Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 May 2016Auto 2000 s.p.a.Auto 2000 s.p.a. was fined by the Garante for collecting personal data through its website without providing users with the required information notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
12 Oct 2016Lorenzo RiccitelliLorenzo Riccitelli was fined 16,000 EUR by the Italian data protection authority, Garante. The case concerned unsolicited emails and SMS messages used for electoral propaganda without the required information or consent from recipients.ITGaranteGDPR€16,000
22 Jul 2021Atac s.p.a.Atac s.p.a. was fined by the Garante 400,000 EUR for processing personal data without a specific legal basis and without adequate security measures. The case concerned users of paid parking services in Rome.ITGaranteGDPR€400,000
11 Jan 2023Azienda Sanitaria Locale di BrindisiAzienda Sanitaria Locale di Brindisi was fined by the Garante 2,500 EUR for failing to respond to a data access request. The authority found a breach of GDPR Article 15.ITGaranteGDPR€2,500
11 Mar 2021Mediacom s.r.l.Mediacom s.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The authority found that this conduct breached GDPR rules on the processing of personal data for marketing purposes.ITGaranteGDPR€15,000
05 Sept 2013Ri.Dat. di Boldetti RenatoRi.Dat. di Boldetti Renato was fined EUR 4,000 by the Garante. The sanction concerned sending unsolicited promotional emails without proper consent, in breach of data protection rules.ITGaranteGDPR€4,000
31 Aug 2023GEDI News Network S.p.a.The Garante imposed a EUR 30,000 fine on GEDI News Network S.p.a. for publishing a photo of minors with insufficient pixelation, making them identifiable. The authority found this to be a breach of data protection rules concerning children.ITGaranteGDPR€30,000
02 Mar 2023H&M Hennes & Mauritz s.r.l.H&M Hennes & Mauritz s.r.l. was fined EUR 50,000 by the Garante for violations related to installing surveillance systems without the required authorization. Employees were informed about the systems, but this did not cure the underlying compliance breach.ITGaranteGDPR€50,000
12 Sept 2024Top Quality Corporation S.r.l.s.Top Quality Corporation S.r.l.s. was fined by the Garante 5,000 EUR for failing to respond to a data subject’s request to access personal data related to employment. The authority found a breach of GDPR Articles 12 and 15.ITGaranteGDPR€5,000
13 May 2015Barbirato Danilo s.a.s.Barbirato Danilo s.a.s. was fined by the Garante EUR 16,800 for failing to provide the required privacy notice on its website and for improper use of a video surveillance system. The authority cited inadequate CCTV signage and excessive retention of recorded images.ITGaranteGDPR€16,800
19 Dec 2024Altroconsumo Edizioni S.r.l.Altroconsumo Edizioni S.r.l. was fined by the Garante EUR 60,000 for sending unsolicited marketing emails despite unsubscribe requests. The authority also found deficiencies in obtaining valid consent and in the handling of personal data by third-party affiliates involved in the campaign.ITGaranteGDPR€60,000
18 Apr 2013Digital Design di Patron AndreaDigital Design di Patron Andrea was fined 2,400 EUR by the Garante. The authority found that the website's contact form lacked the required data protection information, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
26 Mar 2015Artsana s.p.a.Artsana s.p.a. was fined by the Garante for failing to provide adequate simplified information about its video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
14 Jan 2016Comune di Santa FlaviaThe Garante fined Comune di Santa Flavia €10,000 for unlawfully publishing documents on its website that disclosed individuals' health data. The case involved the disclosure of sensitive personal data without a lawful basis.ITGaranteGDPR€10,000
07 Sept 2011Aga s.r.l.Aga s.r.l. was fined EUR 8,000 by the Garante for processing online customers' personal data without ensuring freely given and specific consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€8,000
21 Jan 2016Federico FabiFederico Fabi was fined by the Garante for failing to provide the required information to data subjects when collecting personal data through forms on the company’s website. The case concerns a breach of transparency and notice obligations under data protection rules.ITGaranteGDPR€2,400
09 May 2024Polisportiva Mimmo Ferrito s.r.l.The Garante fined Polisportiva Mimmo Ferrito s.r.l. EUR 3,000 for failing to respond to a data subject's request to exercise their rights. The case concerns non-compliance with data protection obligations.ITGaranteGDPR€3,000
02 Mar 2017Trilogy s.r.l.Trilogy s.r.l. and Fastweb s.p.a. were fined for making unsolicited promotional calls to a phone number listed in the public opt-out register. The conduct breached data protection rules.ITGaranteGDPR€20,000
14 Nov 2024Comune di Borgo Val di TaroComune di Borgo Val di Taro was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€8,000
08 Sept 2016Pan YinpinPan Yinpin was fined 2,400 EUR by the Garante. The authority found that data subjects were not informed about the processing of personal data through a video surveillance system.ITGaranteGDPR€2,400