Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Dec 2023Azienda socio sanitaria territoriale nord MilanoAzienda socio sanitaria territoriale nord Milano was fined by the Garante EUR 40,000 for allowing unrestricted access to patient data across hospital departments. The authority found breaches of data minimization and purpose limitation principles during the COVID-19 emergency.ITGaranteGDPR€40,000
23 May 2024Azienda Socio-sanitaria Territoriale RhodenseAzienda Socio-sanitaria Territoriale Rhodense was fined EUR 4,500 by the Garante for breaching GDPR Article 16. The case concerned data processing in the health sector, where strict compliance controls are required.ITGaranteGDPR€4,500
21 Jul 2022Azienda Socio Sanitaria Territoriale RhodenseAzienda Socio Sanitaria Territoriale Rhodense was fined by the Garante EUR 3,000 for violations of data protection rules. The case concerned data breaches and inadequate security measures.ITGaranteGDPR€3,000
28 May 2020Azienda Teatro del GiglioAzienda Teatro del Giglio was fined 6,000 EUR by the Garante for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€6,000
17 Nov 2010Azienda trasporti di MessinaAzienda trasporti di Messina was fined 20,000 EUR by the Garante for processing sensitive personal data without providing the required information notice and without obtaining consent from the data subjects. The case concerns breaches of core transparency and lawful-processing obligations.ITGaranteGDPR€20,000
21 Apr 2011Azienda Trasporti per l'Area Metropolitana S.p.A.Azienda Trasporti per l'Area Metropolitana S.p.A. was fined by the Garante €10,000 for failing to provide adequate data protection information on its website. The conduct breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€10,000
28 May 2026Azienda Tutela della Salute per la LiguriaAzienda Tutela della Salute per la Liguria was fined by the Garante 6,000 EUR for violations related to the processing of personal data using a satellite localization system in a disciplinary procedure against an employee. The case concerned the use of data in a manner that did not comply with data protection requirements.ITGaranteGDPR€6,000
17 May 2023Azienda ULSS 6 EuganeaThe Garante fined Azienda ULSS 6 Euganea 10,000 EUR for the incorrect handling of health-related documents. The authority found breaches of GDPR Articles 5, 6, and 32.ITGaranteGDPR€10,000
13 Feb 2025Azienda ULSS n. 02573090236The public health company was fined for making a disciplinary proceeding document visible to unauthorized employees. The authority found breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€4,000
17 Jul 2024Azienda ULSS n. 14The Garante fined Azienda ULSS n. 14 EUR 22,000 for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies resulted in a data breach involving sensitive health data.ITGaranteGDPR€22,000
30 Jan 2025Azienda Unità Sanitaria locale di ModenaAzienda Unità Sanitaria locale di Modena was fined by the Garante €10,000 for processing personal data concerning health and other sensitive information without a proper legal basis. The case involved unlawful processing of special-category data, which raises heightened compliance and privacy risks.ITGaranteGDPR€10,000
11 Feb 2021Azienda Unità Sanitaria Locale di ParmaAzienda Unità Sanitaria Locale di Parma was fined by the Garante €10,000 for improper handling of sensitive personal data. The violation was linked to an occasional malfunction of its IT system, which led to improper data processing.ITGaranteGDPR€10,000
06 Jun 2018Azienda Unità Sanitaria Locale di PiacenzaAzienda Unità Sanitaria Locale di Piacenza was fined by the Garante EUR 36,000 for creating electronic health records without informing patients or obtaining their consent. The authority found this to be a breach of privacy rules.ITGaranteGDPR€36,000
06 Feb 2020Azienda Unità Sanitaria Locale Toscana CentroAzienda Unità Sanitaria Locale Toscana Centro was fined by the Garante 10,000 EUR for violations related to data processing in the health sector. The case concerned the handling of patient data without full compliance with GDPR requirements.ITGaranteGDPR€10,000
17 Dec 2020Azienda Unità Sanitaria Locale Toscana Sud EstAzienda Unità Sanitaria Locale Toscana Sud Est was fined for processing personal data without proper safeguards. The authority also found that patient data was shared without anonymization, in breach of GDPR requirements.ITGaranteGDPR€100,000
15 Dec 2022Azienda Universitaria Friuli CentraleAzienda Universitaria Friuli Centrale was fined EUR 55,000 by the Garante for processing personal data without a legal basis. The authority also found failures to provide instructions for data deletion and to stop unauthorized processing by Insiel spa.ITGaranteGDPR€55,000
15 Dec 2022Azienda Universitaria Friuli OccidentaleAzienda Universitaria Friuli Occidentale was fined EUR 55,000 by the Garante for processing personal data without a legal basis. The authority also found that the organization failed to provide required information about data deletion, in breach of the GDPR and national privacy rules.ITGaranteGDPR€55,000
18 Jun 2015Azienda USL5 di PisaAzienda USL5 di Pisa was fined EUR 6,000 for unlawful processing of personal data through a video surveillance system. The authority found that the required information notice was not provided to individuals, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
27 May 2021Azienda Usl della RomagnaAzienda Usl della Romagna was fined by the Garante in the amount of EUR 120,000 for violations related to the processing of a patient's health data in the gynecology department. The case also involved issues with electronic health records and data breaches.ITGaranteGDPR€120,000
27 Jan 2021Azienda USL della RomagnaAzienda USL della Romagna was fined by the Garante 50,000 EUR for failing to implement procedures to prevent unauthorized disclosure of patients' health information. The authority found a breach of GDPR Article 9 on special categories of personal data.ITGaranteGDPR€50,000