Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Dec 2012Azienda sanitaria regionale MoliseThe Regional Health Company of Molise was fined for failing to designate data processing officers for each employee. The authority also found that minimum security measures for electronic processing were not implemented, including weak password policies and insufficient protection against unauthorized external access.ITGaranteGDPR€15,000
15 Feb 2018Casa della legalità e della cultura onlusCasa della legalità e della cultura onlus was fined EUR 20,000 by the Garante. The authority found a data protection breach because the organization failed to respond to requests for information about the publication of personal data on its websites.ITGaranteGDPR€20,000
24 Nov 2022Azienda per la tutela della salute - ATS SardegnaATS Sardegna was fined by the Garante for breaching data protection principles in its handling of personal data relating to an employee's vaccination status. The authority found violations of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
15 Dec 2022Altroconsumo Edizioni S.r.lAltroconsumo Edizioni S.r.l was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a proper legal basis. The authority also found that the company failed to provide adequate information and to obtain free and specific consent from data subjects.ITGaranteGDPR€100,000
25 Mar 2021Fastweb S.p.A.Fastweb S.p.A. was sanctioned by the Garante for making unauthorized promotional calls and sending messages without proper consent. The authority also found insufficient measures to ensure data processing security and GDPR compliance.ITGaranteGDPR€4,501,000
26 Jan 2011Doss s.a.s. di Mazza Mario & C.Doss s.a.s. was fined by the Garante EUR 6,000 for processing personal data without proper consent. The company purchased and used personal data lists for promotional mailings without an adequate legal basis.ITGaranteGDPR€6,000
23 Mar 2011Radio Casa s.r.l.Radio Casa s.r.l. was fined 8,000 EUR by the Garante for activating an automatic preselection service without the user's consent. The authority treated this as a breach of data protection rules.ITGaranteGDPR€8,000
08 May 2014Galleria Voci s.r.l.Galleria Voci s.r.l. was fined EUR 2,400 by the Garante for failing to provide simplified information about the use of a video surveillance system. The authority found this to be a breach of privacy and data protection rules.ITGaranteGDPR€2,400
21 Jan 2010I.S.A. - Istituto Scolastico Ambrosiano s.n.c.I.S.A. - Istituto Scolastico Ambrosiano s.n.c. was fined EUR 6,000 by the Garante. The case concerned the collection of personal data through its website without providing users with adequate information required under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
29 Nov 2012Eco Education s.r.l.Eco Education s.r.l. was fined by the Garante 10,400 EUR for sending promotional faxes without prior, specific, and informed consent from recipients. The authority found this to be a breach of data protection rules.ITGaranteGDPR€10,400
16 Sept 2021Azienda Ospedaliero-Universitaria di ModenaAzienda Ospedaliero-Universitaria di Modena was fined by the Garante for the incorrect handling of sensitive health data, including HIV diagnoses, during the COVID-19 emergency. The case concerned breaches of personal data protection rules and medical confidentiality.ITGaranteGDPR€20,000
16 Dec 2010Eraclea Minoa Village s.r.l.Eraclea Minoa Village s.r.l. was fined 6,000 EUR by the Garante for collecting personal data through its website without providing the required privacy notice. The case concerned a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
26 Mar 2026Euro Bangla MinimarketThe Garante fined Euro Bangla Minimarket EUR 1,000 for improper use of a video surveillance system. Images from six cameras were visible to everyone on a monitor in the store, which breached GDPR requirements.ITGaranteGDPR€1,000
15 Dec 2022Verizon Connect Italy S.p.A.Verizon Connect Italy S.p.A. was fined EUR 30,000 by the Garante for violations linked to the unauthorized installation of a geolocation device in a vehicle. The authority found that the processing of personal data breached GDPR requirements.ITGaranteGDPR€30,000
01 Oct 2015San Vincenzo di Fernando Rota s.r.l.San Vincenzo di Fernando Rota s.r.l. was fined by the Garante for processing employees’ biometric data without notifying the authority and without requesting prior verification. The conduct breached privacy rules and the requirements applicable to sensitive data processing.ITGaranteGDPR€30,000
24 Jun 2020Azienda Sanitaria Universitaria Giuliano IsontinaAzienda Sanitaria Universitaria Giuliano Isontina was fined by the Garante for unlawfully communicating health data without an adequate legal basis. The conduct breached Article 20 of the Italian Privacy Code.ITGaranteGDPR€10,000
10 Nov 2010Fitness Solution società sportiva dilettantistica s.r.l.Fitness Solution was fined EUR 10,000 by the Garante. The authority found that biometric personal data were processed without proper consent and retained longer than necessary.ITGaranteGDPR€10,000
27 Jan 2021Azienda ospedaliera regionale “San Carlo” di PotenzaAzienda ospedaliera regionale “San Carlo” di Potenza was fined EUR 70,000 by the Garante for violations related to the processing of personal data. The case concerned the handling of sensitive health data.ITGaranteGDPR€70,000
29 Apr 2021Azienda Ospedaliero Universitaria PisanaAzienda Ospedaliero Universitaria Pisana was fined by the Garante EUR 4,000 for breaches of the principles of lawfulness, fairness, transparency, integrity, and confidentiality in data processing. The case concerned improper handling of personal data under GDPR requirements.ITGaranteGDPR€4,000
30 Oct 2013Continental Terme srlContinental Terme srl was fined EUR 12,400 by the Garante for providing inadequate privacy notices and obtaining a single consent for multiple data processing activities. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€12,400