Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Feb 2021Azienda Sanitaria Locale n. 2 Lanciano-Vasto-ChietiAzienda Sanitaria Locale n. 2 Lanciano-Vasto-Chieti was fined by the Garante 6,500 EUR for violations related to the processing of health data. The нарушения led to a data breach incident.ITGaranteGDPR€6,500
13 Jan 2022Azienda Sanitaria Locale FrosinoneAzienda Sanitaria Locale Frosinone was fined by the Italian supervisory authority, Garante, in the amount of EUR 7,500. The case concerned breaches of transparency and information duties in personal data processing under GDPR Articles 12 and 13.ITGaranteGDPR€7,500
14 Sept 2006Azienda sanitaria locale di PiacenzaAzienda sanitaria locale di Piacenza was fined for failing to notify the Garante about processing data relating to health and sexual life. The authority treated this as a breach of the Italian Privacy Code.ITGaranteGDPR€10,000
04 Apr 2007Azienda sanitaria locale di PescaraAzienda sanitaria locale di Pescara was fined €10,000 by the Garante for breaching data protection rules. The case involved improper handling of sensitive personal data, including genetic and health information, without the required notification to the authority.ITGaranteGDPR€10,000
29 Apr 2026Azienda Sanitaria Locale di MateraAzienda Sanitaria Locale di Matera was fined by the Garante EUR 8,600 after a data breach caused by a ransomware attack. The incident led to the exfiltration of personal data, and the authority found inadequate technical and organizational measures to protect data security.ITGaranteGDPR€8,600
13 Sept 2007Azienda sanitaria locale di Lanciano/VastoAzienda sanitaria locale di Lanciano/Vasto was fined by the Garante 10,000 EUR for improper handling of sensitive personal data. The case involved genetic and biometric data processed without proper authorization.ITGaranteGDPR€10,000
05 Mar 2020Azienda Sanitaria Locale di Ciriè, Chivasso e Ivrea (ASL TO4)ASL TO4 was fined by the Garante EUR 8,000 for unlawful data processing through video surveillance. The authority found that the required agreements with unions were not in place.ITGaranteGDPR€8,000
22 Jul 2021Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5)Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5) was fined EUR 4,000 by the Garante for violations related to the processing of personal data, including health data, during the COVID-19 pandemic. The case concerned improper handling of sensitive data in the context of pandemic-related activities.ITGaranteGDPR€4,000
11 Jan 2023Azienda Sanitaria Locale di BrindisiAzienda Sanitaria Locale di Brindisi was fined by the Garante 2,500 EUR for failing to respond to a data access request. The authority found a breach of GDPR Article 15.ITGaranteGDPR€2,500
22 Jul 2021Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 35,000 by the Garante for failing to adopt minimum security measures. The breach resulted in exposure of health data, creating a significant compliance and privacy risk.ITGaranteGDPR€35,000
02 Mar 2023Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 50,000 by the Garante for violations in the processing of personal data. The authority found non-compliance with the principles of data minimization and integrity and confidentiality.ITGaranteGDPR€50,000
28 Jun 2018Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined by the Garante €20,000 for sharing access credentials among employees. The authority found this to be a breach of data protection rules and access control requirements.ITGaranteGDPR€20,000
31 Jan 2019Azienda Sanitaria Locale di AlessandriaAzienda Sanitaria Locale di Alessandria was fined by the Garante 16,000 EUR for processing personal data through the health dossier without full compliance with data protection rules. The case concerned improper handling of sensitive data in a medical system.ITGaranteGDPR€16,000
14 Sept 2006Azienda sanitaria locale della provincia di MantovaThe local health authority in Mantua was fined for failing to notify the processing of personal data revealing health status and sexual life. The case concerned obligations under the privacy code.ITGaranteGDPR€10,000
14 Sept 2006Azienda sanitaria locale città di MilanoAzienda sanitaria locale città di Milano was fined by the Garante EUR 20,000 for improperly processing personal data concerning health and sexual life without adequate safeguards. The authority found that the processing breached data protection rules.ITGaranteGDPR€20,000
13 Sept 2007Azienda sanitaria locale Avellino 1Azienda sanitaria locale Avellino 1 was fined by the Garante in the amount of 10,000 EUR. The authority found that the entity failed to notify the processing of sensitive personal data, including genetic and biometric data, as required by the Italian Data Protection Code.ITGaranteGDPR€10,000
14 Sept 2023Azienda Sanitaria dell'Alto Adige - Suedtiroler SanitaetsbetriebThe Garante fined Azienda Sanitaria dell'Alto Adige EUR 10,000 for failing to provide an adequate response to a data subject's rights request. The case also concerned the processing of sensitive data related to vaccination status.ITGaranteGDPR€10,000
12 Dec 2024Azienda Sanitaria dell’Alto AdigeThe Garante imposed a fine on Azienda Sanitaria dell’Alto Adige for breaches of data protection rules. The case involved inadequate data handling and insufficient security measures.ITGaranteGDPR€5,000
05 Feb 2015Azienda Regionale per il diritto allo studio universitario della ToscanaAzienda Regionale per il diritto allo studio universitario della Toscana was fined EUR 10,000 by the Garante. The authority found that its website unlawfully disclosed personal data revealing the health status of students with disabilities.ITGaranteGDPR€10,000
21 Apr 2021Azienda provinciale per i servizi sanitari di TrentoAzienda provinciale per i servizi sanitari di Trento was fined by the Garante EUR 40,000 for violations related to the processing of health data. The authority found omissions in implementing technical and organizational measures for access to the health dossier.ITGaranteGDPR€40,000