Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Mar 2026INPS – Istituto nazionale previdenza socialeThe Italian Data Protection Authority fined INPS EUR 40,000 for improperly displaying personal data of individuals residing in a care facility during an ISEE precompilation request. The authority found a breach of data protection principles.ITGaranteGDPR€40,000
19 Oct 2017Grant Change s.r.l.Grant Change s.r.l. was fined €32,000 by the Italian data protection authority, Garante. The penalty concerned the sending of promotional SMS messages and emails without valid consent from recipients, in breach of data protection rules.ITGaranteGDPR€32,000
23 Nov 2017AMAT PALERMO S.P.A.AMAT PALERMO S.P.A. was fined by the Garante 20,000 EUR for failing to properly notify the use of a geolocation system to track vehicles. The authority found a breach of the Italian data protection code.ITGaranteGDPR€20,000
25 Jan 2018Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined by the Garante 60,000 EUR for publishing special-category personal data, including health information, on its institutional website. The disclosure breached data protection rules and triggered supervisory enforcement.ITGaranteGDPR€60,000
28 Jun 2018ANSORGE LOGISTICA ITALIA S.r.l.ANSORGE LOGISTICA ITALIA S.r.l. was fined EUR 8,000 by the Garante. The case concerned employee geolocation carried out without proper compliance with data protection rules.ITGaranteGDPR€8,000
17 Mar 2016Gruppo Scuole s.r.l. – Istituto Giuseppe Mazzini di AvezzanoGruppo Scuole s.r.l. was fined by the Garante for collecting personal data through its website without providing the required privacy notice and without obtaining consent. The authority found violations of Articles 13 and 23 of the Italian Privacy Code.ITGaranteGDPR€2,400
18 Apr 2018Anas S.p.A.Anas S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to designate employees as data processors and for not issuing instructions on the proper use of surveillance and geolocation systems. The authority found that these omissions breached data protection rules.ITGaranteGDPR€20,000
15 Jun 2011Fastrent Money srlFastrent Money srl was fined by the Garante EUR 6,000 for sending unsolicited commercial faxes. The authority also found that the required data protection information under Article 13 of the Italian Data Protection Code was not provided.ITGaranteGDPR€6,000
24 Oct 2013Stadek sncStadek snc was fined EUR 4,000 by the Garante for non-compliant video surveillance signage. The case concerns a breach of data protection requirements related to informing individuals about surveillance.ITGaranteGDPR€4,000
12 Mar 2015Azienda Ospedaliera Bolognini di SeriateAzienda Ospedaliera Bolognini di Seriate was fined by the Garante for sending medical reports to an incorrect address without the patient's consent. The case involved a breach of data protection rules and the confidentiality of medical information.ITGaranteGDPR€4,000
21 Feb 2013Terme Forlenza di Forlenza Ferruccio & C. s.n.c.Terme Forlenza was fined EUR 4,800 by the Italian Garante. The case concerned the failure to provide the required privacy notice when collecting personal data through the hotel booking form on its website.ITGaranteGDPR€4,800
28 Feb 2019Comune di MisterbiancoComune di Misterbianco was fined by the Garante 4,000 EUR for unlawful processing of personal data. The breach involved publishing personal information on its website beyond the legally permitted period.ITGaranteGDPR€4,000
21 Jul 2022Global Service s.r.l.Global Service s.r.l. was fined by the Garante EUR 2,000 for installing a video surveillance system without the required informational signage. The case concerned a breach of data protection rules and the duty to properly inform individuals under surveillance.ITGaranteGDPR€2,000
14 Dec 2017Rotondi AndreaAndrea Rotondi was fined for the improper handling of banking documents that were found by a private citizen. Banca Nazionale del Lavoro was held jointly liable for the violation.ITGaranteGDPR€4,000
16 Nov 2017Ricciotti CorradoRicciotti Corrado was fined by the Garante 4,000 EUR for violations related to personal data protection. The case involved improper handling of banking documentation.ITGaranteGDPR€4,000
15 Dec 2016Ordinanza ingiunzione - 15 dicembre 2016 [6526145]The Garante imposed a EUR 72,000 fine for sending promotional SMS messages without the recipients’ consent. The contact data came from a database obtained through agreements with a German company, which involved the transfer of personal data abroad.ITGaranteGDPR€72,000
25 Sept 2025Vimar S.p.A.Vimar S.p.A. was fined EUR 15,000 by the Garante for failing to provide adequate information to a complainant and for improper account handling. The account was accessible to unauthorized individuals, indicating weaknesses in access control and safeguards.ITGaranteGDPR€15,000
10 Jul 2014Clinica Siligato s.r.l.Clinica Siligato s.r.l. was fined for failing to notify the Garante of certain processing activities involving health data. The case concerned data used to detect infectious diseases and HIV status, which had to be reported under the Italian Data Protection Code.ITGaranteGDPR€8,000
23 Jan 2020Runwhip s.r.l.Runwhip s.r.l. was fined €80,000 by the Italian supervisory authority, Garante. The sanction concerned failure to respond to information requests, which was treated as a breach of GDPR Article 5.ITGaranteGDPR€80,000
17 Mar 2016Belzirossi s.r.l.Belzirossi s.r.l. was fined by the Italian Garante in the amount of EUR 2,400. The case concerned the use of a video surveillance system without providing data subjects with the required information under data protection rules.ITGaranteGDPR€2,400