Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Jul 2022Comune di GinosaComune di Ginosa was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the whistleblowing context. The authority found that an adequately high level of confidentiality and protection for the data subjects was not ensured.ITGaranteGDPR€5,000
16 May 2018Bolignari PietroBolignari Pietro, a general practitioner, was fined for failing to implement minimum security measures for personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
28 Apr 2022Liceo Statale “Isabella Gonzaga”Liceo Statale “Isabella Gonzaga” was fined by the Garante 2,500 EUR for publishing information on teachers' Law 104 benefits in an electronic register. The register was accessible to other teachers, which breached the GDPR and national privacy code provisions.ITGaranteGDPR€2,500
06 Oct 2016Infantino Auto S.r.l.ITGaranteGDPR€2,400
28 May 2015Xpedite Systems s.r.l.Xpedite Systems s.r.l. was fined 64,000 EUR by the Garante for sending unsolicited promotional faxes without the required notice and consent. The authority found this to be a breach of privacy rules.ITGaranteGDPR€64,000
19 Jul 2018Active Network S.p.a.Active Network S.p.a. was fined by the Garante 20,000 EUR for retaining telematic traffic data for more than 12 months. The authority found that this practice breached data protection rules in the context of crime detection and repression.ITGaranteGDPR€20,000
28 Jul 2022Auto Hi-Fi System S.n.cAuto Hi-Fi System S.n.c was fined EUR 2,000 by the Garante. The surveillance camera captured public areas and private property without proper notice, breaching data protection principles.ITGaranteGDPR€2,000
22 Oct 2015Comune di Montelupo FiorentinoThe Municipality of Comune di Montelupo Fiorentino was fined 4,000 EUR by the Garante for unlawfully publishing personal data online. The case concerned the results of participants in a competitive examination disclosed without a proper legal basis.ITGaranteGDPR€4,000
22 Jun 2016Aemme Car S.r.l.Aemme Car S.r.l. was fined by the Garante in the amount of 2,400 EUR for collecting personal data through its website without providing users with the required information notice. This conduct breached the Italian data protection code.ITGaranteGDPR€2,400
11 Apr 2024Facile.Energy S.r.l.Facile.Energy S.r.l. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without prior consent and activating energy supplies without a request from the customer. The authority found that these practices breached GDPR rules on data protection and security measures.ITGaranteGDPR€100,000
23 Apr 2015Novelli DonataNovelli Donata was fined EUR 20,000 by the Garante. The case concerned the activation of eight phone cards in the names of four individuals without their knowledge, which breached data protection rules.ITGaranteGDPR€20,000
09 May 2024Ordine dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche, della Riabilitazione e della Prevenzione della provincia di MantovaThe Garante imposed a 3,000 EUR fine on the Ordine dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche, della Riabilitazione e della Prevenzione della provincia di Mantova for breaches of data protection principles. The authority found non-compliance with lawfulness, fairness, transparency, and data minimization. The infringement affected a significant number of data subjects.ITGaranteGDPR€3,000
13 Jan 2022Azienda Sanitaria Locale FrosinoneAzienda Sanitaria Locale Frosinone was fined by the Italian supervisory authority, Garante, in the amount of EUR 7,500. The case concerned breaches of transparency and information duties in personal data processing under GDPR Articles 12 and 13.ITGaranteGDPR€7,500
23 Mar 2023Consiglio Nazionale dell'Ordine degli Assistenti SocialiConsiglio Nazionale dell'Ordine degli Assistenti Sociali was fined EUR 3,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data during a recruitment process, including disclosure of information about a candidate's exclusion.ITGaranteGDPR€3,000
23 Jan 2014Impresa individuale Destro AnnaImpresa individuale Destro Anna was fined EUR 4,800 by the Garante. The violation concerned collecting personal data through a website form and using a video surveillance system without the required privacy information notice.ITGaranteGDPR€4,800
30 Mar 2017Acantho s.p.a.Acantho s.p.a. was fined by the Garante in the amount of EUR 30,000 for retaining telephone and telematic traffic data longer than legally permitted. The authority found this to be a breach of data protection rules.ITGaranteGDPR€30,000
16 Nov 2017Terre Etrusche e di Maremma Credito CooperativoThe Garante fined Terre Etrusche e di Maremma Credito Cooperativo EUR 10,000 for inadequate password security measures. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€10,000
13 Jul 2006Comune di LatinaThe Municipality of Latina was fined by the Garante for failing to notify the processing of students’ personal data obtained from public records. The authority found a breach of the obligations under the data protection code.ITGaranteGDPR€5,164
20 Jun 2013ASL di SalernoASL di Salerno was fined EUR 18,000 by the Garante for failing to implement minimum security measures. The authority cited, among other issues, the absence of designated data processing managers and the use of common, outdated passwords for electronic systems.ITGaranteGDPR€18,000
20 Oct 2022Azienda Ospedaliero-Universitaria Careggi di FirenzeAzienda Ospedaliero-Universitaria Careggi di Firenze was fined by the Garante 9,000 EUR for violations involving the processing of sensitive health data. The authority cited inadequate safeguards in the handling of histological examinations.ITGaranteGDPR€9,000