Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Apr 2014Armando ChessaArmando Chessa was fined by the Garante for failing to provide adequate information about the use of a video surveillance system. The authority found a breach of data protection rules.ITGaranteGDPR€2,400
14 Dec 2017Telenando di Sannino Caterina e C s.a.s.Telenando di Sannino Caterina e C s.a.s. was fined by the Garante EUR 30,000 for registering phone cards to unaware third parties without their consent. The case concerned a breach of data protection rules.ITGaranteGDPR€30,000
11 Feb 2021Istituti ospedalieri bergamaschiThe Garante fined Istituti ospedalieri bergamaschi EUR 45,000 for a data protection breach. Online medical reports were accessible to other patients, exposing sensitive personal data.ITGaranteGDPR€45,000
20 Mar 2014Liguria Radiologia s.r.lLiguria Radiologia s.r.l was fined by the Garante EUR 16,000 for breaching data protection rules. The company improperly communicated patient data to third parties without adequate consent.ITGaranteGDPR€16,000
09 Jul 2020Burgo Group S.p.A.Burgo Group S.p.A. was fined EUR 20,000 by the Garante for violating GDPR principles. The case concerned improper restriction of access to an employee’s corporate email account, which was accessible to other staff members without the employee’s consent.ITGaranteGDPR€20,000
22 Feb 2018SIDA GROUP SrlSIDA GROUP Srl was fined by the Garante for failing to promptly update its company name and registered office in its data processing notification. The case concerned non-compliance with data protection obligations.ITGaranteGDPR€20,000
25 Jun 2015San Bartolo s.r.l.San Bartolo s.r.l. was fined by the Garante for processing employees’ biometric data without prior notification and without the required preliminary verification. The case concerns a breach of privacy rules governing special-category data.ITGaranteGDPR€24,000
19 Feb 2015HHHH was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice for its video surveillance system. The authority found a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
20 Feb 2014Magazzini Gabrielli s.p.a.Magazzini Gabrielli s.p.a. was fined by the Garante 2,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
17 Oct 2024Giancarlo FranciniThe Garante imposed a EUR 6,500 fine on Giancarlo Francini for breaches related to the processing of health data. The authority found failures to meet transparency obligations and noted that data subject requests were answered only after a complaint was filed.ITGaranteGDPR€6,500
29 Jan 2026Ministero della CulturaMinistero della Cultura was fined EUR 12,000 by the Garante for using surveillance footage for disciplinary purposes without ensuring proper transparency toward visitors and employees. The authority found breaches of the GDPR and national data protection rules.ITGaranteGDPR€12,000
19 Oct 2017A.N.S.A. s.r.l.A.N.S.A. s.r.l. was fined for processing personal health data without notifying the Garante. The authority found a breach of Articles 37 and 38 of the Italian Privacy Code.ITGaranteGDPR€20,000
20 Nov 2008Banca di Roma S.p.A.Banca di Roma S.p.A. was fined EUR 30,000 by the Garante for unauthorized access to the Bank of Italy's risk center. The authority also found that the company failed to provide adequate information to data subjects, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€30,000
11 Jul 2018CAA Liberi professionisti s.r.l.CAA Liberi professionisti s.r.l. was fined by the Garante in the amount of 12,400 EUR for failing to properly designate and instruct personnel involved in data processing. The authority found this to be a breach of data protection rules.ITGaranteGDPR€12,400
12 Feb 2026Comune di AversaThe Garante fined Comune di Aversa 3,000 EUR for failing to communicate the contact details of the Data Protection Officer. The case concerns Article 37 GDPR and the obligation to make DPO contact information available.ITGaranteGDPR€3,000
23 Mar 2011Nuova Demolizione Sas di Saviotti GaetanoNuova Demolizione Sas was fined by the Garante 6,000 EUR for sending unsolicited promotional faxes without proper consent. The conduct breached data protection and direct marketing rules.ITGaranteGDPR€6,000
22 Jun 2023Futuro Molise S.r.l.Futuro Molise S.r.l. was fined EUR 2,000 by the Garante for publishing an article that contained personal data without demonstrating a public interest basis. The authority found a breach of data protection rules.ITGaranteGDPR€2,000
04 May 2017Easy C@ll s.r.l.Easy C@ll s.r.l. was fined EUR 32,000 by the Garante for making unsolicited promotional calls to individuals listed in the public opt-out register. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€32,000
11 Jan 2024Comune di TrentoThe Garante fined Comune di Trento EUR 50,000 for conducting two research projects using cameras, microphones, and social networks in breach of data protection rules. The case concerns improper processing of personal data in the context of research activities.ITGaranteGDPR€50,000
22 Nov 2012Mediabusiness Int. s.r.l.Mediabusiness Int. s.r.l. was fined EUR 26,000 by the Garante for sending unsolicited promotional faxes. The authority found that the company did not obtain valid consent from recipients, which breached data protection rules.ITGaranteGDPR€26,000