Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Mar 2016Zhu XiaozhenZhu Xiaozhen was fined by the Garante for failing to provide the simplified information required under the data protection code and the video surveillance rules. The surveillance system was operated without proper notice to the individuals concerned.ITGaranteGDPR€2,400
31 Mar 2016avv. Gioacchino GenchiAvv. Gioacchino Genchi was fined by the Italian Garante for creating a database containing personal data, including phone traffic data. The database was accessible to his collaborators, which breached data protection rules.ITGaranteGDPR€192,000
31 Mar 2016Pia GiordanoPia Giordano was fined by the Garante for collecting personal data through her website without providing users with the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
17 Mar 2016Ghi Mar di Ghidetti Roberto & Callegari F.lli s.n.c.Ghi Mar di Ghidetti Roberto & Callegari F.lli s.n.c. was fined EUR 2,400 by the Garante. The authority found that the company collected personal data, including name and email, through its website without providing the required privacy notice, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
17 Mar 2016Gruppo Scuole s.r.l. – Istituto Giuseppe Mazzini di AvezzanoGruppo Scuole s.r.l. was fined by the Garante for collecting personal data through its website without providing the required privacy notice and without obtaining consent. The authority found violations of Articles 13 and 23 of the Italian Privacy Code.ITGaranteGDPR€2,400
17 Mar 2016Belzirossi s.r.l.Belzirossi s.r.l. was fined by the Italian Garante in the amount of EUR 2,400. The case concerned the use of a video surveillance system without providing data subjects with the required information under data protection rules.ITGaranteGDPR€2,400
17 Mar 2016Caaf Consulenti del lavoro srlCaaf Consulenti del lavoro srl was fined EUR 4,800 by the Garante. The authority found that the company failed to provide the required privacy notice for data collected through its website contact form and video surveillance system, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€4,800
17 Mar 2016Giuseppe VesceraGiuseppe Vescera was fined by the Garante in the amount of 2,400 EUR for failing to provide adequate information to data subjects about video surveillance. The authority found a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
17 Mar 2016Aurelia FevolaAurelia Fevola was fined by the Garante for collecting personal data through her website without providing users with the required information notice. This conduct breached the Italian Data Protection Code.ITGaranteGDPR€2,400
17 Mar 2016Nico MannelliNico Mannelli was fined by the Garante EUR 2,400 for inadequate video surveillance signage and for failing to inform individuals about the purpose of processing and the data controller. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
17 Mar 2016Apcoa Parking Italia spaApcoa Parking Italia spa was fined EUR 4,800 by the Garante for improper use of surveillance images to enforce parking rules and recover debts. The authority also found inadequate data protection information on the company’s website and in its communications with data subjects.ITGaranteGDPR€4,800
17 Mar 2016Università degli studi di FoggiaUniversità degli studi di Foggia was fined 4,000 EUR by the Garante for unlawfully disclosing health-related data to third parties. The authority found that the disclosure lacked an appropriate legal basis and breached privacy rules.ITGaranteGDPR€4,000
10 Mar 2016Il Desiderio s.a.s.Il Desiderio s.a.s. was fined EUR 2,400 by the Garante for failing to provide adequate simplified information about video surveillance. The breach concerned Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
10 Mar 2016Ministero della giustizia – Dipartimento dell’amministrazione penitenziariaThe Ministry of Justice's Department of Penitentiary Administration was fined EUR 4,000 by the Garante for unlawful processing of personal data. The breach involved disclosing the names and details of prison police personnel who received overtime compensation.ITGaranteGDPR€4,000
09 Mar 2016PIXMANIA S.A.S.PIXMANIA S.A.S. was fined by the AEPD in the amount of €20,000 for sending unsolicited commercial emails to a user. The company continued sending messages despite multiple unsubscribe requests, which breached the LSSI.ESAEPDePrivacy€20,000
03 Mar 2016Comune di Ischia di CastroThe Municipality of Comune di Ischia di Castro was fined 4,000 EUR by the Garante for unlawfully publishing personal data of jury members on its online notice board for longer than the legally permitted period. The case concerned a breach of data protection rules and retention limits.ITGaranteGDPR€4,000
25 Feb 2016Sol Levante s.r.l.Sol Levante s.r.l. was fined EUR 12,000 by the Garante for retaining surveillance footage for 11 days. This exceeded the 7-day limit set out in the authority’s video surveillance guidelines.ITGaranteGDPR€12,000
25 Feb 2016Decatel s.r.l.Decatel s.r.l. was fined €10,000 by the Italian Garante. The case concerned the processing and retention of telephone traffic data without the required safeguards, including biometric recognition and strong authentication.ITGaranteGDPR€10,000
25 Feb 2016Associazione sportivo dilettantistica Feriolo Sporting ClubFeriolo Sporting Club was fined by the Garante 14,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority also found that recorded images were retained longer than permitted.ITGaranteGDPR€14,400
25 Feb 2016COF Lanzo Hospital SpaCOF Lanzo Hospital Spa was fined by the Garante for failing to respond to an information request concerning the handling of patient medical records. The authority found a breach of Article 164 of the Italian Data Protection Code.ITGaranteGDPR€4,000