Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Jan 2019Istituto Comprensivo Paolo StefanelliIstituto Comprensivo Paolo Stefanelli was fined by the Garante 4,000 EUR for publishing personal data on its website that revealed individuals' health status. The case involved a breach of privacy rules and the protection of sensitive data.ITGaranteGDPR€4,000
13 Mar 2025G@S Telecomunicazioni di Losito LuciaG@S Telecomunicazioni di Losito Lucia was fined EUR 15,000 by the Garante. The case concerned the unauthorized activation of a fixed-line telephone offer, which breached data protection rules.ITGaranteGDPR€15,000
14 Mar 2013Sfera s.r.l.Sfera s.r.l. was fined by the Garante 2,400 EUR for collecting personal data through a website form without providing the required privacy notice. The conduct breached the Italian Data Protection Code.ITGaranteGDPR€2,400
17 Dec 2015Orange s.r.l.Orange s.r.l. was fined by the Garante in the amount of 8,800 EUR for processing personal data without the required information and consent. The authority also found that the company used a video surveillance system without providing adequate simplified information.ITGaranteGDPR€8,800
23 Apr 2015Compagnia dei Telefoni s.r.l.Compagnia dei Telefoni s.r.l. was fined by the Garante 80,000 EUR for conducting telemarketing through automated calls without prior informed consent. The company also made promotional calls while concealing the caller's identity.ITGaranteGDPR€80,000
26 Jul 2017Equilibra s.r.l.Equilibra s.r.l. was fined by the Garante for failing to provide adequate data protection information to individuals and for not appointing the required data processing officers. The case concerned breaches of the Italian Data Protection Code.ITGaranteGDPR€12,400
04 May 2017McDonald’s Development ItalyMcDonald’s Development Italy was fined EUR 15,000 by the Garante. The authority found that the company retained surveillance footage longer than permitted under the video surveillance guidelines.ITGaranteGDPR€15,000
24 Nov 2016Unione Comunale del Chianti fiorentinoUnione Comunale del Chianti fiorentino was fined by the Garante 10,000 EUR for publishing on its website the personal data of individuals who were not admitted to a financial benefit. The conduct breached data protection rules.ITGaranteGDPR€10,000
18 Dec 2025Comune di NaveComune di Nave was fined by the Garante for failing to ensure transparency in the processing of vehicle license plate data captured by surveillance cameras. The authority also found a breach of GDPR principles and the absence of a data protection impact assessment.ITGaranteGDPR€6,000
14 Sept 2006Asl FerraraAsl Ferrara was fined by the Garante for processing genetic, health, and sexual life data without the required notification. The authority found a breach of the Italian Privacy Code.ITGaranteGDPR€10,000
24 Jan 2013Saverio ProcopioSaverio Procopio was fined €16,800 by the Garante for sending unsolicited promotional emails without obtaining explicit consent from recipients. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code.ITGaranteGDPR€16,800
26 Feb 2026Radio Immagine Uno S.r.l.The Garante imposed a €10,000 fine on Radio Immagine Uno S.r.l. for failing to respond to a data subject's request to remove an online article containing personal data. The company did not comply with the right to be forgotten, resulting in a data protection breach.ITGaranteGDPR€10,000
10 Sept 2015Aurelia ZanniAurelia Zanni was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice. The case concerned its “compro oro” business and non-compliance with the Italian Data Protection Code and the 2010 video surveillance guidelines.ITGaranteGDPR€2,400
05 Oct 2017Start S.p.A.Start S.p.A. was fined by the Garante 40,000 EUR for operating a geolocation system on its buses without full compliance with data protection rules. The case concerned location data processing without the required legal basis and safeguards.ITGaranteGDPR€40,000
01 Dec 2016Adda Gestioni Industriali e Mobiliari s.p.a.Adda Gestioni Industriali e Mobiliari S.p.a. was fined by the Garante 2,400 EUR for improper data processing through a video surveillance system. The authority found that adequate notices were not provided for external cameras monitoring the parking area.ITGaranteGDPR€2,400
10 Jul 2014Comune di OrbetelloThe Municipality of Orbetello was fined EUR 10,000 by the Italian data protection authority, Garante. The sanction concerned the publication of individuals’ personal health data on the municipality’s official website, in breach of privacy rules.ITGaranteGDPR€10,000
15 Feb 2018AUTONOLEGGI 24 S.a.s. DI GIAQUINTO GIOVANNIAUTONOLEGGI 24 S.a.s. was fined by the Garante for processing personal data through a geolocation system without the required notification. The case concerned breaches of notification and supervisory obligations linked to that processing.ITGaranteGDPR€20,000
08 Jul 2021Consiglio Regionale della Valle d’AostaConsiglio Regionale della Valle d’Aosta was fined EUR 1,000 by the Garante for failing to remove personal data from its website after a request. The authority found this to be a breach of data protection rights.ITGaranteGDPR€1,000
21 Dec 2023Gestioni Aziendali s.r.l.Gestioni Aziendali s.r.l. was fined by the Garante in the amount of 5,000 EUR for operating a video surveillance system at Hotel della Vittoria without appropriate informational signage. The authority found this to be a breach of GDPR transparency requirements toward monitored individuals.ITGaranteGDPR€5,000
12 Apr 2018Insurances Global Services S.r.l.Insurances Global Services S.r.l. was fined by the Garante EUR 20,000 for violations involving access to and handling of client data from credit risk databases without proper authorization. The case concerned the unauthorized use of personal data in the context of credit risk assessment.ITGaranteGDPR€20,000