Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Nov 2025About YouThe Hungarian Competition Authority (GVH) found that About You used misleading discount pricing and pressured consumers with countdown timers and scarcity messages. The company was ordered to pay HUF 505 million to the Hungarian central budget and to provide compensation to affected Hungarian customers.HUGazdasági VersenyhivatalOmnibus€1,323,000
21 May 2025Autostrade per l'Italia SpaThe Italian data protection authority fined Autostrade per l'Italia Spa EUR 420,000 for unlawfully processing an employee's personal data. The company used content from her Facebook profile and private Messenger and WhatsApp chats to support disciplinary proceedings and justify her dismissal.ITGarante per la protezione dei dati personaliGDPR€420,000
27 Feb 2020Tim S.p.A.The Italian data protection authority imposed a EUR 27.8 million fine on Tim S.p.A. The case concerned privacy violations in marketing and telemarketing activities, including issues with obtaining valid consent.ITGarante per la protezione dei dati personaliGDPR€27,800,000
04 Aug 2025Azienda Ospedaliero-UniversitariaThe Italian data protection authority fined Azienda Ospedaliero-Universitaria EUR 80,000 for improperly configuring its health dossier. It found that staff could access patients’ clinical histories without proper profiling, alerts, or access logging, and that patients were not adequately informed or able to consent or object.ITGarante per la protezione dei dati personaliGDPR€80,000
Enel Energia SpAEnel Energia SpA was fined EUR 79.1 million by the Italian data protection authority, Garante. The case concerned misuse of personal data and was a major GDPR enforcement action.ITGarante per la protezione dei dati personaliGDPR€79,100,000
20 Dec 2024OpenAIThe Italian data protection authority fined OpenAI EUR 15 million for GDPR noncompliance related to ChatGPT. The 20 December 2024 decision cites issues with the legal basis for training data processing, transparency obligations, age verification, breach notification, and the security and accuracy of outputs.ITGarante per la protezione dei dati personaliGDPR€15,000,000
04 Jun 2025Noi Compriamo Auto.it S.r.l.On 4 June 2025, the Italian Data Protection Authority fined Noi Compriamo Auto.it S.r.l. for GDPR breaches in email marketing. The authority found that the company sent promotional emails without consent, failed to properly govern its processors, and did not adequately support data subject rights.ITGarante per la protezione dei dati personaliGDPR€27,800,000
03 Jun 2025Regione LombardiaThe Italian Data Protection Authority, Garante per la protezione dei dati personali, imposed a EUR 50,000 fine on Regione Lombardia. The case concerned unlawful retention of employees' email metadata, excessive retention of web browsing logs, and prolonged storage of helpdesk ticket data.ITGarante per la protezione dei dati personaliGDPR€50,000
30 Apr 2026Intesa SanpaoloItaly’s data protection authority, Garante, fined Intesa Sanpaolo EUR 31.8 million. The sanction concerned serious failures in security and access management for personal data.ITGarante per la protezione dei dati personaliGDPR€31,800,000
01 Jan 2025RaiItaly’s data protection authority fined Rai EUR 150,000 over a Report broadcast on 8 December 2024 that disclosed a private conversation. The case concerns unlawful processing of personal data in a television report.ITGarante per la protezione dei dati personaliGDPR€150,000
10 Apr 2025Luka Inc.The Italian data protection authority fined Luka Inc., the US company behind the Replika chatbot, EUR 5,000,000. The 2025-04-10 decision concerned inadequate age verification, an unlawful processing basis, and missing privacy notice information required under the GDPR.ITGarante per la protezione dei dati personaliGDPR€5,000,000
10 Oct 2023ComuneThe Italian data protection authority fined a municipality EUR 12,000 for unlawfully publishing personal data online in access request registers. Documents in the transparency section of the municipal website exposed names, protocol numbers, and other sensitive details of hundreds of citizens.ITGarante per la protezione dei dati personaliGDPR€12,000
28 Mar 2023Sky Italia S.r.l.The Italian Data Protection Authority fined Sky Italia S.r.l. EUR 842,062 for violations related to telemarketing and commercial communications. The company failed to properly verify consent, relied on outdated consents, and did not check the Public Register of Oppositions before campaigns.ITGarante per la protezione dei dati personaliGDPR€842,000
29 Apr 2025Ordine professionale degli psicologi della LombardiaOn 2025-04-29, the Italian Data Protection Authority fined the Ordine professionale degli psicologi della Lombardia EUR 30,000. The sanction concerned breaches of Articles 5(1)(f) and 32 GDPR following a data breach and the failure to implement adequate security measures.ITGarante per la protezione dei dati personaliGDPR€30,000
02 Nov 2024Intesa SanpaoloThe Italian Data Protection Authority fined Intesa Sanpaolo €31.8 million for a data breach involving unauthorized access to banking information of more than 3,500 clients. The authority also found that the bank detected the activity late and filed an incomplete and delayed breach notification.ITGarante per la protezione dei dati personaliGDPR€31,800
21 May 2026The European House – Ambrosetti spaThe Italian data protection authority fined The European House – Ambrosetti spa EUR 85,000 for security shortcomings following a data breach affecting 61,670 people. The company notified affected individuals too late, only after intervention by the authority.ITGarante per la protezione dei dati personaliGDPR€85,000
14 Nov 2024Comune di MaddaloniThe Garante fined Comune di Maddaloni EUR 2,000 for failing to communicate the Data Protection Officer’s contact details to the Authority. This constituted a breach of Article 37(7) GDPR.ITGaranteGDPR€2,000
13 May 2015Iperal S.p.A.Iperal S.p.A. was fined EUR 40,000 by the Garante for activating 11 phone cards in the names of 5 individuals without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€40,000
27 Oct 2016Studio Medico Odontoiatrico Associato Gimmelli B. & G.Studio Medico Odontoiatrico Associato Gimmelli B. & G. was fined by the Garante for unlawfully processing personal data by disclosing it to Ina Assitalia s.p.a. without obtaining the required informed consent from the data subject. The case reflects a breach of core lawful-processing requirements.ITGaranteGDPR€6,400
25 Mar 2021Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules.ITGaranteGDPR€50,000