Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
25 Mar 2021OneDirect S.r.l.OneDirect S.r.l. was fined EUR 30,000 by the Garante. The authority found that the company sent unsolicited promotional emails despite objections and failed to respond to data subject requests.ITGaranteGDPR€30,000
10 Jun 2021dott. MariniThe Garante imposed a EUR 20,000 fine on dott. Marini for unlawfully collecting information about patients' HIV status. The authority found a breach of the principles of necessity and proportionality in personal data processing.ITGaranteGDPR€20,000
26 Mar 2026Copacabana s.r.l.Copacabana s.r.l. was fined EUR 2,000 by the Garante for installing a video surveillance system without the required informational signage and necessary authorization. The authority cited a breach of GDPR Article 13.ITGaranteGDPR€2,000
22 Jan 2015Iama Consulting s.r.l.Iama Consulting s.r.l. was fined by the Garante for collecting email addresses through a website form without providing the required privacy notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
22 Oct 2015Bagni Miramare srlBagni Miramare srl was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned collecting email addresses through its website without providing the required privacy notice, in breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
13 Jul 2016Italian Lab s.r.l.Italian Lab s.r.l. was fined EUR 4,000 by the Garante. The case concerned the processing of personal data for a mailing list and newsletter without obtaining user consent.ITGaranteGDPR€4,000
17 May 2023Fabio Giovanni PettaFabio Giovanni Petta was fined by the Garante 60,000 EUR for the unauthorized publication of personal data, including names, addresses, and phone numbers, on www.trovanumeri.com. The authority also noted continued processing of the data despite a prior prohibition. The case constitutes a GDPR violation.ITGaranteGDPR€60,000
06 Jul 2006Pricewaterhouse Cooper Executive Search & SelectionPricewaterhouse Cooper Executive Search & Selection was fined 258 EUR by the Italian Garante. The case concerned inadequate information provided to candidates about the processing of their personal data in job advertisements, in breach of Art. 13 of the Codice Privacy.ITGaranteGDPR€258
29 Jan 2015Comune di BarzagoComune di Barzago was fined for failing to provide the required information notice to individuals whose personal data were processed for sending informational SMS messages. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
09 Nov 2017Consorzio di Polizia locale Valle AgnoConsorzio di Polizia locale Valle Agno was fined EUR 10,400 by the Garante for deploying a mobile video surveillance system and a localization system on employee devices without the required information or prior notification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€10,400
20 Dec 2024OpenAIThe Italian data protection authority fined OpenAI EUR 15 million for GDPR noncompliance related to ChatGPT. The 20 December 2024 decision cites issues with the legal basis for training data processing, transparency obligations, age verification, breach notification, and the security and accuracy of outputs.ITGarante per la protezione dei dati personaliGDPR€15,000,000
01 Jun 2016Midica s.r.l.Midica s.r.l. was fined by the Garante for making promotional calls without the consent of the individuals concerned. The company also failed to respond to information requests from the supervisory authority.ITGaranteGDPR€10,000
26 Jul 2018Primo s.r.l.Primo s.r.l., a dental center, was fined by the Italian Garante in the amount of 10,000 EUR. The authority found inadequate security measures in the processing of patients’ personal data.ITGaranteGDPR€10,000
23 Mar 2023Comune di PulsanoComune di Pulsano was fined by the Garante for unlawfully publishing personal data related to an employee’s disciplinary proceedings on its institutional website. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€3,000
10 Apr 2025Yolo Group S.p.a.Yolo Group S.p.a. was fined by the Garante 30,000 EUR for a data breach involving personal and contact data of a large number of individuals. The authority found a violation of Article 33 of the GDPR, which concerns notification of personal data breaches.ITGaranteGDPR€30,000
26 Apr 2018Falotico Luca CarmeloFalotico Luca Carmelo, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
28 May 2015People & Comunication s.r.l.People & Comunication s.r.l. was fined EUR 20,000 by the Garante. The authority found that the company retained telephone traffic data for more than 24 months, in breach of Article 132 of the Italian Data Protection Code.ITGaranteGDPR€20,000
03 Feb 2011Il Filo s.r.l.Il Filo s.r.l. was fined by the Garante in the amount of €6,000 for processing personal data without providing the required information notice to data subjects. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
11 Jul 2018BUSITALIA VENETO S.p.A.BUSITALIA VENETO S.p.A. was fined by the Garante for unlawful processing of personal data through the installation of a geolocation system on its public transport vehicles. The measure infringed employee privacy and data protection rules.ITGaranteGDPR€10,000
02 Oct 2014San Petronio s.r.l.San Petronio s.r.l. was fined by the Garante for failing to appoint data processing officers and for providing inadequate information about video surveillance. The authority found that these practices breached data protection rules.ITGaranteGDPR€10,000