Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Nov 2016Minerv@ s.r.l.Minerv@ s.r.l. was fined by the Garante 10,000 EUR for sending promotional emails to a complainant after they objected and requested deletion of their data. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€10,000
29 Apr 2025Comune di San Francesco al CampoThe Garante imposed a fine of 1,200 EUR on Comune di San Francesco al Campo for violations related to the publication of personal data on its institutional website. The data were subsequently removed.ITGaranteGDPR€1,200
26 Jul 2012Comune di MilanoThe Garante fined Comune di Milano EUR 20,000 for failing to implement minimum security measures on two computer stations at a primary school. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€20,000
13 Feb 2025Comune di TuscaniaThe Garante imposed a 4,000 EUR fine on Comune di Tuscania for violating data protection rules. The authority took into account the limited financial resources of the small municipality when setting the sanction.ITGaranteGDPR€4,000
04 Jun 2025Comune di PompeiThe Garante fined Comune di Pompei EUR 5,000 for failing to provide the Authority with the contact details of its Data Protection Officer. The breach concerned the notification duty under Article 37 GDPR.ITGaranteGDPR€5,000
07 Feb 2013Società delle terme s.p.a.Società delle terme s.p.a. was fined by the Garante 18,400 EUR for providing inadequate information when collecting personal data and for obtaining invalid consent. The authority found violations of Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€18,400
27 Mar 2014Comune di ConversanoComune di Conversano was fined 4,000 EUR by the Garante for failing to update the annual Security Policy Document. The breach concerned compliance with data protection obligations.ITGaranteGDPR€4,000
13 Sept 2007Asl Salerno 2Asl Salerno 2 was fined EUR 10,000 by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code.ITGaranteGDPR€10,000
05 Apr 2018Azienda Ospedaliera Sant’Andrea di RomaAzienda Ospedaliera Sant’Andrea di Roma was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate individuals responsible for data processing, in breach of data protection rules.ITGaranteGDPR€10,000
17 May 2023Ministero delle infrastrutture e dei trasportiThe Ministry of Infrastructure and Transport was fined by the Garante for improper online disclosure of personal data. The authority found a breach of GDPR transparency obligations.ITGaranteGDPR€24,000
20 Oct 2011Betfair Italia srlBetfair Italia srl was fined EUR 40,000 by the Garante for violations related to the omission of information on how data subjects can exercise their rights, as well as other data protection obligations. The case concerned incomplete compliance with information requirements toward users.ITGaranteGDPR€40,000
29 Jan 2015Comunicando di Rizzotto Fabio & C. s.a.s.Comunicando di Rizzotto Fabio & C. s.a.s. was fined €80,000 by the Garante for activating 88 phone cards in the names of 16 individuals without their knowledge. The authority found this to be a breach of data protection rules.ITGaranteGDPR€80,000
12 Mar 2015Hayat KhizerHayat Khizer was fined EUR 3,000 by the Garante for improper registration of SIM cards. The cards were used by persons other than the formal registrants in connection with a criminal investigation into drug trafficking.ITGaranteGDPR€3,000
07 Nov 2018Comune di BuccinoComune di Buccino was fined for unlawfully publishing personal data online without a legal basis. This violated Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
16 Dec 2021FCA Italy s.p.a.FCA Italy s.p.a. was fined 20,000 EUR by the Garante for breaching GDPR provisions on the right of access and transparency obligations. The case arose from a complaint by an English citizen about the handling of their personal data.ITGaranteGDPR€20,000
06 Oct 2016Comune di FurnariThe Municipality of Furnari was fined 4,000 EUR by the Garante. The authority found that personal data remained published on the institutional website beyond the legally permitted period.ITGaranteGDPR€4,000
18 Nov 2015G.M.C. - Giuseppe Marra Communications s.a.p.a.G.M.C. - Giuseppe Marra Communications s.a.p.a. was fined by the Garante in the amount of €4,000 for unlawfully obtaining consent for data processing through a newsletter subscription. The form included marketing purposes beyond the stated intent, which breached Article 23 of the Italian Data Protection Code.ITGaranteGDPR€4,000
15 Feb 2018Innovastem s.r.l.Innovastem s.r.l. was fined by the Garante for processing personal data without providing the required information notice and for handling health-related data without proper consent. The case indicates breaches of transparency obligations and the rules governing the lawful processing of sensitive data.ITGaranteGDPR€22,400
20 Oct 2022I.S.P.R.O.The Italian Data Protection Authority fined I.S.P.R.O. EUR 7,000 for violations related to the processing of health data. The case concerned improper handling of sensitive data, creating a material compliance risk.ITGaranteGDPR€7,000
14 Sept 2023GFB One s.r.l.GFB One s.r.l. was fined EUR 90,000 by the Italian Garante. The case concerned its failure to respond to requests for information relating to the unauthorized activation of SIM cards and the misuse of personal identification documents.ITGaranteGDPR€90,000