Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Oct 2022Poste Italiane S.p.a.Poste Italiane S.p.a. was fined 10,000 EUR by the Garante. The authority found a breach of Article 15 GDPR due to failure to respond to a data access request.ITGaranteGDPR€10,000
12 Mar 2026Enel Energia S.p.A.Enel Energia S.p.A. was fined by the Italian data protection authority, Garante, for making unwanted telemarketing calls without a proper legal basis. The authority found that the company’s conduct breached data protection principles.ITGaranteGDPR€563,000
21 Mar 2024Azienda sanitaria locale Roma 3The Garante fined Azienda sanitaria locale Roma 3 10,000 EUR for failing to adequately protect personal data. The breach led to attempted unauthorized access to user accounts and indicated insufficient cybersecurity controls.ITGaranteGDPR€10,000
14 Jan 2021Agenzia regionale protezione ambientale Campania (ARPAC)ARPAC was fined by the Garante EUR 8,000 for violations concerning data security measures and data breach notification obligations. The case involved non-compliance with GDPR Articles 5 and 32.ITGaranteGDPR€8,000
14 Sept 2006Banca Sella S.p.a.Banca Sella S.p.a. was fined EUR 20,000 by the Garante for processing biometric data without the notification required under the privacy code. The authority found this to be a breach of Italian privacy rules.ITGaranteGDPR€20,000
17 Apr 2026Comune di Campo CalabroThe Garante fined Comune di Campo Calabro EUR 6,000 for publishing personal data online. The case concerned a breach of data protection rules and the unlawful disclosure of information.ITGaranteGDPR€6,000
24 Apr 2013Free Time s.r.l.Free Time s.r.l. was fined EUR 54,000 by the Italian Garante. The case concerned the registration of numerous phone cards to unaware third parties without providing the required information on data processing.ITGaranteGDPR€54,000
09 May 2018Mercuri SalvatoreMercuri Salvatore was fined by the Garante EUR 60,000 for making unsolicited promotional calls to individuals whose phone numbers were listed in the opposition register. This conduct infringed their right to object to such communications.ITGaranteGDPR€60,000
14 Feb 2013Impresa individuale Mail TrainingThe company was fined for making an unsolicited promotional phone call without providing the required information or obtaining consent. The authority treated this as a breach of data protection rules.ITGaranteGDPR€6,400
24 Oct 2013Comune di Torre CajetaniComune di Torre Cajetani was fined by the Garante for unlawfully publishing an individual's health data on a public notice board. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€10,000
11 Sept 2025ISV Group SrlsISV Group Srls was fined €15,000 by the Garante for sending unsolicited promotional emails without consent. The authority also found that the company failed to properly control its partner Ismax, which carried out unlawful data processing activities.ITGaranteGDPR€15,000
26 Oct 2023Edizioni Proposta Sud S.r.l.The Garante fined Edizioni Proposta Sud S.r.l. €20,000 for publishing false information about an individual's health status without verifying its accuracy. The authority found this breached GDPR principles on data protection and accuracy.ITGaranteGDPR€20,000
26 Feb 2026Groupharma s.r.l.s.Groupharma s.r.l.s. was fined EUR 3,000 by the Italian supervisory authority, Garante. The case concerned the company’s failure to respond to a former employee’s request to access and delete personal data, including photos and contact details, from its website after employment ended.ITGaranteGDPR€3,000
28 Jul 2022Ordinanza ingiunzione - 28 luglio 2022 [9813385]The Garante imposed a fine of EUR 1,000 on the website administrator for failing to remove or de-index a page containing a Corriere della Sera article about a judicial case involving the complainant's father. The authority found a violation of the right to be forgotten.ITGaranteGDPR€1,000
29 Jan 2015Abruzzo Vigilanza s.r.l.Abruzzo Vigilanza s.r.l. was fined €8,000 by the Garante for using a vehicle tracking system without the required notification. The case concerns non-compliance with data protection notification obligations.ITGaranteGDPR€8,000
14 Sept 2006Asl n. 8 di Asolo (TV)Asl n. 8 di Asolo was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The notification was required under the Italian Privacy Code.ITGaranteGDPR€10,000
09 Oct 2025Arienti & C. s.r.l. a socio unicoThe Garante fined Arienti & C. s.r.l. a socio unico EUR 8,000 for denying a former employee access to their email account after the employment contract ended. The authority found this breached GDPR Article 15 on the right of access to personal data.ITGaranteGDPR€8,000
07 Jul 2022Senseonics Inc.Senseonics Inc. was fined EUR 45,000 by the Garante for violations related to the processing of personal data. The authority cited issues with data integrity and confidentiality, including health data.ITGaranteGDPR€45,000
28 Oct 2021Anfiteatro Flavio s.r.l.Anfiteatro Flavio s.r.l. was fined EUR 2,000 by the Garante for operating a video surveillance system without the required privacy notice. The authority found a breach of Article 13 of the GDPR.ITGaranteGDPR€2,000
23 Apr 2015Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e LagunaThe Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e Laguna was fined 4,000 EUR by the Garante. The authority found that personal data had been unlawfully communicated to private entities without an appropriate legal basis, in breach of Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000