Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Sept 2007Azienda sanitaria locale Avellino 1Azienda sanitaria locale Avellino 1 was fined by the Garante in the amount of 10,000 EUR. The authority found that the entity failed to notify the processing of sensitive personal data, including genetic and biometric data, as required by the Italian Data Protection Code.ITGaranteGDPR€10,000
23 Dec 2010Bitmovers s.r.l.Bitmovers s.r.l. was fined by the Garante 6,000 EUR for collecting personal data through its website without the required information notice. The case concerned a breach of the Italian Data Protection Code.ITGaranteGDPR€6,000
23 Mar 2023Ministero dell’InternoMinistero dell’Interno was fined EUR 4,000 by the Garante for unlawfully communicating personal data, including health information, to the police without proper justification. The case concerned a breach of lawfulness and purpose limitation requirements.ITGaranteGDPR€4,000
16 Dec 2021Università Telematica Internazionale UninettunoUniversità Telematica Internazionale Uninettuno was fined EUR 1,000 by the Italian supervisory authority Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€1,000
13 Mar 2014Paolo ZaniniPaolo Zanini was fined EUR 4,000 by the Garante for sending unsolicited promotional faxes. The conduct breached data protection rules and the requirement for prior consent for marketing communications.ITGaranteGDPR€4,000
06 Feb 2020Azienda Unità Sanitaria Locale Toscana CentroAzienda Unità Sanitaria Locale Toscana Centro was fined by the Garante 10,000 EUR for violations related to data processing in the health sector. The case concerned the handling of patient data without full compliance with GDPR requirements.ITGaranteGDPR€10,000
20 Apr 2017Hotel Savoia Genova s.r.l.Hotel Savoia Genova s.r.l. was fined €16,800 by the Garante. The authority found that the company failed to provide the required information to individuals about its video surveillance system and kept surveillance footage longer than permitted.ITGaranteGDPR€16,800
10 Jul 2025Centro Medico Italiano S.r.l.Centro Medico Italiano S.r.l. was fined by the Garante 30,000 EUR for failing to provide an adequate response to a data subject’s request for access to health data and information about its processing. The authority found a breach of GDPR Article 15.ITGaranteGDPR€30,000
13 Nov 2024Comune di UgentoThe Garante fined Comune di Ugento 2,400 EUR for publishing data on its website that could reveal individuals' health status. The case involved the improper disclosure of sensitive information in a public online setting.ITGaranteGDPR€2,400
03 Jun 2010ICTS Italia s.r.l.ICTS Italia s.r.l. was fined by the Garante for using a biometric system for employee access control and attendance without adequate notice, consent, or minimum security measures. The company also failed to notify the Garante.ITGaranteGDPR€18,400
12 May 2022Comune di VillabateComune di Villabate was fined 6,000 EUR for failing to update the Data Protection Officer’s contact details on its website and in communications with the Authority. The conduct was found to breach the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€6,000
06 Jun 2024Azienda Usl RomagnaThe Garante fined Azienda Usl Romagna EUR 24,000 for data protection violations related to the management of health data. The case concerned irregularities in the processing of sensitive data, which requires heightened safeguards and GDPR compliance.ITGaranteGDPR€24,000
14 May 2026Comune di VentassoComune di Ventasso was fined EUR 8,000 by the Garante. The authority found breaches of the principles of lawful, fair and transparent processing of personal data, as well as data minimization.ITGaranteGDPR€8,000
15 Jun 2017F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante in the amount of 10,000 EUR for making unsolicited promotional calls to a number listed in the public opposition registry. The conduct breached data protection rules and the right to object to direct marketing.ITGaranteGDPR€10,000
27 Nov 2025Verisure Italy s.r.l.Verisure Italy s.r.l. was fined by the Garante EUR 400,000 for breaches of data retention and information obligations in connection with marketing activities. The case concerned customer and former customer data processed without proper consent and notice.ITGaranteGDPR€400,000
11 Sept 2025Comune di NichelinoComune di Nichelino was fined EUR 18,000 by the Garante for failing to provide an adequate response to a data subject's request to exercise their rights. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€18,000
16 Nov 2023Provvedimento del 16 novembre 2023 [9960948]The Garante imposed an EUR 18,000 fine on a training company for the unauthorized online publication of personal data relating to health. The case concerned breaches of GDPR Articles 5 and 32 on data processing principles and security.ITGaranteGDPR€18,000
29 Jan 2015Azienda Ospedaliera Universitaria Policlinico Sant'Orsola-MalpighiAzienda Ospedaliera Universitaria Policlinico Sant'Orsola-Malpighi was fined EUR 2,400 by the Garante. The authority found that personal data collected through the website’s “contact us” form was processed without the required privacy notice, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
14 Sept 2006Azienda sanitaria locale n. 6 di CirièASL Ciriè was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The breach concerned obligations under the Italian Privacy Code.ITGaranteGDPR€10,000
23 Feb 2017Lucini & Lucini Communication LtdLucini & Lucini Communication Ltd was fined EUR 72,000 by the Garante. The authority found that the company collected personal data through its websites and sent promotional emails without proper consent.ITGaranteGDPR€72,000