Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Sept 2007Asl Enna 4The Garante fined Asl Enna 4 EUR 10,000 for processing personal data, including genetic and biometric data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
14 Sept 2006Asl FerraraAsl Ferrara was fined by the Garante for processing genetic, health, and sexual life data without the required notification. The authority found a breach of the Italian Privacy Code.ITGaranteGDPR€10,000
16 Dec 2021ASL LatinaASL Latina was fined for violations of data protection rules. The authority found inadequate measures to prevent data breaches involving health data.ITGaranteGDPR€10,000
24 Oct 2013ASL n.1 – Avezzano/Sulmona/L'AquilaASL n.1 – Avezzano/Sulmona/L'Aquila was fined EUR 8,000 by the Garante. The authority found a breach consisting of failure to make the notification required under the Italian Data Protection Code.ITGaranteGDPR€8,000
14 Nov 2019ASL n. 2 SavoneseASL n. 2 Savonese was fined EUR 8,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data, including failures to comply with lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€8,000
13 Feb 2007Asl n. 5 CrotoneAsl n. 5 Crotone was fined by the Garante for failing to notify the processing of sensitive personal data, including genetic and health data. The notification requirement was set out in the Italian Data Protection Code.ITGaranteGDPR€10,000
14 Sept 2006Asl n. 8 di Asolo (TV)Asl n. 8 di Asolo was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The notification was required under the Italian Privacy Code.ITGaranteGDPR€10,000
13 Jan 2022A.S.L. Napoli 1 CentroA.S.L. Napoli 1 Centro was fined EUR 6,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data in violation of lawfulness, fairness, transparency, and data minimization requirements.ITGaranteGDPR€6,000
20 Nov 2014Asl Napoli 2 nordThe Garante imposed a 16,000 EUR fine on Asl Napoli 2 nord for failing to designate data protection officers and for keeping surveillance footage longer than permitted without prior authorization. The case concerned organizational compliance failures and unlawful data retention.ITGaranteGDPR€16,000
13 May 2015ASL Napoli 2 NordASL Napoli 2 Nord was fined 20,000 EUR by the Garante for publishing personal data on its website. The disclosed information could reveal individuals' health status, which breached privacy rules.ITGaranteGDPR€20,000
28 Sept 2023Asl Napoli 3 SudThe Garante fined Asl Napoli 3 Sud EUR 30,000 for inadequate security measures that led to a data breach. The incident caused limited service disruption.ITGaranteGDPR€30,000
08 Feb 2007Asl OristanoAsl Oristano was fined EUR 10,000 by the Garante for failing to notify the processing of personal data concerning health and sexual life. The breach concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
04 Feb 2016A.S.L. Roma 2A.S.L. Roma 2 was fined EUR 4,000 by the Garante for failing to respond to requests for information concerning the processing of personal data relating to a minor's civil disability. The authority found this to be a breach of Article 164 of the Italian Privacy Code.ITGaranteGDPR€4,000
13 Sept 2007Asl Salerno 2Asl Salerno 2 was fined EUR 10,000 by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code.ITGaranteGDPR€10,000
13 Sept 2007Asl San Severo (Foggia 1)Asl San Severo (Foggia 1) was fined by the Garante for processing personal data, including genetic and biometric data, without proper compliance with data protection rules. The case indicates insufficient legal basis and safeguards for the handling of sensitive data.ITGaranteGDPR€10,000
14 Sept 2006Asl VercelliAsl Vercelli was fined by the Garante for processing special-category personal data, including genetic and health data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
08 Feb 2007Asl Vibo ValentiaThe health authority Asl Vibo Valentia was fined by Garante for improperly handling sensitive personal data, including genetic and biometric data, without proper authorization. The case concerns a breach of data protection rules and the legal basis required for processing such data.ITGaranteGDPR€10,000
01 Jan 2024a small recruitment bureauA small recruitment bureau in the Netherlands was fined EUR 6,000 by the Autoriteit Persoonsgegevens for failing to respond on time to an ex-candidate’s request to delete personal data. The Raad van State upheld the fine in case ECLI:NL:RVS:2024:2221.NLAutoriteit PersoonsgegevensGDPR€6,000
01 Jan 2021ASM PRATASM PRAT was fined EUR 5,000 by the AEPD for requiring recipients to submit photos of their ID cards without consent. The company also failed to provide information about the data processing, which breached data protection rules.ESAEPDGDPR€5,000
15 Jul 2024ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD 200,000 EUR for failing to properly handle a data subject’s request for deletion and for processing personal data without a legal basis. The case concerns breaches of core data protection obligations.ESAEPDGDPR€200,000