Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Feb 2026Istituto Tecnico Statale L. 80014050357Istituto Tecnico Statale was fined by the Garante for breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization. The school improperly published personal data on its website.ITGaranteGDPR€2,000
29 Apr 2026Lepida S.c.p.A.Lepida S.c.p.A. was fined by the Italian supervisory authority Garante €100,000 for unauthorized access and data handling violations linked to SPID digital identity management. The authority found breaches of GDPR Articles 25 and 32, covering data protection by design and security of processing.ITGaranteGDPR€100,000
04 Dec 2014Itala s.p.aItala s.p.a was fined EUR 4,000 by the Garante for processing personal data related to job applications without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€4,000
05 Aug 2022Colosseo S.r.l.Colosseo S.r.l. was fined EUR 1,000 by the Garante for sending unsolicited promotional emails without prior recipient consent. The authority found this breached GDPR rules on lawful processing and consent.ITGaranteGDPR€1,000
22 May 2018Ordinanza ingiunzione - 22 maggio 2018 [9027240]A general practitioner was fined for failing to adopt minimum security measures in a health information system. The deficiencies allowed unauthorized access to the data.ITGaranteGDPR€10,000
28 Apr 2022Ministero della DifesaMinistero della Difesa was fined EUR 10,000 by the Garante for improperly disclosing personal data, including health-related information, to unauthorized personnel. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€10,000
10 Nov 2011C.O.E.STRA. S.p.A.C.O.E.STRA. S.p.A. was fined EUR 30,000 by the Italian data protection authority, Garante. The sanction concerned the failure to appoint data processing officers, which breached the minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€30,000
21 Mar 2018Ditta individuale Smile di Remmert OriettaThe company was fined for processing the personal data of 36 individuals without consent in connection with training enrollments. It also submitted false documents to the Province of Turin to account for courses that were never conducted.ITGaranteGDPR€40,000
17 Mar 2016Università degli studi di FoggiaUniversità degli studi di Foggia was fined 4,000 EUR by the Garante for unlawfully disclosing health-related data to third parties. The authority found that the disclosure lacked an appropriate legal basis and breached privacy rules.ITGaranteGDPR€4,000
10 Jul 2025Comune di ConversanoComune di Conversano was fined €3,000 by the Garante for failing to communicate the contact details of its Data Protection Officer. The breach concerned the obligation under Article 37 GDPR to notify the supervisory authority.ITGaranteGDPR€3,000
11 Feb 2016Circolo ricreativo D.D. PeckerCircolo ricreativo D.D. Pecker was fined by the Garante for providing inadequate information to data subjects about the processing of their personal data. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
12 May 2011Centrale Palace HotelCentrale Palace Hotel was fined EUR 6,000 by the Garante. The violation concerned the failure to provide the required privacy notice for its video surveillance system, in breach of the Italian data protection code.ITGaranteGDPR€6,000
01 Mar 2018Priolo Servizi S.c.p.A.Priolo Servizi S.c.p.A. was fined EUR 52,000 for the unlawful processing of biometric data of about 6,700 workers. The authority found that the company failed to properly notify the Garante and provided inadequate information to the data subjects.ITGaranteGDPR€52,000
15 Jan 2020Comune di Francavilla FontanaThe Municipality of Francavilla Fontana was fined 10,000 EUR by the Garante for publishing personal data on its institutional website. The conduct breached data protection rules and triggered supervisory action.ITGaranteGDPR€10,000
18 Mar 2025JRSY Laser LimitedThe Jersey Data Protection Authority fined JRSY Laser Limited 500 GBP following an investigation opened on 27 March 2024. The case concerned a breach of data protection requirements by the data controller.JEJOICGDPR€594
25 Mar 2025Star Delta Electrical ServicesThe Jersey Data Protection Authority fined Jon Peacock t/a Star-Delta Electrical Services £4,000. The case arose from a client complaint concerning the handling of personal data by the sole trader. The penalty was issued under the Data Protection (Jersey) Law 2018.JEJOICGDPR€4,787
10 Oct 2023UAB RamidonasThe supervisory authority imposed a €6,000 fine on UAB Ramidonas for personal data security violations. The case concerned deficiencies in data protection controls that could have exposed individuals’ information to risk.LTValstybinė duomenų apsaugos inspekcijaGDPR€6,000
01 Jan 2024UAB VintedUAB Vinted received a EUR 2.385 million GDPR fine in Lithuania. The authority cited issues in user data processing, handling of data subject rights, and risk management.LTValstybinė duomenų apsaugos inspekcijaGDPR€2,385,000
01 Feb 2026Biržų ligoninėVDAI imposed a EUR 6,000 fine on Biržų ligoninė for improper processing of personal data. The case concerns a breach of data protection requirements and indicates non-compliance with GDPR obligations.LTVDAIGDPR€6,000
13 Dec 2022Anonymisé (CNPD decision-23-fr-2022)The company failed to meet the transparency obligations under Article 12(1) GDPR by not providing the required information in a concise, transparent, and easily accessible manner. CNPD treated this as a breach of the information duties owed to data subjects.LUCNPDGDPR€1,300