Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Feb 2013Forum Media Edizioni s.r.l.Forum Media Edizioni s.r.l. was fined by the Italian Garante in the amount of €6,400. The case concerned the sending of unsolicited promotional faxes without the required information and without obtaining consent, in breach of Articles 13 and 130 of the Italian Data Protection Code.ITGaranteGDPR€6,400
24 Jun 2021Comune di FiscianoComune di Fisciano was fined EUR 1,000 by the Garante for improper handling of personal data. The data were removed after the complaint, and the case concerned transparency and data protection obligations.ITGaranteGDPR€1,000
28 Oct 2021Società LARCSocietà LARC was fined EUR 8,000 by the Garante for violations related to the processing of health data. The authority found non-compliance with GDPR requirements in the handling of these data.ITGaranteGDPR€8,000
18 Dec 2025Elba Catering Distribuzioni s.r.l.s.Elba Catering Distribuzioni s.r.l.s. was fined EUR 2,000 by the Garante for installing a video surveillance system that primarily captured public streets. The authority found that this processing breached data protection rules.ITGaranteGDPR€2,000
24 Nov 2011Gema s.p.a.Gema s.p.a. was fined by the Italian data protection authority, Garante, for failing to provide the required data protection information to users and entities through its website. The authority also found that the company used a video surveillance system without proper notification, in breach of the Italian Data Protection Code.ITGaranteGDPR€22,000
16 Dec 2009BonassisaLab s.r.l.BonassisaLab s.r.l. was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code.ITGaranteGDPR€10,000
11 Sept 2014Villa dei Cedri s.p.a.Villa dei Cedri s.p.a. was fined by the Garante 2,400 EUR for failing to provide simplified information on the use of video surveillance systems. The authority found this to be a breach of privacy rules.ITGaranteGDPR€2,400
18 Jun 2015Wind Telecomunicazioni SpaWind Telecomunicazioni Spa was fined EUR 130,000 by the Garante. The case concerned the unlawful disclosure of mobile phone numbers in the White Pages directory without proper consent.ITGaranteGDPR€130,000
21 Jan 2010Servizi sanitari s.r.l. – Istituto cardiovascolare CamogliServizi sanitari s.r.l. was fined by the Garante 10,000 EUR for violations related to the processing of personal data without the required notification. The case concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
29 Jan 2026dott. Paolo MontemurroDott. Paolo Montemurro was fined 5,000 EUR by the Garante for posting photographs of a patient's surgical procedure on Instagram without consent. The authority found this breached GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€5,000
21 Sept 2017Tra.n.sider S.p.A.Tra.n.sider S.p.A. was fined EUR 20,000 by the Italian Garante. The case concerned the failure to notify the installation of a geolocation system on company vehicles, breaching data protection notification requirements.ITGaranteGDPR€20,000
12 Nov 2015A.S.D. Associazione di promozione culturale e sociale Social ClubA.S.D. Associazione di promozione culturale e sociale Social Club was fined EUR 2,400 by the Garante for publishing an inadequate privacy notice on its website. The authority found this to be a breach of Article 161 of the Italian Data Protection Code.ITGaranteGDPR€2,400
28 Nov 2013Axa società cooperativa a responsabilità limitataAxa società cooperativa a responsabilità limitata was fined by the Garante 46,000 EUR for using biometric systems to monitor employee attendance and working hours. The authority found that the processing took place without proper consent and required notifications, in breach of data protection rules.ITGaranteGDPR€46,000
10 Apr 2025Ente di Patrocinio ed Assistenza per i Cittadini e l’Agricoltura (EPACA)EPACA was fined EUR 5,000 by the Italian Garante. The authority found that the organization retained personal data beyond the legally permitted period and accessed the INPS database without a valid mandate.ITGaranteGDPR€5,000
16 Dec 2009Campolongo Hospital s.p.a.Campolongo Hospital s.p.a. was fined by the Garante in the amount of 20,000 EUR. The case concerned the processing of personal data without the required notification under the Italian Data Protection Code.ITGaranteGDPR€20,000
02 Dec 2021Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.The Garante imposed a EUR 30,000 fine on Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting patient health data.ITGaranteGDPR€30,000
08 Jul 2021Azienda ospedaliero-universitaria SeneseAzienda ospedaliero-universitaria Senese was fined by the Garante 25,000 EUR for violations related to data breaches involving health data and patient information. The case concerned the handling of sensitive data and required assessment of compliance with data protection obligations.ITGaranteGDPR€25,000
12 Sept 2013Cheng LiangxiaoCheng Liangxiao was fined by the Italian Garante for failing to provide the required privacy notice for a surveillance camera at his commercial premises. The breach concerned the absence of information on personal data processing for individuals captured by the camera.ITGaranteGDPR€2,400
08 May 2014Domenico Ciano AlbaneseDomenico Ciano Albanese was fined 4,800 EUR by the Garante for collecting personal data without providing adequate information to the data subjects. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€4,800
12 May 2016Leonardo SestaLeonardo Sesta, a lawyer, was fined by the Italian data protection authority, Garante. The violation concerned transmitting personal data by email instead of registered mail, contrary to data protection rules.ITGaranteGDPR€4,000