Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Dec 2014Silvestri RobertoSilvestri Roberto was fined 2,400 EUR by the Garante. The case concerned inadequate information provided to data subjects through web forms on his website, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
17 Apr 2026Poste Italiane S.p.a. e PostePay S.p.a.Poste Italiane S.p.a. and PostePay S.p.a. were sanctioned for unlawful processing of personal data in their Bancoposta and PostePay apps on Android devices. The apps required users to authorize access to data to detect malicious software, which breached GDPR principles.ITGaranteGDPR€6,624,000
05 Apr 2012XY s.r.l.XY s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial communications by email despite the recipient's repeated objections. The case indicates a breach of data protection rules governing electronic marketing and respect for opt-out requests.ITGaranteGDPR€10,400
16 Sept 2021Farpa s.r.l.Farpa s.r.l. was fined by the Garante 1,000 EUR for failing to provide proper information to data subjects, including workers, about the processing of personal data through a video surveillance system. The authority found that the information duty toward affected individuals was not met adequately.ITGaranteGDPR€1,000
24 Nov 2016Minerv@ s.r.l.Minerv@ s.r.l. was fined by the Garante 10,000 EUR for sending promotional emails to a complainant after they objected and requested deletion of their data. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€10,000
29 Apr 2025Comune di San Francesco al CampoThe Garante imposed a fine of 1,200 EUR on Comune di San Francesco al Campo for violations related to the publication of personal data on its institutional website. The data were subsequently removed.ITGaranteGDPR€1,200
26 Jul 2012Comune di MilanoThe Garante fined Comune di Milano EUR 20,000 for failing to implement minimum security measures on two computer stations at a primary school. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€20,000
13 Feb 2025Comune di TuscaniaThe Garante imposed a 4,000 EUR fine on Comune di Tuscania for violating data protection rules. The authority took into account the limited financial resources of the small municipality when setting the sanction.ITGaranteGDPR€4,000
04 Jun 2025Comune di PompeiThe Garante fined Comune di Pompei EUR 5,000 for failing to provide the Authority with the contact details of its Data Protection Officer. The breach concerned the notification duty under Article 37 GDPR.ITGaranteGDPR€5,000
07 Feb 2013Società delle terme s.p.a.Società delle terme s.p.a. was fined by the Garante 18,400 EUR for providing inadequate information when collecting personal data and for obtaining invalid consent. The authority found violations of Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€18,400
27 Mar 2014Comune di ConversanoComune di Conversano was fined 4,000 EUR by the Garante for failing to update the annual Security Policy Document. The breach concerned compliance with data protection obligations.ITGaranteGDPR€4,000
13 Sept 2007Asl Salerno 2Asl Salerno 2 was fined EUR 10,000 by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code.ITGaranteGDPR€10,000
05 Apr 2018Azienda Ospedaliera Sant’Andrea di RomaAzienda Ospedaliera Sant’Andrea di Roma was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate individuals responsible for data processing, in breach of data protection rules.ITGaranteGDPR€10,000
17 May 2023Ministero delle infrastrutture e dei trasportiThe Ministry of Infrastructure and Transport was fined by the Garante for improper online disclosure of personal data. The authority found a breach of GDPR transparency obligations.ITGaranteGDPR€24,000
20 Oct 2011Betfair Italia srlBetfair Italia srl was fined EUR 40,000 by the Garante for violations related to the omission of information on how data subjects can exercise their rights, as well as other data protection obligations. The case concerned incomplete compliance with information requirements toward users.ITGaranteGDPR€40,000
29 Jan 2015Comunicando di Rizzotto Fabio & C. s.a.s.Comunicando di Rizzotto Fabio & C. s.a.s. was fined €80,000 by the Garante for activating 88 phone cards in the names of 16 individuals without their knowledge. The authority found this to be a breach of data protection rules.ITGaranteGDPR€80,000
12 Mar 2015Hayat KhizerHayat Khizer was fined EUR 3,000 by the Garante for improper registration of SIM cards. The cards were used by persons other than the formal registrants in connection with a criminal investigation into drug trafficking.ITGaranteGDPR€3,000
07 Nov 2018Comune di BuccinoComune di Buccino was fined for unlawfully publishing personal data online without a legal basis. This violated Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
16 Dec 2021FCA Italy s.p.a.FCA Italy s.p.a. was fined 20,000 EUR by the Garante for breaching GDPR provisions on the right of access and transparency obligations. The case arose from a complaint by an English citizen about the handling of their personal data.ITGaranteGDPR€20,000
06 Oct 2016Comune di FurnariThe Municipality of Furnari was fined 4,000 EUR by the Garante. The authority found that personal data remained published on the institutional website beyond the legally permitted period.ITGaranteGDPR€4,000