Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Mar 2019Vestas s.r.l.Vestas s.r.l. was fined by the Garante 4,000 EUR for obtaining a single mandatory consent covering different processing purposes. This approach breached data protection rules because consent was not separated by purpose.ITGaranteGDPR€4,000
02 Oct 2014Addressvitt s.r.l.Addressvitt s.r.l. was fined by the Garante in the amount of EUR 130,000 for processing personal data without providing adequate information or obtaining consent. The case also involved data taken from public telephone directories and used without proper authorization.ITGaranteGDPR€130,000
05 Jul 2018Gianolini Servizi e Trasporti s.r.l.Gianolini Servizi e Trasporti s.r.l. was fined €8,000 by the Garante for failing to notify the authority about its use of a vehicle localization system with GPS devices. The conduct was found to breach notification obligations under the Italian Data Protection Code.ITGaranteGDPR€8,000
18 Sept 2014History s.a.s.History s.a.s. was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned failure to provide the required information notice under Article 13 of the Italian Privacy Code when operating a video surveillance system.ITGaranteGDPR€2,400
28 Apr 2022Ekss s.r.l.Ekss s.r.l. was fined by the Garante EUR 2,000 for operating a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR.ITGaranteGDPR€2,000
26 Mar 2026Messina Social CityMessina Social City was fined by the Garante 10,000 EUR for breaching GDPR principles. The case concerned the improper dissemination of personal data, including images of minors, on Facebook without proper legal grounds and contracts.ITGaranteGDPR€10,000
01 Jun 2016Ordinanza ingiunzione - 1 giugno 2016 [5423590]A paramedical professional processed clients’ personal data for health purposes without providing the required privacy notice or obtaining consent. The Garante found violations of Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€6,400
13 Jun 2013BBJ s.r.l.BBJ s.r.l. was fined by the Garante EUR 64,000 for running SMS and email marketing campaigns without providing the required information to data subjects and without obtaining their consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€64,000
20 Jul 2017Crea Futuro s.r.l.Crea Futuro s.r.l. was fined by the Garante 64,000 EUR for processing personal data without providing adequate information and obtaining consent. The breach affected about 2 million people, indicating a broad compliance impact.ITGaranteGDPR€64,000
18 May 2016Istituto Robert Kennedy s.r.l.Istituto Robert Kennedy s.r.l. was fined EUR 2,400 by the Italian Garante for providing clients with inadequate information about data processing. The authority found a breach of the information duties under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
08 Jul 2021Regione PugliaThe Garante fined Regione Puglia EUR 30,000 for the unlawful dissemination of personal health data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€30,000
03 Sept 2020Comune di CasaloldoComune di Casaloldo was fined by the Garante for publishing personal data on its institutional website without an appropriate legal basis. The conduct breached the principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€2,000
07 Apr 2022Azienda ospedaliera di PerugiaAzienda ospedaliera di Perugia was fined by the Garante EUR 40,000 for breaches related to the protection of whistleblower identities. The authority found that adequate personal data protection measures were not in place.ITGaranteGDPR€40,000
12 Oct 2016Condominio via Michelangelo da CaravaggioThe condominium was fined €4,800 by the Garante. The authority found that the surveillance system notices did not identify the data controller, which breached data protection rules.ITGaranteGDPR€4,800
12 Feb 2026Provvedimento del 12 febbraio 2026 [10225110]The Garante imposed a EUR 1,000 fine for using a video surveillance system without providing the required information notice to data subjects. The case concerned a breach of GDPR transparency obligations.ITGaranteGDPR€1,000
13 Nov 2024FederprivacyFederprivacy was fined EUR 6,000 by the Garante after a data breach caused by a cyberattack. The attack compromised the website, email accounts, and social media, indicating inadequate technical and organizational measures.ITGaranteGDPR€6,000
10 Jun 2011Azienda mobilità trasporti di Bari s.p.a.Azienda mobilità trasporti di Bari s.p.a. was fined by the Garante for processing employees' biometric data without proper notice, consent, or adequate information. The authority found violations of several provisions of the Italian data protection code.ITGaranteGDPR€34,000
05 Sept 2013Perini GianfrancoPerini Gianfranco was fined EUR 2,400 by the Garante. The authority found that individuals were given inadequate data protection information, in breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
10 Feb 2022Costampress S.p.A.Costampress S.p.A. was fined EUR 10,000 by the Garante for failing to take required steps after employment ended. The company did not delete the former employee’s email account or transfer the phone number, which breached GDPR requirements.ITGaranteGDPR€10,000
18 Jul 2023Tiscali Italia S.p.A.Tiscali Italia S.p.A. was fined EUR 100,000 by the Garante for sending promotional SMS messages to existing customers without their consent. The authority also found inadequate data retention policies and insufficient transparency in the privacy notices.ITGaranteGDPR€100,000