Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Oct 2025Azzurra Sport s.r.l.Azzurra Sport s.r.l. was fined EUR 4,000 by the Garante for unlawful processing of personal data through a video surveillance system. The breach concerned the absence of appropriate informational signage for individuals subject to the monitoring.ITGaranteGDPR€4,000
25 Sept 2025RCS MediaGroup S.p.a.RCS MediaGroup S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 100,000. The case concerned the publication of images of a person in a private setting without consent, which infringed privacy rights.ITGaranteGDPR€100,000
06 Oct 2022Servizio Idrico Integrato S.c.p.a.Servizio Idrico Integrato S.c.p.a. was fined by the Garante EUR 15,000 for failing to implement adequate security measures to protect the personal data of users registered on its website. The case concerned insufficient safeguards for data processed online.ITGaranteGDPR€15,000
19 Sept 2013Impresa Individuale Oriana Grandi EventiThe company was fined for collecting personal data through a website form without providing the required privacy notice. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
07 Mar 2013Paolo RanieriPaolo Ranieri was fined 6,400 EUR by the Italian data protection authority, Garante. The sanction concerned sending an electoral email without the required information and without obtaining consent from recipients.ITGaranteGDPR€6,400
30 Jan 2025Azienda Unità Sanitaria locale di ModenaAzienda Unità Sanitaria locale di Modena was fined by the Garante €10,000 for processing personal data concerning health and other sensitive information without a proper legal basis. The case involved unlawful processing of special-category data, which raises heightened compliance and privacy risks.ITGaranteGDPR€10,000
03 Apr 2014Armando ChessaArmando Chessa was fined by the Garante for failing to provide adequate information about the use of a video surveillance system. The authority found a breach of data protection rules.ITGaranteGDPR€2,400
14 Dec 2017Telenando di Sannino Caterina e C s.a.s.Telenando di Sannino Caterina e C s.a.s. was fined by the Garante EUR 30,000 for registering phone cards to unaware third parties without their consent. The case concerned a breach of data protection rules.ITGaranteGDPR€30,000
11 Feb 2021Istituti ospedalieri bergamaschiThe Garante fined Istituti ospedalieri bergamaschi EUR 45,000 for a data protection breach. Online medical reports were accessible to other patients, exposing sensitive personal data.ITGaranteGDPR€45,000
20 Mar 2014Liguria Radiologia s.r.lLiguria Radiologia s.r.l was fined by the Garante EUR 16,000 for breaching data protection rules. The company improperly communicated patient data to third parties without adequate consent.ITGaranteGDPR€16,000
09 Jul 2020Burgo Group S.p.A.Burgo Group S.p.A. was fined EUR 20,000 by the Garante for violating GDPR principles. The case concerned improper restriction of access to an employee’s corporate email account, which was accessible to other staff members without the employee’s consent.ITGaranteGDPR€20,000
22 Feb 2018SIDA GROUP SrlSIDA GROUP Srl was fined by the Garante for failing to promptly update its company name and registered office in its data processing notification. The case concerned non-compliance with data protection obligations.ITGaranteGDPR€20,000
25 Jun 2015San Bartolo s.r.l.San Bartolo s.r.l. was fined by the Garante for processing employees’ biometric data without prior notification and without the required preliminary verification. The case concerns a breach of privacy rules governing special-category data.ITGaranteGDPR€24,000
19 Feb 2015HHHH was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice for its video surveillance system. The authority found a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
20 Feb 2014Magazzini Gabrielli s.p.a.Magazzini Gabrielli s.p.a. was fined by the Garante 2,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
17 Oct 2024Giancarlo FranciniThe Garante imposed a EUR 6,500 fine on Giancarlo Francini for breaches related to the processing of health data. The authority found failures to meet transparency obligations and noted that data subject requests were answered only after a complaint was filed.ITGaranteGDPR€6,500
29 Jan 2026Ministero della CulturaMinistero della Cultura was fined EUR 12,000 by the Garante for using surveillance footage for disciplinary purposes without ensuring proper transparency toward visitors and employees. The authority found breaches of the GDPR and national data protection rules.ITGaranteGDPR€12,000
19 Oct 2017A.N.S.A. s.r.l.A.N.S.A. s.r.l. was fined for processing personal health data without notifying the Garante. The authority found a breach of Articles 37 and 38 of the Italian Privacy Code.ITGaranteGDPR€20,000
20 Nov 2008Banca di Roma S.p.A.Banca di Roma S.p.A. was fined EUR 30,000 by the Garante for unauthorized access to the Bank of Italy's risk center. The authority also found that the company failed to provide adequate information to data subjects, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€30,000
11 Jul 2018CAA Liberi professionisti s.r.l.CAA Liberi professionisti s.r.l. was fined by the Garante in the amount of 12,400 EUR for failing to properly designate and instruct personnel involved in data processing. The authority found this to be a breach of data protection rules.ITGaranteGDPR€12,400