Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Oct 2022Associazione Rescue Drones Network ODVAssociazione Rescue Drones Network ODV was fined by the Garante in the amount of 3,000 EUR for failing to comply with data access requests. The authority treated this as a breach of GDPR Article 5.ITGaranteGDPR€3,000
10 Jan 2013Consodata S.p.A.Consodata S.p.A. was fined by the Garante 400,000 EUR for violations linked to unsolicited telemarketing. The authority also found that the company failed to provide individuals with proper data protection information.ITGaranteGDPR€400,000
11 Apr 2024Innova Camera – Azienda speciale della Camera di commercio, industria, artigianato e agricoltura di RomaInnova Camera was fined by the Garante EUR 25,000 for inadequate data security measures. The breach resulted in personal data being accessed and published online following an SQL Injection attack.ITGaranteGDPR€25,000
06 Apr 2017Siportal s.r.l.Siportal s.r.l. was fined by the Garante for retaining telephone and internet traffic data longer than permitted by law. The authority found this to be a breach of data protection rules.ITGaranteGDPR€30,000
21 Dec 2023Azienda socio-sanitaria localeThe Garante imposed a fine on a local health authority for violations related to the handling of sensitive personal data. The case concerned improper processing of special-category data, which breached data protection rules.ITGaranteGDPR€18,000
16 May 2018Ordinanza ingiunzione - 16 maggio 2018 [9023208]A general practitioner was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This failure allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
24 Nov 2022Società Lombarda Sport s.r.l.Società Lombarda Sport s.r.l. was fined by the Garante 4,000 EUR for processing personal data without an adequate legal basis. The authority also found failures to ensure data integrity and confidentiality in connection with the issuance of medical certificates for non-competitive sports activities.ITGaranteGDPR€4,000
24 Mar 2022Uber B.V. e Uber Technologies Inc.Uber B.V. and Uber Technologies Inc. were fined by the Italian authority Garante EUR 2,120,000 for a data protection breach linked to the 2016 incident. The breach affected the personal data of about 57 million users worldwide, including users in Italy.ITGaranteGDPR€2,120,000
07 Apr 2022Comune di OrteComune di Orte was fined for improper handling of personal data collected through video surveillance. The authority found a lack of transparency and insufficient data protection measures.ITGaranteGDPR€5,000
12 Feb 2026Comune di Mazara del ValloComune di Mazara del Vallo was fined EUR 4,000 by the Garante for breaches of data protection principles. The authority found that the municipality failed to provide adequate information to data subjects and did not carry out a data protection impact assessment for its video surveillance system.ITGaranteGDPR€4,000
26 Feb 2026Conservatorio “XX” di XXThe Garante fined Conservatorio “XX” di XX EUR 5,000 for processing personal data relating to criminal convictions without a valid legal basis. The authority found breaches of the GDPR and the national privacy code.ITGaranteGDPR€5,000
11 Jun 2015Banca Nazionale del Lavoro S.p.a.Banca Nazionale del Lavoro S.p.a. was fined by the Garante 32,000 EUR for processing personal data without first informing the data subjects and without obtaining their consent. The case concerns a breach of core notice and consent obligations in personal data processing.ITGaranteGDPR€32,000
23 Jul 2015Bike Service s.n.c.Bike Service s.n.c. was fined by the Garante 2,400 EUR for failing to inform data subjects about the processing of personal data through a video surveillance system. The breach concerned the absence of required notices for individuals subject to the monitoring.ITGaranteGDPR€2,400
16 Jan 2026Provvedimento del 16 gennaio 2026 [10213836]The Garante imposed a fine of EUR 500 on an anonymized data controller for a minor breach of data protection rules in the health sector. The authority also ordered publication of the decision on its website.ITGaranteGDPR€500
12 Jul 2006Diomede s.r.l.Diomede s.r.l. was fined EUR 258 by the Garante for failing to provide adequate information to data subjects in job advertisements. This constituted a breach of the Italian Privacy Code.ITGaranteGDPR€258
20 Mar 2008Marco TardelliMarco Tardelli was fined by the Garante for failing to provide a complete response to a personal data access request. The authority found a breach of the Italian data protection code.ITGaranteGDPR€4,000
11 Jan 2018N.J.L. & Time di Bernasconi NadiaN.J.L. & Time di Bernasconi Nadia was fined 68,000 EUR by the Garante. The authority found that promotional emails were sent without proper consent, in breach of data protection rules.ITGaranteGDPR€68,000
16 Sept 2021La Prima S.r.l.La Prima S.r.l. was fined by the Garante for carrying out promotional activities without a valid legal basis. The authority found that this conduct breached GDPR requirements.ITGaranteGDPR€5,000
13 Sept 2012Ruzzo Reti S.p.a.Ruzzo Reti S.p.a. was fined EUR 4,000 by the Italian Garante. The authority found that the company failed to designate data processors, meaning it did not adopt the minimum security measures required by the Italian Privacy Code.ITGaranteGDPR€4,000
12 Apr 2018Tonino CeciliaTonino Cecilia, owner of Telefonia Trigoria, was fined by the Italian authority Garante. The penalty concerned activating phone cards for two individuals without their consent, which breached data protection rules.ITGaranteGDPR€20,000