Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Nov 2017Terre Etrusche e di Maremma Credito CooperativoThe Garante fined Terre Etrusche e di Maremma Credito Cooperativo EUR 10,000 for inadequate password security measures. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€10,000
13 Jul 2006Comune di LatinaThe Municipality of Latina was fined by the Garante for failing to notify the processing of students’ personal data obtained from public records. The authority found a breach of the obligations under the data protection code.ITGaranteGDPR€5,164
20 Jun 2013ASL di SalernoASL di Salerno was fined EUR 18,000 by the Garante for failing to implement minimum security measures. The authority cited, among other issues, the absence of designated data processing managers and the use of common, outdated passwords for electronic systems.ITGaranteGDPR€18,000
20 Oct 2022Azienda Ospedaliero-Universitaria Careggi di FirenzeAzienda Ospedaliero-Universitaria Careggi di Firenze was fined by the Garante 9,000 EUR for violations involving the processing of sensitive health data. The authority cited inadequate safeguards in the handling of histological examinations.ITGaranteGDPR€9,000
13 Sept 2007Asl Benevento 1The Garante fined Asl Benevento 1 10,000 EUR for failing to notify data processing activities within the required timeframe. The breach concerned Article 163 of the Italian Data Protection Code.ITGaranteGDPR€10,000
26 May 2022Regione ToscanaThe Garante fined Regione Toscana EUR 16,000 for publishing unnecessary personal data on the web. The data were later removed, but the authority still found a sanctionable breach.ITGaranteGDPR€16,000
23 Oct 2025Provvedimento del 23 ottobre 2025 [10195910]A fine of EUR 1,000 was imposed for the unlawful online publication of personal data by a local authority. The conduct breached core data protection principles.ITGaranteGDPR€1,000
13 Mar 2025ImmosanremoImmosanremo was fined EUR 3,000 by the Garante for sending unsolicited marketing messages via WhatsApp without valid consent. The authority found that the conduct breached GDPR rules on processing personal data for promotional purposes.ITGaranteGDPR€3,000
26 Mar 2026Esselunga S.p.A.Esselunga S.p.A. was fined EUR 5,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 GDPR, including access to employee attendance records.ITGaranteGDPR€5,000
04 Jun 2015SIAS srlSIAS srl was fined EUR 4,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unlawful processing of personal data, including the acquisition of income data without consent.ITGaranteGDPR€4,000
14 Feb 2013Face2Face s.r.l.Face2Face s.r.l. was fined EUR 40,000 by the Italian data protection authority, Garante. The authority found that the company failed to provide the required privacy notice and did not obtain specific consent from data subjects before processing their data.ITGaranteGDPR€40,000
12 Feb 2026Comune di AnconaThe Garante fined Comune di Ancona EUR 3,000 for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found that no proper contract was in place with a data processor, in breach of GDPR Articles 5 and 28.ITGaranteGDPR€3,000
08 Nov 2012Enterprise Service s.r.l.Enterprise Service s.r.l. was fined by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The authority also found that the required information notice was not provided, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€18,000
14 Sept 2006Azienda sanitaria locale della provincia di MantovaThe local health authority in Mantua was fined for failing to notify the processing of personal data revealing health status and sexual life. The case concerned obligations under the privacy code.ITGaranteGDPR€10,000
12 Mar 2026Almas SalonThe Garante imposed an EUR 800 fine on Almas Salon for operating a video surveillance system without proper compliance with data protection rules. The case concerns a breach of GDPR Article 5, indicating failure to meet core data processing principles.ITGaranteGDPR€800
23 Oct 2025Istituto d'Istruzione Superiore “Statista Aldo Moro” di Fara SabinaThe school published on its website a document containing personal data related to a student's disciplinary proceeding. Garante found that this breached the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
15 Dec 2011dott. Mancini Endriodott. Mancini Endrio was fined EUR 8,000 by the Garante for violating data protection rules. The case concerned inadequate compliance with data security requirements under Article 162, paragraph 2-bis, of the Italian Privacy Code.ITGaranteGDPR€8,000
15 Nov 2012Italiasalute s.r.l.Italiasalute s.r.l. was fined by the Garante EUR 10,400 for processing personal data on its website without providing data subjects with adequate information. The authority also found that consent was obtained in a non-compliant manner, particularly for profiling and marketing purposes.ITGaranteGDPR€10,400
25 Feb 2016Sol Levante s.r.l.Sol Levante s.r.l. was fined EUR 12,000 by the Garante for retaining surveillance footage for 11 days. This exceeded the 7-day limit set out in the authority’s video surveillance guidelines.ITGaranteGDPR€12,000
28 May 2026AgID – Agenzia per l’Italia digitaleThe Italian Data Protection Authority fined AgID €55,000 for failing to adequately inform professionals about the automatic registration of their digital domiciles. The authority found breaches of transparency and data processing principles.ITGaranteGDPR€55,000