Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Aug 2022Mister Brick S.a.s.Mister Brick S.a.s. was fined EUR 1,000 by the Garante for sending an unsolicited promotional email without obtaining prior consent from the recipient. The authority found this to be a breach of GDPR requirements on lawful processing and consent.ITGaranteGDPR€1,000
22 Jul 2021Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5)Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5) was fined EUR 4,000 by the Garante for violations related to the processing of personal data, including health data, during the COVID-19 pandemic. The case concerned improper handling of sensitive data in the context of pandemic-related activities.ITGaranteGDPR€4,000
20 Oct 2022Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined by the Garante €40,000 for failing to provide a data subject with access to personal data relating to derivative transactions. The authority found a breach of the principles of lawful, fair, and transparent processing.ITGaranteGDPR€40,000
11 Feb 2016E-Via s.p.a.E-Via s.p.a. was fined 10,000 EUR by the Garante for failing to implement minimum security measures in the processing of telematic traffic data. The authority found a breach of Article 33 of the Italian Data Protection Code.ITGaranteGDPR€10,000
28 May 2026Action Fit di MilanoThe Garante fined Action Fit di Milano EUR 3,930 for sending unsolicited commercial emails to a customer without consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€3,930
31 Aug 2023RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined by the Garante EUR 10,000 for publishing an article on the Corriere della Sera website. The article included a photograph of a holographic will that disclosed a witness’s personal data without consent.ITGaranteGDPR€10,000
11 Feb 2016Vito Roma s.r.l.Vito Roma s.r.l. was fined by the Garante for operating a video surveillance system without providing the required data protection notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
18 Apr 2013Itel s.r.l. UnipersonaleItel s.r.l. Unipersonale was fined EUR 102,000 by the Garante for improper processing of personal data. The case involved registering phone cards to third parties without their knowledge, in breach of privacy rules.ITGaranteGDPR€102,000
13 Feb 2025MDE – Movimento Diritti Europei s.r.l.s.MDE – Movimento Diritti Europei s.r.l.s. was fined 15,000 EUR by the Garante. The authority found that the company failed to provide shareholders with the information required under GDPR Article 14 and instead referred them to a website that did not contain sufficient details.ITGaranteGDPR€15,000
17 Jul 2024Mark s.r.l.s.Mark s.r.l.s. was fined by the Garante for operating a video surveillance system without the required signage. The case concerned a breach of GDPR information obligations.ITGaranteGDPR€5,000
01 Oct 2015Semplice viaggi s.r.l.Semplice viaggi s.r.l. was fined EUR 6,400 by the Garante for providing insufficient information to users on its website and for pre-setting consent to the processing of personal data for promotional purposes. The authority found these practices to be in breach of data protection rules.ITGaranteGDPR€6,400
06 Nov 2014Fengfeng WuFengfeng Wu was fined by the Garante in the amount of EUR 2,400 for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system at Bar Wu Fengfeng in Milan. The case concerns a breach of transparency and information obligations linked to CCTV processing.ITGaranteGDPR€2,400
09 May 2024Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante for violations related to telemarketing and teleselling. The authority found that individuals listed in the opposition register were contacted without proper consent.ITGaranteGDPR€500,000
17 Oct 2013Ideal Service srlIdeal Service srl was fined by the Garante EUR 2,400 for sending promotional emails without the required privacy information. The authority found this to be a breach of Article 161 of the Italian Data Protection Code.ITGaranteGDPR€2,400
14 Apr 2011Trentino Trasporti Esercizio S.p.A.Trentino Trasporti Esercizio S.p.A. was fined by the Garante 25,000 EUR for collecting personal data through web forms without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€25,000
11 Apr 2024Comune di MadignanoThe Garante fined Comune di Madignano EUR 3,000 for unlawfully using surveillance data in a disciplinary proceeding against an employee. The authority found breaches of data protection and transparency principles.ITGaranteGDPR€3,000
10 Jun 2020Istituto autonomo per le case popolari della provincia di IserniaIstituto autonomo per le case popolari della provincia di Isernia was fined EUR 2,000 by the Garante. The authority found that personal data, including health information, had been published on the institutional website without a proper legal basis.ITGaranteGDPR€2,000
26 Feb 2026Dedalus Italia S.p.A.Dedalus Italia S.p.A. was fined EUR 32,000 by the Garante for inadequate security measures that led to a data breach. The company implemented corrective actions promptly, but prior violations were taken into account when setting the penalty.ITGaranteGDPR€32,000
19 Sept 2013dott. Luigi Ventronedott. Luigi Ventrone was fined for failing to respond to requests for information concerning the processing of personal data in connection with a complaint by Ms. Ilaria Corsale. The authority found a breach of Article 157 of the Italian Data Protection Code.ITGaranteGDPR€4,000
01 Dec 2022Amazon Italia Logistica s.r.l.Amazon Italia Logistica s.r.l. was fined by the Garante for delaying its response to a data subject’s request to access professional certificates. The authority found a breach of Article 15 GDPR.ITGaranteGDPR€20,000