Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Dec 2023Azienda OspedalieraAzienda Ospedaliera was fined EUR 8,000 by the Garante for breaches of data protection rules. The case concerned data processing principles and insufficient security measures.ITGaranteGDPR€8,000
30 Jan 2014Orovicenza di Picaro CristinaOrovicenza di Picaro Cristina was fined EUR 4,800 by the Garante. The authority found that the website’s contact and registration forms did not provide the required data protection information, in breach of the Italian data protection code.ITGaranteGDPR€4,800
11 Jan 2023Reweb s.r.l.Reweb s.r.l. was fined 5,000 EUR by the Garante. The company kept a former employee’s email account active and accessed it after the employment relationship ended, in breach of GDPR requirements.ITGaranteGDPR€5,000
03 May 2018Ordinanza ingiunzione - 3 maggio 2018 [9023941]A fine of EUR 20,000 was imposed for failing to notify the Garante about the processing of geolocation data collected through GPS devices. The case concerns a breach of the Italian Data Protection Code.ITGaranteGDPR€20,000
12 Oct 2023Scionti Selezioni Superiori S.r.l.Scionti Selezioni Superiori S.r.l. was fined EUR 70,000 by the Garante for failing to implement adequate measures to prevent unauthorized access to customer data. The data was then used for promotional purposes without the individuals' consent.ITGaranteGDPR€70,000
12 Feb 2015Visini FabioVisini Fabio was fined EUR 12,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection requirements.ITGaranteGDPR€12,000
16 May 2018Conafi Prestitò s.p.a.Conafi Prestitò s.p.a. was fined by the Garante for failing to notify certain data processing activities related to loan management. The breach concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€20,000
15 Jan 2015Barta s.r.l.Barta s.r.l. was fined by the Garante EUR 12,000 for operating a video surveillance system without prior authorization. Footage was retained for 15 days, exceeding the permitted one-week period.ITGaranteGDPR€12,000
28 Mar 2019Comune di GenovaComune di Genova was fined for unlawfully communicating personal data to third-party companies without a proper legal basis. The authority found a breach of data protection rules.ITGaranteGDPR€8,000
13 Jan 2022Azienda sanitaria unica regionale MarcheAzienda sanitaria unica regionale Marche was fined EUR 14,000 by the Garante for inadequate data protection measures. The breach involved health data and was linked to QR code generation; improved security measures were later implemented.ITGaranteGDPR€14,000
17 Jul 2025Poliambulatorio San Liberale S.r.l.The Garante imposed a EUR 12,500 fine on Poliambulatorio San Liberale S.r.l. for failing to meet information and transparency obligations in the processing of personal data, including health data. The company also did not respond to a data access request, adding a further breach of data subject rights.ITGaranteGDPR€12,500
19 Feb 2015Andrea AngeloniAndrea Angeloni was fined by the Garante for sending unsolicited promotional letters. The entity also failed to respond to information requests from the supervisory authority.ITGaranteGDPR€10,000
13 Feb 2025Azienda ULSS n. 02573090236The public health company was fined for making a disciplinary proceeding document visible to unauthorized employees. The authority found breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€4,000
04 May 2017Starweb s.r.l.Starweb s.r.l. was fined €16,000 by the Garante for making unsolicited promotional calls. The authority found that the company failed to provide the required information notice and did not obtain consent from the contacted individuals.ITGaranteGDPR€16,000
14 Jun 2018Faiella Nicola s.r.l.Faiella Nicola s.r.l. was fined EUR 112,000 by the Garante for improper processing of personal data using geolocation and video surveillance systems. The authority found that the company did not comply with data protection requirements when deploying these tools.ITGaranteGDPR€112,000
02 Jul 2015Lycamobile s.r.l.Lycamobile s.r.l. was fined EUR 102,000 by the Garante for failing to provide requested information on the retention of telephone and telematic traffic data. The case concerned a breach of data protection rules.ITGaranteGDPR€102,000
25 Sept 2025Azienda Ospedaliero Universitaria di FerraraAzienda Ospedaliero Universitaria di Ferrara was fined EUR 20,000 by the Garante for irregularities in the handling of personal data in its health dossier system. The authority found that the organization failed to implement adequate measures to protect data privacy.ITGaranteGDPR€20,000
13 Nov 2025Maviglia Assicurazioni snc di Gherardo Maviglia & c.Maviglia Assicurazioni was fined by the Garante 10,000 EUR for unlawful processing of personal data. The case involved automatic email redirection and indefinite retention of email logs and content, which breached GDPR principles.ITGaranteGDPR€10,000
27 Feb 2025Ministero dell’Interno-Dipartimento per gli affari interni e territorialiThe Ministry of the Interior was fined EUR 3,000 for processing personal data through the CIE-Agenda Online service. The authority found that the processing did not comply with the principles of lawfulness, fairness, transparency, and purpose limitation.ITGaranteGDPR€3,000
23 May 2024Provvedimento del 23 maggio 2024 [10043051]The Garante imposed a fine of EUR 400 for the unlawful use of surveillance cameras capturing public areas without a proper legal basis. The conduct breached privacy and data protection requirements.ITGaranteGDPR€400