Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Sept 2021Azienda sanitaria provinciale di CosenzaAzienda sanitaria provinciale di Cosenza was fined by the Garante for unlawfully publishing health data on its institutional website. The case involved breaches of data protection principles and required security measures for sensitive data.ITGaranteGDPR€18,000
06 Sept 2012Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined 34,000 EUR by the Garante. The authority found a breach of notification obligations under data protection rules.ITGaranteGDPR€34,000
14 Jan 2021Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined by the Garante €30,000 for unlawfully processing employees’ biometric data to monitor attendance. The conduct breached GDPR requirements on lawful processing and data minimisation.ITGaranteGDPR€30,000
13 Nov 2024Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 8,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data. The decision indicates non-compliance with core rules on lawful and proper processing.ITGaranteGDPR€8,000
27 Nov 2024Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 20,000 EUR for publishing employees’ personal data without a legal basis. The disclosure included details on additional payments, sickness absences, and union rights, breaching the GDPR and the national privacy code.ITGaranteGDPR€20,000
11 Oct 2012Azienda sanitaria provinciale di Vibo ValentiaAzienda sanitaria provinciale di Vibo Valentia was fined by the Garante EUR 15,000 for failing to adopt the required minimum security measures. The authority found that the Security Programmatic Document (DPS) was not updated by the deadline required under the Italian Privacy Code.ITGaranteGDPR€15,000
13 Dec 2012Azienda sanitaria regionale MoliseThe Regional Health Company of Molise was fined for failing to designate data processing officers for each employee. The authority also found that minimum security measures for electronic processing were not implemented, including weak password policies and insufficient protection against unauthorized external access.ITGaranteGDPR€15,000
26 Sept 2024Azienda Sanitaria Territoriale di Ascoli PicenoThe Garante fined Azienda Sanitaria Territoriale di Ascoli Piceno EUR 17,000 for failing to implement procedures that would prevent unauthorized linkage between individuals and health departments. The issue could reveal information about a person's health status.ITGaranteGDPR€17,000
27 Mar 2025Azienda sanitaria territoriale di MacerataAzienda sanitaria territoriale di Macerata was fined 5,000 EUR by the Garante for failing to comply with data access requests and for breaches of data protection rules. The case concerned the processing of health data and inadequate security measures.ITGaranteGDPR€5,000
23 Mar 2017Azienda Sanitaria ULSS 6 di VicenzaAzienda Sanitaria ULSS 6 di Vicenza was fined by the Garante 10,000 EUR for unlawfully communicating an individual's health data to the Comune di Arcugnano without proper authorization. The case involved a breach of lawful processing rules and safeguards for special-category data.ITGaranteGDPR€10,000
13 Jan 2022Azienda sanitaria unica regionale MarcheAzienda sanitaria unica regionale Marche was fined EUR 14,000 by the Garante for inadequate data protection measures. The breach involved health data and was linked to QR code generation; improved security measures were later implemented.ITGaranteGDPR€14,000
26 May 2022Azienda sanitaria universitaria Friuli OccidentaleAzienda sanitaria universitaria Friuli Occidentale was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the electronic health dossier. The authority found non-compliance with GDPR requirements.ITGaranteGDPR€5,000
24 Jun 2020Azienda Sanitaria Universitaria Giuliano IsontinaAzienda Sanitaria Universitaria Giuliano Isontina was fined by the Garante for unlawfully communicating health data without an adequate legal basis. The conduct breached Article 20 of the Italian Privacy Code.ITGaranteGDPR€10,000
21 Jun 2018Azienda Semplice s.r.l.Azienda Semplice s.r.l. was fined by the Garante 16,000 EUR for unlawful processing of personal data used to place promotional calls to a private residential phone number without consent. The case concerns a lack of a lawful basis for marketing contact and a breach of data protection rules.ITGaranteGDPR€16,000
21 Dec 2023Azienda socio-sanitaria localeThe Garante imposed a fine on a local health authority for violations related to the handling of sensitive personal data. The case concerned improper processing of special-category data, which breached data protection rules.ITGaranteGDPR€18,000
18 Jul 2023Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest MilaneseThe Garante fined Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest Milanese 12,000 EUR for a data breach. Personal data was accessed without negative consequences for the data subjects. The organization took measures to prevent similar violations in the future.ITGaranteGDPR€12,000
12 May 2022Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante €7,000 for violations related to the processing of health data. The authority also found insufficient data security measures.ITGaranteGDPR€7,000
29 Apr 2021Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante in the amount of 4,000 EUR for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization because personal data remained accessible online for an extended period.ITGaranteGDPR€4,000
29 Apr 2021Azienda socio sanitaria territoriale Melegnano e della MartesanaAzienda socio sanitaria territoriale Melegnano e della Martesana was fined by the Garante €6,000 for a data breach involving the loss of health data. The case concerned special-category personal data and indicates insufficient organizational or technical safeguards.ITGaranteGDPR€6,000
27 Jan 2022Azienda socio sanitaria territoriale Nord di MilanoAzienda socio sanitaria territoriale Nord di Milano was fined by the Garante 20,000 EUR for failing to implement adequate security measures to protect personal data. The authority found a breach of GDPR provisions on data protection and security.ITGaranteGDPR€20,000