di Falconara Marittima was fined EUR 10,000 by the Garante for violating data protection principles. The authority found improper processing of personal data in a disciplinary context, including breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€10,000
05 Apr 2018Broker & Broker s.r.l.Broker & Broker s.r.l. was fined EUR 340,000 by the Italian authority Garante. The case concerned the registration of numerous phone cards to third parties without their knowledge or consent, which breached data protection rules.ITGaranteGDPR€340,000
12 Nov 2014Associazione sportiva dilettantistica Sport Fashion (A.S.D. Sport Fashion)The sports association was fined by the Garante 10,000 EUR for processing clients' biometric data without the required information and consent. The authority found this to be a breach of privacy rules.ITGaranteGDPR€10,000
26 Feb 2026Ministero dell’Economia e delle FinanzeThe Ministry of Economy and Finance was fined 12,000 EUR by Garante for inadequate control measures over the data processor. The authority found breaches of GDPR Articles 3, 5 and 6, as well as Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€12,000
13 May 2021ATS di Bergamo, Agenzia di Tutela della saluteATS di Bergamo was fined by the Garante 20,000 EUR for violations involving the improper handling of sensitive health data. The case concerned the use of email to transmit data, which did not provide an adequate level of protection.ITGaranteGDPR€20,000
18 Jun 2015Martino MarangellaMartino Marangella was fined EUR 2,400 by the Garante for failing to provide simplified information about the use of a video surveillance system. The authority treated this as a breach of data protection rules.ITGaranteGDPR€2,400
26 Feb 2026Flamel S.r.l.Flamel S.r.l. was fined by the Garante 15,000 EUR for carrying out promotional activities without a legal basis. The company used phone numbers not registered with the ROC, affecting the data of more than 500 individuals.ITGaranteGDPR€15,000
17 Dec 2020Comune di LuinoComune di Luino was fined EUR 10,000 by the Garante for unlawfully disclosing personal data online. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€10,000
29 Apr 2025Comune di NoliComune di Noli was fined EUR 2,000 by the Garante for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found a breach of data minimization because unauthorized access to unredacted images was possible through an online portal.ITGaranteGDPR€2,000
11 Jan 2024Provincia di CatanzaroThe Garante fined Provincia di Catanzaro EUR 2,000 for violations of data protection obligations under Article 37 GDPR. The case concerned non-compliance with requirements related to the designation of a data protection officer.ITGaranteGDPR€2,000
25 Feb 2016COF Lanzo Hospital SpaCOF Lanzo Hospital Spa was fined by the Garante for failing to respond to an information request concerning the handling of patient medical records. The authority found a breach of Article 164 of the Italian Data Protection Code.ITGaranteGDPR€4,000
04 Dec 2014Manca FedericoManca Federico was fined by the Garante in the amount of EUR 2,400 for failing to provide the required information to data subjects when collecting personal data through a web form on his website. The case concerns a breach of transparency and information duties in online data collection.ITGaranteGDPR€2,400
29 Nov 2018Istituto Nazionale Previdenza Sociale (INPS)INPS was fined for processing the personal data of 12.6 million private workers using automated software without prior verification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€40,000
13 Nov 2024Istituto Nazionale della Previdenza SocialeThe Italian Data Protection Authority fined Istituto Nazionale della Previdenza Sociale (INPS) EUR 40,000 for violations related to the processing of personal data for official statistics. The authority found that the processing did not comply with core data protection principles.ITGaranteGDPR€40,000
21 Sept 2017Unidata s.p.a.Unidata s.p.a. was fined EUR 36,000 by the Garante for failing to implement adequate security measures for personal data processing. The authority noted, among other issues, the use of passwords shorter than eight characters, which breached data protection requirements.ITGaranteGDPR€36,000
08 Mar 2018Riacetech S.r.l.Riacetech S.r.l. was fined for failing to notify the Garante about the installation of a biometric data processing system for employees. The case concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€20,000
29 Jan 2015Iper Market Yi-Gou s.r.l.Iper Market Yi-Gou s.r.l. was fined EUR 6,000 by the Italian supervisory authority, Garante. The case concerned the failure to provide the required information to data subjects about personal data processing through a video surveillance system.ITGaranteGDPR€6,000
01 Jun 2016Liceo Scientifico di Stato G. BattagliniLiceo Scientifico di Stato G. Battaglini was fined by the Garante 10,400 EUR for processing staff biometric data without providing the required information. The authority also found that the processing had not been notified as required by law.ITGaranteGDPR€10,400
17 Jul 2024Hera Comm S.p.A.Hera Comm S.p.A. was fined by the Garante 5,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy contracts and insurance policies with forged signatures.ITGaranteGDPR€5,000,000