Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Oct 2016AG Preziosi Banco Metalli s.r.l.AG Preziosi Banco Metalli s.r.l. was fined by the Garante for collecting personal data through a website contact form without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
12 Mar 2015Comune di TorittoComune di Toritto was fined by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its website. The conduct breached privacy rules and triggered enforcement action by the supervisory authority.ITGaranteGDPR€10,000
12 Dec 2024Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined by the Garante in the amount of EUR 40,000 for violations related to data processing. The case concerned non-compliance with Art. 2-ter of the Italian Data Protection Code.ITGaranteGDPR€40,000
17 Jul 2025Smart R.E. S.r.l.Smart R.E. S.r.l. was fined EUR 8,000 by the Italian authority Garante for failing to comply with a former employee’s deletion request. After the employment ended, the assigned email account remained active and redirected messages to another company account.ITGaranteGDPR€8,000
06 Feb 2014Arianna ContuArianna Contu was fined by the Garante for operating a video surveillance system in her bar without the required notices informing people of the monitoring. The case concerned non-compliance with privacy law signage obligations.ITGaranteGDPR€2,400
13 Apr 2023Unione PilotiUnione Piloti was fined by the Garante in the amount of 4,000 EUR for violations related to the processing of personal data. The authority found that the company failed to ensure lawful, fair, and transparent data handling.ITGaranteGDPR€4,000
04 Feb 2016Fondazione IRCCS Cà Granda, Ospedale Maggiore PoliclinicoFondazione IRCCS Cà Granda, Ospedale Maggiore Policlinico was fined by the Garante €10,000 for unlawful processing of personal data. The breach involved the incorrect delivery of documents containing health information of third parties.ITGaranteGDPR€10,000
05 Jun 2014Comune di GraffignanoComune di Graffignano was fined EUR 4,000 by the Garante. The authority found that personal data remained published on the institutional website for longer than the legally allowed 15 days.ITGaranteGDPR€4,000
29 May 2008impresa individuale Campodonico PierluigiThe sole proprietorship Campodonico Pierluigi was fined EUR 4,000 by the Garante. The sanction concerned sending unsolicited promotional messages by fax, in breach of data protection rules.ITGaranteGDPR€4,000
12 Feb 2026Conversion Media S.r.l.Conversion Media S.r.l. was fined EUR 10,000 by the Garante for failing to meet data protection obligations. The case concerned telemarketing activities in which required transparency and information duties toward data subjects were not fulfilled.ITGaranteGDPR€10,000
13 Apr 2023Arnia società cooperativaThe Garante imposed a fine of 800,000 EUR on Arnia società cooperativa for unauthorized data processing and telemarketing activities. The case concerned a breach of GDPR Article 5.ITGaranteGDPR€800,000
07 Apr 2022Tecnomed Trento s.r.l.Tecnomed Trento s.r.l. was fined by the Garante 10,000 EUR for operating a video surveillance system that did not comply with GDPR and the Italian Privacy Code. The authority found breaches of information duties and general data processing principles.ITGaranteGDPR€10,000
27 Feb 2020Tim S.p.A.The Italian data protection authority imposed a EUR 27.8 million fine on Tim S.p.A. The case concerned privacy violations in marketing and telemarketing activities, including issues with obtaining valid consent.ITGarante per la protezione dei dati personaliGDPR€27,800,000
22 Feb 2024Azienda Usl Valle d’AostaThe Garante imposed a EUR 75,000 fine on Azienda Usl Valle d’Aosta for unauthorized access to patient health records. Healthcare professionals who were not involved in the patients’ care accessed the data, breaching GDPR data protection requirements.ITGaranteGDPR€75,000
12 Nov 2014Sergio FioreseSergio Fiorese was fined EUR 2,400 by the Garante for failing to provide data subjects with the required information about the processing of personal data. The breach concerned a video surveillance system at the association “Sottosopra”.ITGaranteGDPR€2,400
11 Dec 2008Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c.Centro di analisi e patologia clinica A. Agostini & L. Roussier Fusco & C. s.n.c. was fined for failing to notify the Garante of personal data processing activities within the required timeframe. The case concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
25 Jan 2012Porto 2000 società cooperativa a r. l.Porto 2000 società cooperativa a r. l. was fined EUR 30,000 by the Garante. The authority found that the company had not appointed data processing officers and had failed to implement minimum security measures for the video surveillance system at the Ancona tourist port.ITGaranteGDPR€30,000
15 Apr 2021Clear Channel Italia S.p.A.Clear Channel Italia S.p.A. was fined by the Garante EUR 75,000 for conducting intrusive checks on employees’ devices without a proper legal basis. The authority found breaches of data minimization and proportionality principles.ITGaranteGDPR€75,000
29 May 2008Zampetti PasqualinaZampetti Pasqualina was fined EUR 1,549 by the Garante for sending unsolicited emails. The case concerns a breach of data protection rules in connection with marketing communications sent without a valid legal basis.ITGaranteGDPR€1,549
12 Apr 2018ABC OROLOGERIA E TELEFONIA S.r.l.ABC OROLOGERIA E TELEFONIA S.r.l. was fined by the Garante in the amount of 60,000 EUR for activating SIM cards without the express consent of the individuals to whom the cards were registered. The case concerns a breach of data protection rules.ITGaranteGDPR€60,000