Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Apr 2022Azienda ospedaliera di PerugiaAzienda ospedaliera di Perugia was fined by the Garante EUR 40,000 for breaches related to the protection of whistleblower identities. The authority found that adequate personal data protection measures were not in place.ITGaranteGDPR€40,000
12 Oct 2016Condominio via Michelangelo da CaravaggioThe condominium was fined €4,800 by the Garante. The authority found that the surveillance system notices did not identify the data controller, which breached data protection rules.ITGaranteGDPR€4,800
12 Feb 2026Provvedimento del 12 febbraio 2026 [10225110]The Garante imposed a EUR 1,000 fine for using a video surveillance system without providing the required information notice to data subjects. The case concerned a breach of GDPR transparency obligations.ITGaranteGDPR€1,000
13 Nov 2024FederprivacyFederprivacy was fined EUR 6,000 by the Garante after a data breach caused by a cyberattack. The attack compromised the website, email accounts, and social media, indicating inadequate technical and organizational measures.ITGaranteGDPR€6,000
10 Jun 2011Azienda mobilità trasporti di Bari s.p.a.Azienda mobilità trasporti di Bari s.p.a. was fined by the Garante for processing employees' biometric data without proper notice, consent, or adequate information. The authority found violations of several provisions of the Italian data protection code.ITGaranteGDPR€34,000
05 Sept 2013Perini GianfrancoPerini Gianfranco was fined EUR 2,400 by the Garante. The authority found that individuals were given inadequate data protection information, in breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
10 Feb 2022Costampress S.p.A.Costampress S.p.A. was fined EUR 10,000 by the Garante for failing to take required steps after employment ended. The company did not delete the former employee’s email account or transfer the phone number, which breached GDPR requirements.ITGaranteGDPR€10,000
18 Jul 2023Tiscali Italia S.p.A.Tiscali Italia S.p.A. was fined EUR 100,000 by the Garante for sending promotional SMS messages to existing customers without their consent. The authority also found inadequate data retention policies and insufficient transparency in the privacy notices.ITGaranteGDPR€100,000
03 Apr 2014Travelplan Italia s.r.l.Travelplan Italia s.r.l. was fined EUR 16,000 by the Garante for sending unsolicited promotional faxes. The authority found that the company failed to provide the required information notice and did not obtain consent, in breach of the Italian Data Protection Code.ITGaranteGDPR€16,000
28 May 2026Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna TorrigianiThe Italian Data Protection Authority imposed a 700 EUR fine on Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna Torrigiani. The case concerned a data protection breach during a patient's hospitalization in the orthopedics department, including improper handling of information about HIV status.ITGaranteGDPR€700
12 Mar 2026Artemide S.r.l.s.Artemide S.r.l.s., the owner of MeridioNews.it, was fined 10,000 EUR by the Garante. The authority found that the company failed to properly handle a request to delete and de-index articles concerning judicial matters, thereby infringing data protection rights.ITGaranteGDPR€10,000
27 Apr 2023Ama S.p.a.Ama S.p.a. was fined €239,000 by the Garante for the unlawful processing and dissemination of personal health data concerning women who had terminated pregnancies. The identities were displayed on crosses at a cemetery, resulting in an unlawful disclosure of sensitive data.ITGaranteGDPR€239,000
27 Oct 2016Porto di Imperia s.p.a.Porto di Imperia s.p.a. was fined by the Italian Garante in the amount of €2,400. The authority found a data protection breach linked to the use of a video surveillance system because individuals entering the port were not provided with simplified information.ITGaranteGDPR€2,400
02 Dec 2021Società Med Store Saronno s.r.l.The Garante fined Società Med Store Saronno s.r.l. EUR 7,000 for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting personal health data.ITGaranteGDPR€7,000
15 Jun 2017F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante 16,000 EUR for making unsolicited promotional calls. The authority found that the required privacy notice was not provided and consent was not obtained, in breach of data protection rules.ITGaranteGDPR€16,000
26 Mar 2020Cavauto s.r.l.Cavauto s.r.l. was fined by the Garante EUR 10,000 for violating GDPR principles on data processing. The case involved improper handling of employee data and failures to ensure proper access and deletion rights.ITGaranteGDPR€10,000
17 May 2023M.S.M. Immobiliare s.r.l.M.S.M. Immobiliare s.r.l. was fined €1,000 by the Garante for a video surveillance system that captured areas beyond its property. The authority also found that proper informational signage was missing, in breach of data protection rules.ITGaranteGDPR€1,000
11 Apr 2013Errebian S.p.aErrebian S.p.a was fined EUR 6,000 by the Italian Garante. The case concerned the failure to provide the required data protection notice on website forms, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
17 Jan 2008Proemotion s.r.l.Proemotion s.r.l. was fined EUR 3,000 by the Italian data protection authority, Garante. The case concerned promotional activities for travel, vacations, weddings, and meetings, where personal data were collected through website forms without adequate prior information.ITGaranteGDPR€3,000
12 Feb 2026Comune di CoccaglioComune di Coccaglio was fined EUR 6,000 for using surveillance footage for disciplinary purposes without informing employees. The authority also found that no data protection impact assessment had been carried out, in breach of data protection rules.ITGaranteGDPR€6,000