Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Feb 2011Federconsorzi Dolomiti SuperskiFederconsorzi Dolomiti Superski was fined EUR 12,000 by the Italian Garante. The authority found that the company failed to provide the required data protection information to individuals, in breach of Articles 13 and 161 of the Italian Data Protection Code.ITGaranteGDPR€12,000
28 Jul 2016Jurica PavicJurica Pavic was fined by the Garante for failing to provide adequate information to data subjects about video surveillance. The authority found this to be a breach of privacy regulations.ITGaranteGDPR€2,400
11 Sept 2025Casa di Cura Città di RomaCasa di Cura Città di Roma was fined EUR 12,000 by the Garante for allowing unauthorized access to patient medical records. The case concerns a breach of data protection rules and indicates a need for stronger access controls.ITGaranteGDPR€12,000
06 Jul 2006Comune di AugustaThe Municipality of Augusta was fined by the Garante for failing to make a required notification under data protection law. The breach concerned Article 163 of the Codice Privacy.ITGaranteGDPR€5,164
18 Dec 2013Comune di MonticianoThe Municipality of Monticiano was fined 8,000 EUR by the Garante. The authority found a privacy violation after the municipality failed to provide requested information about the publication of personal data on its institutional website.ITGaranteGDPR€8,000
23 Oct 2025Provvedimento del 23 ottobre 2025 [10210718]The Garante imposed a EUR 10,000 fine on an individual tobacco shop owner for suspicious financial transactions involving the misuse of a third party’s identification data with a prepaid card. The case concerns unauthorized use of personal data in the context of payment operations.ITGaranteGDPR€10,000
13 Apr 2023Retimedia S.r.l.Retimedia S.r.l. was fined 2,500 EUR by the Garante for publishing detailed health data of an individual without consent. The conduct breached GDPR Article 9 on special categories of personal data.ITGaranteGDPR€2,500
03 May 2018Omis s.p.a.Omis s.p.a. was fined by the Garante 8,000 EUR for failing to notify the processing of geolocation data from vehicles. This notification was required under privacy regulations.ITGaranteGDPR€8,000
18 Nov 2015Zsa Zsa srlZsa Zsa srl was fined EUR 2,400 by the Italian Garante. The violation concerned the failure to provide the required privacy notice on the website’s data collection form, in breach of the Italian data protection code.ITGaranteGDPR€2,400
15 Jun 2011Azienda Multiservizi e Igiene Urbana S.p.A.Azienda Multiservizi e Igiene Urbana S.p.A. was fined for collecting personal data through a web form without providing users with the required privacy notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€9,000
30 Oct 2013Compagnia Assicuratrice Linear s.p.a.Compagnia Assicuratrice Linear s.p.a. was fined by the Garante 80,000 EUR for collecting personal data without specific consent for purposes beyond registration services. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€80,000
27 Jan 2022Azienda socio sanitaria territoriale Nord di MilanoAzienda socio sanitaria territoriale Nord di Milano was fined by the Garante 20,000 EUR for failing to implement adequate security measures to protect personal data. The authority found a breach of GDPR provisions on data protection and security.ITGaranteGDPR€20,000
12 Dec 2024BDM Banca S.p.A.BDM Banca S.p.A. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The sanction concerned the failure to provide a timely response to a data subject’s access request, which constitutes a breach of GDPR Article 15.ITGaranteGDPR€20,000
22 May 2018Wind Tre s.p.a.Wind Tre s.p.a. was fined by the Garante EUR 600,000 for conducting marketing campaigns without obtaining the required user consent. The conduct breached data protection rules.ITGaranteGDPR€600,000
13 Jun 2013Vito GiacoiaVito Giacoia was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned the failure to provide the required privacy notice for a video surveillance system at the “Fratelli Venaria” club, in breach of the Italian Privacy Code.ITGaranteGDPR€2,400
13 May 2015Barbirato Danilo s.a.s. di Barbirato Marco e c.Barbirato Danilo s.a.s. was fined by the Garante 16,800 EUR for failing to provide the required privacy notice on its data collection form. The authority also found breaches of CCTV rules, including inadequate signage and excessive retention of recorded images.ITGaranteGDPR€16,800
05 Feb 2015Comune di San Giuseppe JatoComune di San Giuseppe Jato was fined by the Garante for unlawfully publishing sensitive personal data revealing health status on its website. The conduct breached privacy rules governing the processing and disclosure of sensitive data.ITGaranteGDPR€10,000
05 Sept 2013Maria Vita PezzellaMaria Vita Pezzella was fined EUR 6,000 by Garante for failing to provide the required privacy notice in a video surveillance system. The case concerned a breach of the Italian Privacy Code and the duty to inform individuals subject to monitoring.ITGaranteGDPR€6,000
12 Sept 2013Azienda USL ViterboAzienda USL Viterbo was fined for failing to implement minimum security measures and for not appointing data processing officers. The authority also noted that the security program document was not updated between 2006 and 2010.ITGaranteGDPR€10,000
21 Jul 2022Azienda Socio Sanitaria Territoriale RhodenseAzienda Socio Sanitaria Territoriale Rhodense was fined by the Garante EUR 3,000 for violations of data protection rules. The case concerned data breaches and inadequate security measures.ITGaranteGDPR€3,000