Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Apr 2015Midolo MichelaMidolo Michela was fined EUR 15,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€15,000
09 Oct 2025FT Solutions S.r.l.FT Solutions S.r.l. was fined by the Garante 5,000 EUR for processing personal data for marketing purposes without proper consent. The case involved more than 2 million records and resulted in unauthorized telemarketing activities.ITGaranteGDPR€5,000
21 Dec 2023Impresa individuale Macelleria Salumeria HalalThe Garante fined the owner of Impresa individuale Macelleria Salumeria Halal EUR 2,000 for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency and data processing requirements.ITGaranteGDPR€2,000
12 Feb 2026Bressanelli Galli Gelpi Porta & C. S.r.l.The company was fined EUR 15,000 by the Garante for sending promotional emails without prior consent from recipients. The authority found this to be a breach of GDPR principles, including Article 5.ITGaranteGDPR€15,000
09 Oct 2014Zhao ShujuanZhao Shujuan was fined by the Garante for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system. This constituted a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
16 Sept 2021Accademia di Belle Arti di RomaAccademia di Belle Arti di Roma was fined EUR 5,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data in a disciplinary procedure and the dissemination of sensitive information.ITGaranteGDPR€5,000
09 Oct 2025Sicuritalia S.p.A.Sicuritalia S.p.A. was fined EUR 500,000 by the Italian supervisory authority Garante. The case concerned unauthorized access to a former employee's email account after employment ended, in breach of GDPR requirements.ITGaranteGDPR€500,000
21 Mar 2024LAZIOcrea S.p.a.LAZIOcrea S.p.a. was fined by the Garante for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies led to unauthorized access attempts and temporary unavailability of regional services.ITGaranteGDPR€271,000
21 Jan 2016Malta Games di Belgiorno Chiara & C. s.a.s.Malta Games di Belgiorno Chiara & C. s.a.s. was fined EUR 2,400 by the Garante. The authority found that the company failed to provide the required information to data subjects about personal data processing through a video surveillance system.ITGaranteGDPR€2,400
18 Feb 2010Fibrille s.r.l.Fibrille s.r.l. was fined EUR 6,000 by the Garante for processing personal data from job applicants' CVs without providing the required information. The authority found a breach of the notice obligation under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
06 Jun 2018Dalmesse Italia s.r.l.Dalmesse Italia s.r.l. was fined €22,000 by the Italian supervisory authority, Garante. The case concerned the processing of personal data, including sensitive health data, without proper compliance with data protection rules.ITGaranteGDPR€22,000
31 Jan 2019CT BARCT BAR was fined by the Garante for unlawful processing of personal data through its video surveillance system. The recordings were retained for 15 days without proper compliance with applicable rules.ITGaranteGDPR€12,000
01 Jun 2023AUSL Toscana Sud EstThe Garante fined AUSL Toscana Sud Est 20,000 EUR for the unlawful dissemination of a patient's health data. The authority found a breach of data protection principles.ITGaranteGDPR€20,000
09 Jun 2016Comune di LevantoThe Municipality of Levanto was fined EUR 4,000 by the Garante for publishing on its website a list of candidates for regional contributions. The disclosure of personal data lacked sufficient legal basis and breached data protection rules.ITGaranteGDPR€4,000
22 Feb 2024Sigma s.r.l.Sigma s.r.l. was fined EUR 150,000 by the Garante for unauthorized activation of paid services and devices using customer data without consent. The authority found that the company’s conduct breached GDPR rules on personal data processing.ITGaranteGDPR€150,000
17 Oct 2024ComuneThe Garante fined Comune EUR 8,000 for breaches of GDPR Articles 5, 6 and 9, and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data in the context of public employment and administrative transparency.ITGaranteGDPR€8,000
25 Sept 2025E-Power S.r.l.E-Power S.r.l. was fined EUR 35,000 by the Garante for making promotional calls without a valid legal basis. The authority also found that the company failed to respond to data subject rights requests, which breaches GDPR requirements.ITGaranteGDPR€35,000
27 Nov 2024Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 20,000 EUR for publishing employees’ personal data without a legal basis. The disclosure included details on additional payments, sickness absences, and union rights, breaching the GDPR and the national privacy code.ITGaranteGDPR€20,000
26 Jun 2008Contact point s.r.l.Contact point s.r.l. was fined by the Garante 10,000 EUR for breaching data protection rules. The case concerned improper handling of personal data during opinion surveys.ITGaranteGDPR€10,000
13 Feb 2014Roma CapitaleRoma Capitale was fined for unlawfully publishing personal data related to a disciplinary action on its institutional website. The authority found that this conduct violated Article 19 of the Italian Data Protection Code.ITGaranteGDPR€10,000