Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Apr 2026Azienda Sanitaria Locale di MateraAzienda Sanitaria Locale di Matera was fined by the Garante EUR 8,600 after a data breach caused by a ransomware attack. The incident led to the exfiltration of personal data, and the authority found inadequate technical and organizational measures to protect data security.ITGaranteGDPR€8,600
22 Feb 2018Comune di FiumicinoComune di Fiumicino was fined by the Garante for failing to notify a data breach within the required timeframe. The authority found a violation of the Italian Data Protection Code.ITGaranteGDPR€30,000
14 May 2026FeGi M&A Services s.r.l.FeGi M&A Services s.r.l. was fined EUR 1,000 by the Garante for making promotional phone calls without the required consent. The authority found this conduct breached GDPR principles of fairness and transparency.ITGaranteGDPR€1,000
08 Mar 2018Tekne Progetti s.r.l.Tekne Progetti s.r.l. was fined for failing to respond to an information request from the Garante concerning its data processing activities. The conduct was found to violate Article 164 of the Italian Privacy Code.ITGaranteGDPR€20,000
23 Jan 2008Italmarmo di Rossin EzioItalmarmo di Rossin Ezio was fined EUR 4,000 by the Garante for failing to provide timely access to personal data upon request. The case concerned non-compliance with data protection obligations.ITGaranteGDPR€4,000
22 Feb 2024L’Igiene Urbana Evolution s.r.l.L’Igiene Urbana Evolution s.r.l. was fined €70,000 by the Garante for unlawfully processing biometric data through facial recognition to monitor employee attendance. The authority found that this practice violated GDPR requirements.ITGaranteGDPR€70,000
11 Apr 2024Istituto Nazionale Previdenza Sociale - INPSThe Italian Data Protection Authority fined INPS EUR 20,000 for violating data protection principles. The case concerned the improper handling of candidates’ personal data in a public competition.ITGaranteGDPR€20,000
11 Jan 2023Società Europea di Edizioni S.p.a.The Garante fined Società Europea di Edizioni S.p.a. EUR 10,000 for publishing non-anonymized personal data concerning an individual's health status in an article. This constituted a breach of data protection rules.ITGaranteGDPR€10,000
17 Oct 2013Annamaria FazziniAnnamaria Fazzini was fined EUR 2,400 by the Garante for failing to provide the required privacy notice for a video surveillance system at her business. The case concerns non-compliance with the obligation to inform individuals about the processing of their personal data.ITGaranteGDPR€2,400
26 Oct 2011Smart s.n.c.Smart s.n.c. was fined EUR 12,800 by the Garante. The authority found that the company sent promotional emails without the recipients’ prior explicit consent.ITGaranteGDPR€12,800
05 Feb 2015Comune di MerìComune di Merì was fined EUR 10,000 by the Garante for unlawfully publishing sensitive personal data on its website. The disclosure included information about individuals' health status and mandatory medical treatments, breaching data protection rules.ITGaranteGDPR€10,000
18 Jun 2015Comune di MurosComune di Muros was fined EUR 12,000 by the Garante. The authority found that the municipality failed to provide information and unlawfully published personal data revealing health status on its website.ITGaranteGDPR€12,000
11 Mar 2010Impresa individuale Bellusci MirellaThe company was fined for processing personal data by receiving CVs from aspiring agents without providing the required privacy notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
26 Jul 2012Meeting s.r.l.Meeting s.r.l. was fined by the Garante in the amount of 6,000 EUR for providing inadequate information to clients. The case concerned a breach of Article 13 of the Italian Data Protection Code, which requires proper notice to data subjects.ITGaranteGDPR€6,000
25 Jul 2013Axis Strategic Vision srlAxis Strategic Vision srl was fined by the Garante in the amount of 4,800 EUR for providing inadequate privacy notices on its websites. The authority found that the notices did not meet data protection requirements.ITGaranteGDPR€4,800
13 Sept 2007Asl Enna 4The Garante fined Asl Enna 4 EUR 10,000 for processing personal data, including genetic and biometric data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
10 Mar 2022Agenzia Regionale per la Tutela dell'Ambiente dell'AbruzzoThe Regional Agency for Environmental Protection of Abruzzo was fined by the Garante €8,000 for breaches of data protection principles. The violations concerned lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€8,000
03 Oct 2013Telecom Italia s.p.a.Telecom Italia s.p.a. was fined 80,000 EUR by the Garante for making unsolicited promotional calls to a customer. The calls were made after the customer had withdrawn consent for such communications, which breached data protection rules.ITGaranteGDPR€80,000
21 Apr 2021Società Eurosanità s.p.a.Società Eurosanità s.p.a. was fined by the Garante in the amount of 5,000 EUR for a breach involving the processing of health data. The authority found violations of GDPR Articles 5 and 9, indicating improper handling of special category personal data.ITGaranteGDPR€5,000
09 Dec 2010Circolo Privato PirliCircolo Privato Pirli was fined EUR 6,000 by the Garante for failing to provide the required privacy notice to individuals entering the premises. The breach concerned the Italian Data Protection Code and the Garante's video surveillance guidelines.ITGaranteGDPR€6,000