Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Apr 2021Ordine degli Avvocati di RomaOrdine degli Avvocati di Roma was fined €2,000 by the Garante for a significant delay in responding to a data subject access request. The case highlights a failure to meet the required timelines for handling access requests under data protection rules.ITGaranteGDPR€2,000
25 Sept 2025La Prima SrlLa Prima Srl was fined EUR 10,000 by the Garante for sending unsolicited emails. The authority also found that the company failed to respond to a data deletion request, in breach of the GDPR.ITGaranteGDPR€10,000
02 Apr 2015Regione CalabriaRegione Calabria was fined EUR 80,000 by the Garante for failing to designate data processing officers and for only partially implementing IT security measures. The authority also noted a failure to respond to information requests, which required further investigation.ITGaranteGDPR€80,000
09 Mar 2023Consorzio Concessioni Reti Gas S.c.a.r.l.The Garante fined Consorzio Concessioni Reti Gas S.c.a.r.l. EUR 2,000 for GDPR breaches linked to the improper handling of email accounts and the failure to provide data processing information after an internship ended. The case highlights deficiencies in information duties and access control over personal data.ITGaranteGDPR€2,000
13 Apr 2023Azienda Ospedaliero Universitaria SeneseThe Garante fined Azienda Ospedaliero Universitaria Senese EUR 13,000 for violations related to the processing of personal data in the health sector. The case concerned data minimization and security measures.ITGaranteGDPR€13,000
14 Mar 2013Vinci s.r.l.Vinci s.r.l. was fined €6,000 by the Italian data protection authority, Garante. The case concerned the failure to provide the required privacy notice on the website contact form, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
29 Jan 2026Provincia della Congregazione dei Fratelli delle Suore CristianeThe entity was fined for failing to ensure sufficient transparency in data processing and for not carrying out a data protection impact assessment for workplace surveillance systems. The authority found breaches of the GDPR and the national privacy code.ITGaranteGDPR€12,000
22 May 2018Adolfo AllegriniAdolfo Allegrini, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
13 May 2021Agenzia di Tutela della Salute della Città metropolitana di MilanoAgenzia di Tutela della Salute della Città metropolitana di Milano was fined by the Garante 80,000 EUR for violations linked to data processing during an emergency. The authority found inadequate data protection measures and a failure to provide required information to data subjects.ITGaranteGDPR€80,000
27 Jun 2013New Company di Scattolin LorisNew Company di Scattolin Loris was fined EUR 6,400 by the Garante for making unsolicited promotional phone calls without proper consent. The conduct breached Articles 13 and 130 of the Italian Data Protection Code.ITGaranteGDPR€6,400
23 Oct 2014Simply Gold s.r.l.Simply Gold s.r.l. was fined by the Garante for collecting personal data through a website form without providing the required information notice to data subjects. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
13 Apr 2023Azienda Ospedaliera Universitaria di CagliariAzienda Ospedaliera Universitaria di Cagliari was fined EUR 8,000 by the Garante for unlawfully publishing personal data related to a disciplinary procedure online. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€8,000
09 Oct 2014Comune di Lamezia TermeThe Municipality of Lamezia Terme was fined 4,000 EUR by the Garante. The authority found that personal data, including names, tax codes, and IBANs, had been published on its website without a legal basis.ITGaranteGDPR€4,000
12 Dec 2024Istituto Comprensivo Statale CalenzanoIstituto Comprensivo Statale Calenzano was fined EUR 1,000 by the Garante for breaching data protection principles. The case concerned the processing of personal data without meeting the requirements of lawfulness, fairness, and transparency.ITGaranteGDPR€1,000
21 Feb 2013Elettrodomestici Parise sncElettrodomestici Parise snc was fined 222,000 EUR by the Italian Garante. The company improperly registered numerous phone cards to unaware third parties and then sold them to phone centers, breaching data protection rules.ITGaranteGDPR€222,000
14 Sept 2023Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined 42,000 EUR by the Garante for failing to provide timely access to personal data requested by a parent under GDPR Article 15. The authority said the delay resulted from an operational error that prevented timely handling of the request.ITGaranteGDPR€42,000
20 Nov 2014Andrea Romualdo CerriAndrea Romualdo Cerri was fined €2,400 by the Garante. The violation concerned failing to provide the required information to data subjects when collecting personal data through a web form on the company website.ITGaranteGDPR€2,400
13 Sept 2017Serval s.r.l.Serval s.r.l. was fined by the Garante in the amount of €10,000 for failing to adopt minimum security measures. The authority also found that employees were not appointed as data processors, in breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
15 Oct 2015Macellerie Rinaldo Giampaolo e figli sncMacellerie Rinaldo Giampaolo e figli snc was fined EUR 2,400 by the Garante. The authority found that the company failed to inform data subjects about the processing of personal data through a video surveillance system, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
17 Apr 2026Istituto “Ancelle della Compagnia della Regina dei Gigli”The Garante fined the school EUR 4,000 for processing students’ personal data without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000