Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Apr 2013Stifter Josef KG.Stifter Josef KG. was fined by the Garante for failing to provide the required data protection notice to customers when collecting personal data during e-commerce transactions. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
18 Nov 2015Comune di RecaleComune di Recale was fined EUR 4,000 by the Garante for publishing an individual's personal data on its institutional website without proper legal basis. The case concerned violations of privacy and personal data processing rules.ITGaranteGDPR€4,000
12 Dec 2024Azienda Sanitaria dell’Alto AdigeThe Garante imposed a fine on Azienda Sanitaria dell’Alto Adige for breaches of data protection rules. The case involved inadequate data handling and insufficient security measures.ITGaranteGDPR€5,000
20 Mar 2014Franco Oro più srlFranco Oro più srl was fined EUR 4,800 by the Italian Garante. The case concerned the failure to provide the required data protection information on both a paper form and the company website, in breach of the Italian Data Protection Code.ITGaranteGDPR€4,800
10 Nov 2016Marketing & Comunicazione s.r.l.Marketing & Comunicazione s.r.l. was fined by the Garante for making an unsolicited promotional call to a number listed in the public opposition registry. The conduct breached data protection rules.ITGaranteGDPR€10,000
13 Jan 2022Medicina & Lavoro s.r.l.Medicina & Lavoro s.r.l. was fined by the Garante 4,000 EUR for failing to provide an adequate response to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15.ITGaranteGDPR€4,000
10 Nov 2016Comune di Sant'AgnelloComune di Sant'Agnello was fined EUR 4,000 by the Garante. The authority found that personal data of children had been published on the municipality's website, in breach of privacy rules.ITGaranteGDPR€4,000
15 Apr 2021INPSThe Italian Data Protection Authority fined INPS €12,000 for failing to provide a data subject with access to their personal data and for unlawfully communicating personal data to third parties. The authority found breaches of lawfulness, fairness, and transparency.ITGaranteGDPR€12,000
12 Nov 2014Ruggiero FerdinandoRuggiero Ferdinando was fined EUR 10,000 by the Garante. The sanction concerned failing to provide a complete response to a request for information during a privacy investigation.ITGaranteGDPR€10,000
15 Feb 2018Nazzareno SalernoNazzareno Salerno was fined for unlawful processing of personal data by sending electoral propaganda emails without proper consent. This breached Garante rules on data handling by political parties.ITGaranteGDPR€12,000
27 Jan 2016Punto Fermo s.r.l.Punto Fermo s.r.l. was fined by the Garante EUR 12,000 for retaining surveillance footage for 25 days. This exceeded the one-week limit set by the general rules on video surveillance.ITGaranteGDPR€12,000
06 Jul 2016M2G Solution s.r.l.M2G Solution s.r.l. was fined 4,000 EUR by the Garante for making promotional calls to a number listed in the public opposition register. The authority found this to be a breach of the right to object to direct marketing.ITGaranteGDPR€4,000
20 Oct 2022Fondazione Teatro Regio di TorinoFondazione Teatro Regio di Torino was fined EUR 5,000 by the Garante for publishing an individual's personal data on its website. The authority found a breach of the GDPR principles of lawful, fair, and transparent processing.ITGaranteGDPR€5,000
18 Jan 2018C.S. GROUP S.p.a.C.S. GROUP S.p.a. was fined by the Italian Garante in the amount of €60,000. The case concerned profiling and the processing of personal data without a proper legal basis in connection with vehicle rental services.ITGaranteGDPR€60,000
31 Jan 2019Istituto Comprensivo Paolo StefanelliIstituto Comprensivo Paolo Stefanelli was fined by the Garante 4,000 EUR for publishing personal data on its website that revealed individuals' health status. The case involved a breach of privacy rules and the protection of sensitive data.ITGaranteGDPR€4,000
13 Mar 2025G@S Telecomunicazioni di Losito LuciaG@S Telecomunicazioni di Losito Lucia was fined EUR 15,000 by the Garante. The case concerned the unauthorized activation of a fixed-line telephone offer, which breached data protection rules.ITGaranteGDPR€15,000
14 Mar 2013Sfera s.r.l.Sfera s.r.l. was fined by the Garante 2,400 EUR for collecting personal data through a website form without providing the required privacy notice. The conduct breached the Italian Data Protection Code.ITGaranteGDPR€2,400
17 Dec 2015Orange s.r.l.Orange s.r.l. was fined by the Garante in the amount of 8,800 EUR for processing personal data without the required information and consent. The authority also found that the company used a video surveillance system without providing adequate simplified information.ITGaranteGDPR€8,800
23 Apr 2015Compagnia dei Telefoni s.r.l.Compagnia dei Telefoni s.r.l. was fined by the Garante 80,000 EUR for conducting telemarketing through automated calls without prior informed consent. The company also made promotional calls while concealing the caller's identity.ITGaranteGDPR€80,000
26 Jul 2017Equilibra s.r.l.Equilibra s.r.l. was fined by the Garante for failing to provide adequate data protection information to individuals and for not appointing the required data processing officers. The case concerned breaches of the Italian Data Protection Code.ITGaranteGDPR€12,400