Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Nov 2017Ricciotti CorradoRicciotti Corrado was fined by the Garante 4,000 EUR for violations related to personal data protection. The case involved improper handling of banking documentation.ITGaranteGDPR€4,000
15 Dec 2016Ordinanza ingiunzione - 15 dicembre 2016 [6526145]The Garante imposed a EUR 72,000 fine for sending promotional SMS messages without the recipients’ consent. The contact data came from a database obtained through agreements with a German company, which involved the transfer of personal data abroad.ITGaranteGDPR€72,000
25 Sept 2025Vimar S.p.A.Vimar S.p.A. was fined EUR 15,000 by the Garante for failing to provide adequate information to a complainant and for improper account handling. The account was accessible to unauthorized individuals, indicating weaknesses in access control and safeguards.ITGaranteGDPR€15,000
10 Jul 2014Clinica Siligato s.r.l.Clinica Siligato s.r.l. was fined for failing to notify the Garante of certain processing activities involving health data. The case concerned data used to detect infectious diseases and HIV status, which had to be reported under the Italian Data Protection Code.ITGaranteGDPR€8,000
23 Jan 2020Runwhip s.r.l.Runwhip s.r.l. was fined €80,000 by the Italian supervisory authority, Garante. The sanction concerned failure to respond to information requests, which was treated as a breach of GDPR Article 5.ITGaranteGDPR€80,000
17 Mar 2016Belzirossi s.r.l.Belzirossi s.r.l. was fined by the Italian Garante in the amount of EUR 2,400. The case concerned the use of a video surveillance system without providing data subjects with the required information under data protection rules.ITGaranteGDPR€2,400
27 Jan 2022Musicraiser S.r.l.Musicraiser S.r.l. was fined 1,000 EUR by the Garante for continuing to send newsletters to a user despite multiple requests to be removed. The case concerns a breach of data protection rules on respecting opt-out and cancellation requests for marketing communications.ITGaranteGDPR€1,000
17 Jul 2025Federazione Italiana Sport EquestriThe Italian Data Protection Authority imposed a EUR 10,000 fine on Federazione Italiana Sport Equestri for publishing a disciplinary decision involving a minor on its website without anonymizing personal data. The breach concerned data protection rules and the disclosure of information that could identify the minor.ITGaranteGDPR€10,000
20 Nov 2008Castaldo intermediazione immobiliare di Antonia Romeo e Roberto Castaldo s.n.c.The company was fined by the Garante 6,000 EUR for failing to provide adequate information to data subjects about the processing of personal data collected through its website. The case concerned a breach of the information duties under the Italian Data Protection Code.ITGaranteGDPR€6,000
20 Nov 2008Silvia BriggiSilvia Briggi, a financial consultant, was fined EUR 3,000 by the Garante. The authority found that clients were not provided with the required data protection information under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
29 Mar 2018SERCOM S.r.l.SERCOM S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to notify changes to its name and the cessation of data processing activities related to economic solvency risk.ITGaranteGDPR€20,000
05 Jun 2014Ecaterina GypjasEcaterina Gypjas was fined by the Garante for failing to provide adequate simplified information about the use of a video surveillance system in her hotel. The authority found a breach of data protection rules.ITGaranteGDPR€2,400
04 Mar 2010Enel s.p.a.Enel s.p.a. was fined EUR 24,000 by the Garante for failing to respond to a request for information concerning data protection. The breach concerned Articles 157 and 164 of the Italian Data Protection Code.ITGaranteGDPR€24,000
25 Mar 2021TECNOMEDICAL S.r.l.TECNOMEDICAL S.r.l. was fined by the Garante for violating data protection rules related to the processing of health data. The case concerned non-compliance in the handling of sensitive personal data.ITGaranteGDPR€7,000
17 Apr 2026Comune di VeneziaThe Municipality of Venice was fined €3,000 by the Garante for failing to ensure the required transparency in data processing. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€3,000
24 Nov 2022Dello Russo Giulio ditta individualeThe company was fined for using a biometric fingerprint system to record employee attendance without a valid legal basis. The authority found that the processing did not comply with data protection requirements.ITGaranteGDPR€1,000
19 Jan 2011Center Gross Sicilia S.r.l.Center Gross Sicilia S.r.l. was fined EUR 9,000 by the Garante. The authority found that the required privacy notice was not provided for three external surveillance cameras, in breach of the Italian Data Protection Code.ITGaranteGDPR€9,000
23 Oct 2025Ordine degli Avvocati di LatinaOrdine degli Avvocati di Latina was fined EUR 15,000 by the Garante for unlawful, incorrect, and non-transparent processing of personal data. The authority also found a failure to ensure data minimization.ITGaranteGDPR€15,000
28 Sept 2023Giuseppe AnzaloneThe Garante imposed a EUR 5,000 fine on Giuseppe Anzalone for breaches of personal data processing rules. The case concerned patient data and involved failures to comply with lawfulness, fairness, transparency, data minimization, integrity, and confidentiality principles.ITGaranteGDPR€5,000
17 May 2023Santander Consumer Bank S.p.A.Santander Consumer Bank S.p.A. was fined by the Garante EUR 10,000 for failing to provide timely and adequate access to personal data. The authority also found that prejudicial information related to a loan was not deleted, constituting a breach of GDPR Article 15.ITGaranteGDPR€10,000