Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Jun 2018Azienda Unità Sanitaria Locale di PiacenzaAzienda Unità Sanitaria Locale di Piacenza was fined by the Garante EUR 36,000 for creating electronic health records without informing patients or obtaining their consent. The authority found this to be a breach of privacy rules.ITGaranteGDPR€36,000
11 Feb 2021Azienda Unità Sanitaria Locale di ParmaAzienda Unità Sanitaria Locale di Parma was fined by the Garante €10,000 for improper handling of sensitive personal data. The violation was linked to an occasional malfunction of its IT system, which led to improper data processing.ITGaranteGDPR€10,000
30 Jan 2025Azienda Unità Sanitaria locale di ModenaAzienda Unità Sanitaria locale di Modena was fined by the Garante €10,000 for processing personal data concerning health and other sensitive information without a proper legal basis. The case involved unlawful processing of special-category data, which raises heightened compliance and privacy risks.ITGaranteGDPR€10,000
17 Jul 2024Azienda ULSS n. 14The Garante fined Azienda ULSS n. 14 EUR 22,000 for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies resulted in a data breach involving sensitive health data.ITGaranteGDPR€22,000
13 Feb 2025Azienda ULSS n. 02573090236The public health company was fined for making a disciplinary proceeding document visible to unauthorized employees. The authority found breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€4,000
17 May 2023Azienda ULSS 6 EuganeaThe Garante fined Azienda ULSS 6 Euganea 10,000 EUR for the incorrect handling of health-related documents. The authority found breaches of GDPR Articles 5, 6, and 32.ITGaranteGDPR€10,000
28 May 2026Azienda Tutela della Salute per la LiguriaAzienda Tutela della Salute per la Liguria was fined by the Garante 6,000 EUR for violations related to the processing of personal data using a satellite localization system in a disciplinary procedure against an employee. The case concerned the use of data in a manner that did not comply with data protection requirements.ITGaranteGDPR€6,000
21 Apr 2011Azienda Trasporti per l'Area Metropolitana S.p.A.Azienda Trasporti per l'Area Metropolitana S.p.A. was fined by the Garante €10,000 for failing to provide adequate data protection information on its website. The conduct breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€10,000
17 Nov 2010Azienda trasporti di MessinaAzienda trasporti di Messina was fined 20,000 EUR by the Garante for processing sensitive personal data without providing the required information notice and without obtaining consent from the data subjects. The case concerns breaches of core transparency and lawful-processing obligations.ITGaranteGDPR€20,000
28 May 2020Azienda Teatro del GiglioAzienda Teatro del Giglio was fined 6,000 EUR by the Garante for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€6,000
21 Jul 2022Azienda Socio Sanitaria Territoriale RhodenseAzienda Socio Sanitaria Territoriale Rhodense was fined by the Garante EUR 3,000 for violations of data protection rules. The case concerned data breaches and inadequate security measures.ITGaranteGDPR€3,000
23 May 2024Azienda Socio-sanitaria Territoriale RhodenseAzienda Socio-sanitaria Territoriale Rhodense was fined EUR 4,500 by the Garante for breaching GDPR Article 16. The case concerned data processing in the health sector, where strict compliance controls are required.ITGaranteGDPR€4,500
07 Dec 2023Azienda socio sanitaria territoriale nord MilanoAzienda socio sanitaria territoriale nord Milano was fined by the Garante EUR 40,000 for allowing unrestricted access to patient data across hospital departments. The authority found breaches of data minimization and purpose limitation principles during the COVID-19 emergency.ITGaranteGDPR€40,000
27 Jan 2022Azienda socio sanitaria territoriale Nord di MilanoAzienda socio sanitaria territoriale Nord di Milano was fined by the Garante 20,000 EUR for failing to implement adequate security measures to protect personal data. The authority found a breach of GDPR provisions on data protection and security.ITGaranteGDPR€20,000
29 Apr 2021Azienda socio sanitaria territoriale Melegnano e della MartesanaAzienda socio sanitaria territoriale Melegnano e della Martesana was fined by the Garante €6,000 for a data breach involving the loss of health data. The case concerned special-category personal data and indicates insufficient organizational or technical safeguards.ITGaranteGDPR€6,000
12 May 2022Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante €7,000 for violations related to the processing of health data. The authority also found insufficient data security measures.ITGaranteGDPR€7,000
29 Apr 2021Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante in the amount of 4,000 EUR for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization because personal data remained accessible online for an extended period.ITGaranteGDPR€4,000
18 Jul 2023Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest MilaneseThe Garante fined Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest Milanese 12,000 EUR for a data breach. Personal data was accessed without negative consequences for the data subjects. The organization took measures to prevent similar violations in the future.ITGaranteGDPR€12,000
21 Dec 2023Azienda socio-sanitaria localeThe Garante imposed a fine on a local health authority for violations related to the handling of sensitive personal data. The case concerned improper processing of special-category data, which breached data protection rules.ITGaranteGDPR€18,000
21 Jun 2018Azienda Semplice s.r.l.Azienda Semplice s.r.l. was fined by the Garante 16,000 EUR for unlawful processing of personal data used to place promotional calls to a private residential phone number without consent. The case concerns a lack of a lawful basis for marketing contact and a breach of data protection rules.ITGaranteGDPR€16,000