Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
18 Jan 2018Telecom Italia S.p.A.Telecom Italia S.p.A. was fined EUR 840,000 by the Garante for making promotional phone calls to individuals who had not consented to the processing of their data for marketing purposes. The case indicates a breach of lawful processing rules and consent requirements.ITGaranteGDPR€840,000
03 Apr 2014Gianfranco SiriGianfranco Siri was fined by the Garante for operating a video surveillance system without providing the required minimum information notice. The case concerned a breach of privacy rules and the duty to inform individuals subject to surveillance.ITGaranteGDPR€2,400
24 Apr 2013ModenaFiere S.r.l.ModenaFiere S.r.l. was fined EUR 16,000 by the Garante for processing personal data without adequate notice and consent. The violations covered promotional communications, statistical activities, and the dissemination of data on its website and in publications.ITGaranteGDPR€16,000
11 Jan 2024Provincia di SassariThe Garante imposed a fine of 2,000 EUR on Provincia di Sassari for breaches of data protection obligations under Article 37 GDPR. The case concerned failure to comply with requirements related to the designation of a data protection officer.ITGaranteGDPR€2,000
12 Oct 2023Onda Più S.r.l.Onda Più S.r.l. was fined EUR 200,000 by the Garante for activating energy supply contracts without customer consent. The authority also found the use of inaccurate and outdated personal data.ITGaranteGDPR€200,000
27 May 2021Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante 10,000 EUR for unlawfully communicating a customer's financial data related to a Postepay card to an unauthorized third party. The case concerns a breach of personal data protection and financial confidentiality requirements.ITGaranteGDPR€10,000
22 Feb 2024Ossitocina24 di Patrono AntonellaOssitocina24 di Patrono Antonella was fined 5,000 EUR by the Italian Garante. The case concerned the failure to delete personal data from its website after a contract termination request, which breached GDPR data processing requirements.ITGaranteGDPR€5,000
06 Jul 2006PR3 International s.r.l.PR3 International s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 258. The case concerned inadequate information provided to data subjects in job advertisements, which breached data protection rules.ITGaranteGDPR€258
12 Mar 2026Comune di SutriComune di Sutri was fined EUR 2,000 by the Garante for publishing personal data on its institutional website. The case concerns a breach of data protection rules in the public online disclosure of information.ITGaranteGDPR€2,000
16 Jan 2026BAR GIOIA di XXThe Garante imposed a fine of EUR 600 on BAR GIOIA for the non-compliant installation of a video surveillance system. The case concerned breaches of data protection rules and the requirements for lawful processing.ITGaranteGDPR€600
03 Aug 2023Sdam s.r.l.Sdam s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 5,000 EUR. The case concerned the sending of promotional emails without proper consent, which constitutes a GDPR violation.ITGaranteGDPR€5,000
02 Oct 2014Comune di Piana degli AlbanesiThe Municipality of Piana degli Albanesi was fined EUR 8,000 by the Garante for failing to appoint data processing officers. The authority also found that the required security program document had not been drafted, in breach of data protection rules.ITGaranteGDPR€8,000
29 Sept 2021dott.ssa Manuela MazzoliThe Garante imposed a fine of 2,000 EUR on dott.ssa Manuela Mazzoli for breaches of data protection rules. The case concerned the processing of personal data in the healthcare sector, including the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€2,000
21 Apr 2016Comune di PozzuoliComune di Pozzuoli was fined EUR 10,000 by the Garante for publishing a minor’s personal data, including health information, on its institutional website. The conduct breached privacy and data protection rules.ITGaranteGDPR€10,000
18 Jun 2015Azienda USL5 di PisaAzienda USL5 di Pisa was fined EUR 6,000 for unlawful processing of personal data through a video surveillance system. The authority found that the required information notice was not provided to individuals, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
08 Oct 2015Birrificio Torino srlBirrificio Torino srl was fined EUR 2,400 by the Garante for providing inadequate information in the data collection form on its website. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
11 Dec 2014Silvestri RobertoSilvestri Roberto was fined 2,400 EUR by the Garante. The case concerned inadequate information provided to data subjects through web forms on his website, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
17 Apr 2026Poste Italiane S.p.a. e PostePay S.p.a.Poste Italiane S.p.a. and PostePay S.p.a. were sanctioned for unlawful processing of personal data in their Bancoposta and PostePay apps on Android devices. The apps required users to authorize access to data to detect malicious software, which breached GDPR principles.ITGaranteGDPR€6,624,000
05 Apr 2012XY s.r.l.XY s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial communications by email despite the recipient's repeated objections. The case indicates a breach of data protection rules governing electronic marketing and respect for opt-out requests.ITGaranteGDPR€10,400
16 Sept 2021Farpa s.r.l.Farpa s.r.l. was fined by the Garante 1,000 EUR for failing to provide proper information to data subjects, including workers, about the processing of personal data through a video surveillance system. The authority found that the information duty toward affected individuals was not met adequately.ITGaranteGDPR€1,000