Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Feb 2024Agenzia territoriale della Regione Puglia per il servizio di gestione dei rifiuti (AGER)The Garante fined Agenzia territoriale della Regione Puglia per il servizio di gestione dei rifiuti (AGER) EUR 6,000. The authority found that the organization failed to appoint a Data Protection Officer in a timely manner, despite the GDPR requirement being in force for about three years.ITGaranteGDPR€6,000
30 Jul 2015Comune di GallipoliThe Municipality of Gallipoli was fined by the Garante for unlawfully publishing personal data revealing health status on its institutional website. The conduct breached data protection rules.ITGaranteGDPR€10,000
04 Jun 2025impresa individuale Pasquale GuadagnoThe company was fined for installing a surveillance camera without proper signage. The camera also captured areas beyond its commercial premises, which breached data protection rules.ITGaranteGDPR€2,000
11 Dec 2008Comune di PontenureComune di Pontenure was fined EUR 3,000 by the Garante for failing to provide the required data protection notice when sending a questionnaire about waste management tariffs. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
07 Dec 2023Sirio S.p.A.Sirio S.p.A. was fined EUR 1,000 by the Garante for violating data protection rules. The case concerned the improper handling of an employee’s personal data in connection with issuing a new bank card.ITGaranteGDPR€1,000
06 Jul 2023AcegasApsAmga S.p.A.AcegasApsAmga S.p.A. was fined €10,000 by the Italian supervisory authority, Garante. The sanction concerned the company’s failure to respond to a data subject’s request for access to personal data, in breach of GDPR Article 15.ITGaranteGDPR€10,000
29 Apr 2025Comune di BolognaThe Garante imposed a fine of 40,000 EUR on Comune di Bologna for breaches of data protection principles. The case concerned non-compliance with requirements on lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€40,000
04 Oct 2011Mancosu Editore s.r.l.Mancosu Editore s.r.l. was fined by the Garante 10,400 EUR for sending promotional emails without providing the required information to data subjects and without obtaining explicit consent. The conduct breached Articles 13 and 130 of the Italian Data Protection Code.ITGaranteGDPR€10,400
28 Jul 2016Rigamonti s.r.l.Rigamonti s.r.l. was fined 4,000 EUR by the Garante for sending promotional SMS messages without obtaining the recipient’s prior specific consent. The conduct breached data protection rules governing direct marketing.ITGaranteGDPR€4,000
22 Jul 2021Università degli Studi di Milano-BicoccaUniversità degli Studi di Milano-Bicocca was fined EUR 10,000 by the Garante for data protection violations linked to the publication of personal data on its institutional website. The case concerned the disclosure of information on the university’s website, which breached data processing rules.ITGaranteGDPR€10,000
16 Dec 2021Ubi Banca S.p.a., ora Intesa Sanpaolo S.p.a.Ubi Banca S.p.a., now Intesa Sanpaolo S.p.a., was fined EUR 100,000 by the Italian Garante. The breach involved sending a letter with the phrase “credito anomalo Chieti” visible on the envelope, which could disclose the recipient’s financial information to third parties.ITGaranteGDPR€100,000
14 Sept 2006Azienda sanitaria locale città di MilanoAzienda sanitaria locale città di Milano was fined by the Garante EUR 20,000 for improperly processing personal data concerning health and sexual life without adequate safeguards. The authority found that the processing breached data protection rules.ITGaranteGDPR€20,000
27 Jan 2021Azienda Ospedaliero Universitaria SeneseAzienda Ospedaliero Universitaria Senese was fined by the Garante in the amount of 10,000 EUR for breaches of data protection rules in the healthcare sector. The case concerned the processing of sensitive personal data in a medical setting.ITGaranteGDPR€10,000
26 Sept 2024Città metropolitana di TorinoCittà metropolitana di Torino was fined by the Garante 50,000 EUR for publishing personal data on its institutional website about individuals fined by voluntary ecological guards. The disclosure included names and contact details, breaching data protection rules.ITGaranteGDPR€50,000
14 Oct 2021Azienda per la Tutela della Salute (ATS) della SardegnaAzienda per la Tutela della Salute (ATS) della Sardegna was fined EUR 8,000 by the Garante for improper processing of personal data, including health data. The authority found breaches of GDPR Articles 5 and 9.ITGaranteGDPR€8,000
15 Dec 2022Azienda Universitaria Friuli OccidentaleAzienda Universitaria Friuli Occidentale was fined EUR 55,000 by the Garante for processing personal data without a legal basis. The authority also found that the organization failed to provide required information about data deletion, in breach of the GDPR and national privacy rules.ITGaranteGDPR€55,000
29 Oct 2020Città Metropolitana di NapoliCittà Metropolitana di Napoli was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found that a disciplinary document was not marked as confidential, which allowed unauthorized access within the administration.ITGaranteGDPR€8,000
17 Jan 2013Bagno sport 70 s.a.s.Bagno sport 70 s.a.s. was fined 8,000 EUR by the Garante for processing customers' biometric data for payments. The company failed to notify the supervisory authority, which breached the Italian Data Protection Code.ITGaranteGDPR€8,000
18 Feb 2016Banco dell'oro Operatori professionali in oro srlBanco dell'oro Operatori professionali in oro srl was fined by the Garante EUR 2,400 for operating a video surveillance system without the required data protection notice. The case concerned a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
18 Sept 2008Scip ItaliaScip Italia was fined EUR 3,000 by the Garante for sending unsolicited commercial material by mail. The authority found that the company did not provide the data subject with adequate information required under the Italian Data Protection Code.ITGaranteGDPR€3,000