Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Sept 2015Jackpot srlJackpot srl was fined for failing to respond to a request for information within the required timeframe. This constituted a breach of the Italian Privacy Code.ITGaranteGDPR€4,000
17 Oct 2013ICA Foods S.p.a.ICA Foods S.p.a. was fined by the Garante for installing a video surveillance system without providing employees with adequate information. The conduct breached privacy rules and the information obligations applicable to monitored persons.ITGaranteGDPR€2,400
09 May 2018Telefonika s.r.l.sTelefonika s.r.l.s was fined by the Italian data protection authority, Garante, in the amount of EUR 42,000. The sanction concerned numerous unsolicited promotional phone calls made without proper consent.ITGaranteGDPR€42,000
22 Dec 2016Comune di VergatoComune di Vergato was fined by the Garante for retaining surveillance footage beyond the permitted period. The case concerned non-compliance with data protection rules on storage limitation and video retention.ITGaranteGDPR€12,000
02 Apr 2015Comune di AccianoComune di Acciano was fined 4,000 EUR by the Garante for unlawfully processing personal data by keeping a council resolution online beyond the legally permitted period. The case concerned non-compliance with data protection rules on retention and publication limits.ITGaranteGDPR€4,000
12 Mar 2026INPS – Istituto nazionale previdenza socialeThe Italian Data Protection Authority fined INPS EUR 40,000 for improperly displaying personal data of individuals residing in a care facility during an ISEE precompilation request. The authority found a breach of data protection principles.ITGaranteGDPR€40,000
19 Oct 2017Grant Change s.r.l.Grant Change s.r.l. was fined €32,000 by the Italian data protection authority, Garante. The penalty concerned the sending of promotional SMS messages and emails without valid consent from recipients, in breach of data protection rules.ITGaranteGDPR€32,000
23 Nov 2017AMAT PALERMO S.P.A.AMAT PALERMO S.P.A. was fined by the Garante 20,000 EUR for failing to properly notify the use of a geolocation system to track vehicles. The authority found a breach of the Italian data protection code.ITGaranteGDPR€20,000
25 Jan 2018Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined by the Garante 60,000 EUR for publishing special-category personal data, including health information, on its institutional website. The disclosure breached data protection rules and triggered supervisory enforcement.ITGaranteGDPR€60,000
28 Jun 2018ANSORGE LOGISTICA ITALIA S.r.l.ANSORGE LOGISTICA ITALIA S.r.l. was fined EUR 8,000 by the Garante. The case concerned employee geolocation carried out without proper compliance with data protection rules.ITGaranteGDPR€8,000
17 Mar 2016Gruppo Scuole s.r.l. – Istituto Giuseppe Mazzini di AvezzanoGruppo Scuole s.r.l. was fined by the Garante for collecting personal data through its website without providing the required privacy notice and without obtaining consent. The authority found violations of Articles 13 and 23 of the Italian Privacy Code.ITGaranteGDPR€2,400
04 Aug 2025Azienda Ospedaliero-UniversitariaThe Italian data protection authority fined Azienda Ospedaliero-Universitaria EUR 80,000 for improperly configuring its health dossier. It found that staff could access patients’ clinical histories without proper profiling, alerts, or access logging, and that patients were not adequately informed or able to consent or object.ITGarante per la protezione dei dati personaliGDPR€80,000
18 Apr 2018Anas S.p.A.Anas S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to designate employees as data processors and for not issuing instructions on the proper use of surveillance and geolocation systems. The authority found that these omissions breached data protection rules.ITGaranteGDPR€20,000
15 Jun 2011Fastrent Money srlFastrent Money srl was fined by the Garante EUR 6,000 for sending unsolicited commercial faxes. The authority also found that the required data protection information under Article 13 of the Italian Data Protection Code was not provided.ITGaranteGDPR€6,000
24 Oct 2013Stadek sncStadek snc was fined EUR 4,000 by the Garante for non-compliant video surveillance signage. The case concerns a breach of data protection requirements related to informing individuals about surveillance.ITGaranteGDPR€4,000
12 Mar 2015Azienda Ospedaliera Bolognini di SeriateAzienda Ospedaliera Bolognini di Seriate was fined by the Garante for sending medical reports to an incorrect address without the patient's consent. The case involved a breach of data protection rules and the confidentiality of medical information.ITGaranteGDPR€4,000
21 Feb 2013Terme Forlenza di Forlenza Ferruccio & C. s.n.c.Terme Forlenza was fined EUR 4,800 by the Italian Garante. The case concerned the failure to provide the required privacy notice when collecting personal data through the hotel booking form on its website.ITGaranteGDPR€4,800
28 Feb 2019Comune di MisterbiancoComune di Misterbianco was fined by the Garante 4,000 EUR for unlawful processing of personal data. The breach involved publishing personal information on its website beyond the legally permitted period.ITGaranteGDPR€4,000
21 Jul 2022Global Service s.r.l.Global Service s.r.l. was fined by the Garante EUR 2,000 for installing a video surveillance system without the required informational signage. The case concerned a breach of data protection rules and the duty to properly inform individuals under surveillance.ITGaranteGDPR€2,000
14 Dec 2017Rotondi AndreaAndrea Rotondi was fined for the improper handling of banking documents that were found by a private citizen. Banca Nazionale del Lavoro was held jointly liable for the violation.ITGaranteGDPR€4,000