Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Jan 2017Perrone Rosaria e Azienda Universitaria Ospedaliera Ospedali Riuniti di TriestePerrone Rosaria and Azienda Universitaria Ospedaliera Ospedali Riuniti di Trieste were fined by the Garante 20,000 EUR. The sanction concerned unauthorized access by medical staff to personal health data, in breach of data protection rules.ITGaranteGDPR€20,000
22 Jul 2021Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 35,000 by the Garante for failing to adopt minimum security measures. The breach resulted in exposure of health data, creating a significant compliance and privacy risk.ITGaranteGDPR€35,000
17 Jul 2024IstitutoThe Garante fined Istituto EUR 10,000 for violations related to the processing of personal data in the context of medical and scientific research. The authority found that retention periods were not defined and transparency toward data subjects was insufficient.ITGaranteGDPR€10,000
04 Dec 2014Comune di SparaniseComune di Sparanise was fined for unlawfully publishing personal data, including IBAN and bank account details, on its institutional website without a legal basis. The authority found this to be a breach of data protection rules.ITGaranteGDPR€8,000
18 Jul 2023Prodav s.r.l.Prodav s.r.l. was fined by the Garante 1,000 EUR for operating a surveillance camera without the required informational signage and safeguards. The case concerned non-compliance with data protection rules and the duty to inform individuals under surveillance.ITGaranteGDPR€1,000
12 Apr 2018Emanuele CollaEmanuele Colla was fined by the Garante for activating seven phone cards without the consent of the person whose data was used. The case concerns a breach of data protection rules and the unauthorized use of personal data.ITGaranteGDPR€16,000
18 Apr 2018Futur3 s.r.l.Futur3 s.r.l. was fined EUR 50,000 by the Garante for requiring users to give mandatory consents for marketing and profiling purposes that were not directly related to the requested Wi‑Fi service. The authority found this to be a breach of data protection rules.ITGaranteGDPR€50,000
08 Jun 2023AziendaThe company was fined for failing to process personal data in a lawful, fair, and transparent manner. The authority also found breaches of data minimization and inadequate security measures.ITGaranteGDPR€5,000
12 May 2011Jnternet srlJnternet srl was fined by the Italian data protection authority, Garante, in the amount of EUR 10,000. The case concerned the failure to respond to requests for information about compliance with data protection obligations in connection with promotional emails sent without proper consent.ITGaranteGDPR€10,000
20 Dec 2012Regione Emilia RomagnaRegione Emilia Romagna was fined EUR 14,000 by the Garante for unlawfully disseminating personal data through the Regional Student Registry without a legal basis. The authority also found unauthorized retention of sensitive student data.ITGaranteGDPR€14,000
04 Apr 2013Stifter Josef KGStifter Josef KG was fined 2,400 EUR by the Garante. The company failed to provide the required data protection notice to customers when collecting personal data during online orders.ITGaranteGDPR€2,400
05 Mar 2015Antonianum s.r.l.Antonianum s.r.l. was fined EUR 8,000 by the Garante. The authority found that consent flags for data processing were pre-set on the company’s websites, which did not meet user consent requirements.ITGaranteGDPR€8,000
11 Jul 2018Comune di VollaComune di Volla was fined by the Garante EUR 10,000 for allowing all employees access to sensitive and judicial personal data through its electronic protocol system. The authority found that this setup failed to meet required data protection safeguards.ITGaranteGDPR€10,000
10 Oct 2013TeleTu s.p.a.TeleTu s.p.a. was fined 60,000 EUR by the Italian Garante. The sanction concerned unsolicited promotional phone calls made without the required consent of the data subject.ITGaranteGDPR€60,000
27 Jan 2021Dental Leader S.p.A.Dental Leader S.p.A. was fined EUR 10,000 by the Garante. The authority found that the company required consent to process personal data for promotional purposes in order to complete an online order, even though this was not necessary for contract performance.ITGaranteGDPR€10,000
28 Jul 2022Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined EUR 100,000 by Garante after an employee accessed a customer's financial data without authorization. The data was then used in judicial proceedings. The authority found that the bank had not implemented adequate data protection measures.ITGaranteGDPR€100,000
22 May 2014Tenacta Group s.p.a.Tenacta Group s.p.a. was fined €10,000 by the Garante for making an unsolicited promotional phone call. The conduct breached the complainant’s right to object, as recorded in the public opt-out list.ITGaranteGDPR€10,000
11 Oct 2012Casa di cura Eretenia S.p.a.The Garante fined Casa di cura Eretenia S.p.a. €30,000 for failing to provide proper data protection notices in its video surveillance system. The authority found a breach of privacy rules and the duty to inform individuals subject to monitoring.ITGaranteGDPR€30,000
05 Sept 2013Iniziative Commerciali S.r.l.Iniziative Commerciali S.r.l. was fined by the Garante for collecting personal data through a website contact form without providing the required privacy notice. This breached the Italian Data Protection Code.ITGaranteGDPR€4,800
02 Mar 2023Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 50,000 by the Garante for violations in the processing of personal data. The authority found non-compliance with the principles of data minimization and integrity and confidentiality.ITGaranteGDPR€50,000