Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Nov 2013Ma.CI.E. s.a.s di Favaro Stefano & C.Ma.CI.E. s.a.s was fined EUR 2,400 by the Garante for failing to provide the simplified information required under data protection rules. The breach concerned the use of a video surveillance system at the company’s premises.ITGaranteGDPR€2,400
04 Dec 2025Istituto Comprensivo Centro di Casalecchio di RenoThe Garante fined Istituto Comprensivo Centro di Casalecchio di Reno EUR 2,000 for publishing personal data online without a proper legal basis. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€2,000
28 Sept 2023Ministero dell'Ambiente e della Sicurezza EnergeticaThe Ministry of Environment and Energy Security was fined EUR 5,000 by the Garante for the online publication of personal data relating to numerous workers. The disclosure also included health-related data for some individuals.ITGaranteGDPR€5,000
13 Mar 2025Encore Thermoengineering s.r.l.Encore Thermoengineering s.r.l. was fined EUR 20,000 by the Garante. The case concerned an inadequate response to former employees’ requests about the status and deletion of their email accounts, which infringed data protection rights.ITGaranteGDPR€20,000
13 Apr 2023SWG S.p.A.SWG S.p.A. was fined EUR 15,000 by the Garante for blocking an employee’s access to email and phone before the agreed termination date. This prevented access to personal data, including sensitive data.ITGaranteGDPR€15,000
02 Jul 2020Istituto Nazionale della Previdenza Sociale-Direzione Provinciale di BresciaThe Italian Data Protection Authority fined the INPS Brescia Provincial Directorate for failing to respond to a request for access to personal health data. The authority found a breach of data protection rules.ITGaranteGDPR€5,000
06 Jul 2006Filippi Giovanni & C. s.n.c.Filippi Giovanni & C. s.n.c. was fined 1,549 EUR by the Garante. The authority found that personal data were processed to send commercial messages without proper disclosure required under data protection law.ITGaranteGDPR€1,549
28 May 2015El Dom S.a.s.El Dom S.a.s. was fined EUR 174,000 by the Garante for activating 185 phone cards under the names of 58 individuals without their knowledge. The case involved a breach of data protection rules and the unauthorized use of personal identification data.ITGaranteGDPR€174,000
27 Jan 2021Azienda Ospedaliero Universitaria di ParmaAzienda Ospedaliero Universitaria di Parma was fined by the Garante for violations related to the handling of health data. The violations resulted in a data breach, which led to the 10,000 EUR penalty.ITGaranteGDPR€10,000
22 Jan 2015Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined EUR 4,000 by the Garante. The authority found that personal data had been unlawfully published on its website for longer than the legally permitted fifteen days.ITGaranteGDPR€4,000
21 Apr 2016Romana Supernegozi s.r.l.Romana Supernegozi s.r.l. was fined by the Garante 2,400 EUR for failing to provide adequate simplified information about its video surveillance system. The case concerned breaches of data protection information duties.ITGaranteGDPR€2,400
16 Mar 2017Welcome s.a.s. di Somma MicheleWelcome s.a.s. di Somma Michele was fined EUR 16,000 by the Garante for making unsolicited promotional calls. The authority found that the required privacy notice was not provided and consent was not obtained.ITGaranteGDPR€16,000
04 Dec 2014Hotel Stamira s.r.l.Hotel Stamira s.r.l. was fined by the Garante for processing personal data related to job applications without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
25 Mar 2021OneDirect S.r.l.OneDirect S.r.l. was fined EUR 30,000 by the Garante. The authority found that the company sent unsolicited promotional emails despite objections and failed to respond to data subject requests.ITGaranteGDPR€30,000
10 Jun 2021dott. MariniThe Garante imposed a EUR 20,000 fine on dott. Marini for unlawfully collecting information about patients' HIV status. The authority found a breach of the principles of necessity and proportionality in personal data processing.ITGaranteGDPR€20,000
26 Mar 2026Copacabana s.r.l.Copacabana s.r.l. was fined EUR 2,000 by the Garante for installing a video surveillance system without the required informational signage and necessary authorization. The authority cited a breach of GDPR Article 13.ITGaranteGDPR€2,000
22 Jan 2015Iama Consulting s.r.l.Iama Consulting s.r.l. was fined by the Garante for collecting email addresses through a website form without providing the required privacy notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
22 Oct 2015Bagni Miramare srlBagni Miramare srl was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned collecting email addresses through its website without providing the required privacy notice, in breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
13 Jul 2016Italian Lab s.r.l.Italian Lab s.r.l. was fined EUR 4,000 by the Garante. The case concerned the processing of personal data for a mailing list and newsletter without obtaining user consent.ITGaranteGDPR€4,000
17 May 2023Fabio Giovanni PettaFabio Giovanni Petta was fined by the Garante 60,000 EUR for the unauthorized publication of personal data, including names, addresses, and phone numbers, on www.trovanumeri.com. The authority also noted continued processing of the data despite a prior prohibition. The case constitutes a GDPR violation.ITGaranteGDPR€60,000