Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Apr 2015Ministero dell'Interno – Dipartimento della Pubblica SicurezzaThe Ministry of the Interior – Department of Public Security was fined 4,000 EUR for publishing a ranking list containing personal data without a legal or regulatory basis. This constituted a breach of Article 19 of the Italian Privacy Code.ITGaranteGDPR€4,000
30 Jul 2015Roberto NaccaratoRoberto Naccarato was fined by the Garante for processing the personal data of 12 individuals without providing proper information or obtaining consent. The authority found this to be a breach of Italian data protection law.ITGaranteGDPR€76,800
05 Oct 2017Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante 100,000 EUR for publishing a regional council resolution on its institutional website that contained an employee’s personal data. The document included professional evaluations and transfer details.ITGaranteGDPR€100,000
11 Jan 2024Comune di SiracusaThe Garante fined Comune di Siracusa €5,000 for breaches of data protection obligations under Article 37 GDPR. The case concerned failures related to the appointment and management of the data protection officer requirement.ITGaranteGDPR€5,000
06 Jul 2006La Locanda dei f.lli Rosafio Gianfranco, Adriano e Mauro s.n.c.The company was fined for sending unsolicited promotional emails without providing recipients with the required information on data processing. The authority found a breach of the information obligation under data protection law.ITGaranteGDPR€1,549
24 Apr 2024C.I.EL. S.p.A.C.I.EL. S.p.A. was fined 10,000 EUR by the Garante following a complaint from a former employee. The case concerned violations related to the right of access to training certificates.ITGaranteGDPR€10,000
02 Jul 2020Mapei S.p.A.Mapei S.p.A. was fined EUR 15,000 by the Italian authority Garante. The case concerned the failure to respond to a request for access to email communications and the failure to delete an email account after employment ended, in breach of GDPR principles.ITGaranteGDPR€15,000
11 Apr 2013I.S.P. Italia srlI.S.P. Italia srl was fined by the Garante for sending unsolicited promotional faxes without the required information notice and without obtaining recipients’ consent. The authority found that the conduct breached rules on prior consent and information duties.ITGaranteGDPR€32,000
17 Jul 2024Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 50,000 by the Garante for sending promotional emails without obtaining proper customer consent. The authority found this conduct to be a breach of GDPR rules on electronic marketing.ITGaranteGDPR€50,000
24 Apr 2024Rossi Carta S.r.l. UnipersonaleRossi Carta S.r.l. Unipersonale was fined by the Garante 30,000 EUR for sending unsolicited promotional emails and failing to respond to a data subject rights request. The authority also noted the use of an outdated content management system on the company website, which created potential security risks for personal data.ITGaranteGDPR€30,000
12 Dec 2024Wind Tre S.p.A.Wind Tre S.p.A. was fined €347,520 by the Garante for violations related to processing personal data for promotional purposes and for inadequate technical and organizational measures. The case concerned telemarketing activities and the protection of the data involved.ITGaranteGDPR€347,000
10 Jul 2025Poste Vita S.p.a.Poste Vita S.p.a. was fined EUR 80,000 by the Garante for unlawfully disclosing personal data relating to life insurance policies to an unauthorized third party. The data were then used in judicial proceedings.ITGaranteGDPR€80,000
01 Jun 2023Comune di NapoliComune di Napoli was fined for improperly communicating performance evaluation results of former employees. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€3,000
02 Feb 2012Casa di cura Villa Giustina s.r.l.Casa di cura Villa Giustina s.r.l. was fined 40,000 EUR by the Garante. The authority found that the company failed to submit the required notification for personal data processing activities under the Italian Data Protection Code.ITGaranteGDPR€40,000
11 Dec 2014Ferreri Costruzioni s.r.l.Ferreri Costruzioni s.r.l. was fined EUR 2,400 by the Garante for failing to provide data subjects with the required information about data processing through web forms on its website. The conduct breached Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
30 Nov 2023Techno Security s.r.l.Techno Security s.r.l. was fined by the Garante in the amount of 1,000 EUR for failing to respond to a data subject request and for inadequate security measures in its installed security system. The authority found that these failures breached data protection rules.ITGaranteGDPR€1,000
12 Oct 2016AG Preziosi Banco Metalli s.r.l.AG Preziosi Banco Metalli s.r.l. was fined by the Garante for collecting personal data through a website contact form without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
12 Mar 2015Comune di TorittoComune di Toritto was fined by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its website. The conduct breached privacy rules and triggered enforcement action by the supervisory authority.ITGaranteGDPR€10,000
12 Dec 2024Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined by the Garante in the amount of EUR 40,000 for violations related to data processing. The case concerned non-compliance with Art. 2-ter of the Italian Data Protection Code.ITGaranteGDPR€40,000
17 Jul 2025Smart R.E. S.r.l.Smart R.E. S.r.l. was fined EUR 8,000 by the Italian authority Garante for failing to comply with a former employee’s deletion request. After the employment ended, the assigned email account remained active and redirected messages to another company account.ITGaranteGDPR€8,000