Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Sept 2007Asl Benevento 1The Garante fined Asl Benevento 1 10,000 EUR for failing to notify data processing activities within the required timeframe. The breach concerned Article 163 of the Italian Data Protection Code.ITGaranteGDPR€10,000
26 May 2022Regione ToscanaThe Garante fined Regione Toscana EUR 16,000 for publishing unnecessary personal data on the web. The data were later removed, but the authority still found a sanctionable breach.ITGaranteGDPR€16,000
23 Oct 2025Provvedimento del 23 ottobre 2025 [10195910]A fine of EUR 1,000 was imposed for the unlawful online publication of personal data by a local authority. The conduct breached core data protection principles.ITGaranteGDPR€1,000
13 Mar 2025ImmosanremoImmosanremo was fined EUR 3,000 by the Garante for sending unsolicited marketing messages via WhatsApp without valid consent. The authority found that the conduct breached GDPR rules on processing personal data for promotional purposes.ITGaranteGDPR€3,000
26 Mar 2026Esselunga S.p.A.Esselunga S.p.A. was fined EUR 5,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 GDPR, including access to employee attendance records.ITGaranteGDPR€5,000
04 Jun 2015SIAS srlSIAS srl was fined EUR 4,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unlawful processing of personal data, including the acquisition of income data without consent.ITGaranteGDPR€4,000
14 Feb 2013Face2Face s.r.l.Face2Face s.r.l. was fined EUR 40,000 by the Italian data protection authority, Garante. The authority found that the company failed to provide the required privacy notice and did not obtain specific consent from data subjects before processing their data.ITGaranteGDPR€40,000
12 Feb 2026Comune di AnconaThe Garante fined Comune di Ancona EUR 3,000 for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found that no proper contract was in place with a data processor, in breach of GDPR Articles 5 and 28.ITGaranteGDPR€3,000
08 Nov 2012Enterprise Service s.r.l.Enterprise Service s.r.l. was fined by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The authority also found that the required information notice was not provided, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€18,000
14 Sept 2006Azienda sanitaria locale della provincia di MantovaThe local health authority in Mantua was fined for failing to notify the processing of personal data revealing health status and sexual life. The case concerned obligations under the privacy code.ITGaranteGDPR€10,000
12 Mar 2026Almas SalonThe Garante imposed an EUR 800 fine on Almas Salon for operating a video surveillance system without proper compliance with data protection rules. The case concerns a breach of GDPR Article 5, indicating failure to meet core data processing principles.ITGaranteGDPR€800
23 Oct 2025Istituto d'Istruzione Superiore “Statista Aldo Moro” di Fara SabinaThe school published on its website a document containing personal data related to a student's disciplinary proceeding. Garante found that this breached the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
15 Dec 2011dott. Mancini Endriodott. Mancini Endrio was fined EUR 8,000 by the Garante for violating data protection rules. The case concerned inadequate compliance with data security requirements under Article 162, paragraph 2-bis, of the Italian Privacy Code.ITGaranteGDPR€8,000
15 Nov 2012Italiasalute s.r.l.Italiasalute s.r.l. was fined by the Garante EUR 10,400 for processing personal data on its website without providing data subjects with adequate information. The authority also found that consent was obtained in a non-compliant manner, particularly for profiling and marketing purposes.ITGaranteGDPR€10,400
25 Feb 2016Sol Levante s.r.l.Sol Levante s.r.l. was fined EUR 12,000 by the Garante for retaining surveillance footage for 11 days. This exceeded the 7-day limit set out in the authority’s video surveillance guidelines.ITGaranteGDPR€12,000
28 May 2026AgID – Agenzia per l’Italia digitaleThe Italian Data Protection Authority fined AgID €55,000 for failing to adequately inform professionals about the automatic registration of their digital domiciles. The authority found breaches of transparency and data processing principles.ITGaranteGDPR€55,000
29 Jan 2026Università Telematica e-CampusThe Garante fined Università Telematica e-Campus EUR 50,000 for violations related to biometric data processing. The authority also found that the university failed to carry out a proper Data Protection Impact Assessment (DPIA).ITGaranteGDPR€50,000
26 Sept 2024Azienda Sanitaria Territoriale di Ascoli PicenoThe Garante fined Azienda Sanitaria Territoriale di Ascoli Piceno EUR 17,000 for failing to implement procedures that would prevent unauthorized linkage between individuals and health departments. The issue could reveal information about a person's health status.ITGaranteGDPR€17,000
26 Nov 2020Concentrix Cvg Italy s.r.l.Concentrix Cvg Italy s.r.l. was fined 20,000 EUR by the Garante for violating GDPR principles. The case concerned a company policy that improperly handled employees' personal data, including a requirement to keep personal items visible on desks.ITGaranteGDPR€20,000
29 Apr 2021Azienda Usl di BolognaThe Garante fined Azienda Usl di Bologna EUR 30,000 for violations related to the processing of personal data in the electronic health record. The case resulted in a data breach, indicating deficiencies in the protection or handling of patient data.ITGaranteGDPR€30,000