Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Apr 2014Travelplan Italia s.r.l.Travelplan Italia s.r.l. was fined EUR 16,000 by the Garante for sending unsolicited promotional faxes. The authority found that the company failed to provide the required information notice and did not obtain consent, in breach of the Italian Data Protection Code.ITGaranteGDPR€16,000
28 May 2026Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna TorrigianiThe Italian Data Protection Authority imposed a 700 EUR fine on Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna Torrigiani. The case concerned a data protection breach during a patient's hospitalization in the orthopedics department, including improper handling of information about HIV status.ITGaranteGDPR€700
12 Mar 2026Artemide S.r.l.s.Artemide S.r.l.s., the owner of MeridioNews.it, was fined 10,000 EUR by the Garante. The authority found that the company failed to properly handle a request to delete and de-index articles concerning judicial matters, thereby infringing data protection rights.ITGaranteGDPR€10,000
27 Apr 2023Ama S.p.a.Ama S.p.a. was fined €239,000 by the Garante for the unlawful processing and dissemination of personal health data concerning women who had terminated pregnancies. The identities were displayed on crosses at a cemetery, resulting in an unlawful disclosure of sensitive data.ITGaranteGDPR€239,000
27 Oct 2016Porto di Imperia s.p.a.Porto di Imperia s.p.a. was fined by the Italian Garante in the amount of €2,400. The authority found a data protection breach linked to the use of a video surveillance system because individuals entering the port were not provided with simplified information.ITGaranteGDPR€2,400
02 Dec 2021Società Med Store Saronno s.r.l.The Garante fined Società Med Store Saronno s.r.l. EUR 7,000 for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting personal health data.ITGaranteGDPR€7,000
15 Jun 2017F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante 16,000 EUR for making unsolicited promotional calls. The authority found that the required privacy notice was not provided and consent was not obtained, in breach of data protection rules.ITGaranteGDPR€16,000
26 Mar 2020Cavauto s.r.l.Cavauto s.r.l. was fined by the Garante EUR 10,000 for violating GDPR principles on data processing. The case involved improper handling of employee data and failures to ensure proper access and deletion rights.ITGaranteGDPR€10,000
17 May 2023M.S.M. Immobiliare s.r.l.M.S.M. Immobiliare s.r.l. was fined €1,000 by the Garante for a video surveillance system that captured areas beyond its property. The authority also found that proper informational signage was missing, in breach of data protection rules.ITGaranteGDPR€1,000
11 Apr 2013Errebian S.p.aErrebian S.p.a was fined EUR 6,000 by the Italian Garante. The case concerned the failure to provide the required data protection notice on website forms, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
17 Jan 2008Proemotion s.r.l.Proemotion s.r.l. was fined EUR 3,000 by the Italian data protection authority, Garante. The case concerned promotional activities for travel, vacations, weddings, and meetings, where personal data were collected through website forms without adequate prior information.ITGaranteGDPR€3,000
12 Feb 2026Comune di CoccaglioComune di Coccaglio was fined EUR 6,000 for using surveillance footage for disciplinary purposes without informing employees. The authority also found that no data protection impact assessment had been carried out, in breach of data protection rules.ITGaranteGDPR€6,000
25 Nov 2015Massimo GeraciMassimo Geraci was fined by the Garante for failing to provide adequate simplified information about the use of a video surveillance system. The authority found a breach of data protection requirements.ITGaranteGDPR€2,400
04 Dec 2014R. Nautica s.r.l.R. Nautica s.r.l. was fined by the Garante 2,400 EUR for failing to provide the required privacy notice to individuals whose personal data was collected through a web form. The conduct breached Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
04 Apr 2013Discotape di Filippin Angelo & C. sncDiscotape di Filippin Angelo & C. snc was fined EUR 12,000 by the Garante. The case concerned registering numerous phone cards to an individual without their knowledge and failing to provide the required information notice.ITGaranteGDPR€12,000
26 Jan 2017Comune di Roma CapitaleComune di Roma Capitale was fined EUR 10,000 by the Garante for unlawfully publishing personal data of disabled individuals on its website. The case concerned a breach of data protection rules and required removal of the disclosed information.ITGaranteGDPR€10,000
30 Oct 2014Xiao Bin JiangXiao Bin Jiang was fined EUR 2,400 by the Garante. The violation concerned the failure to provide data subjects with the required information about the processing of personal data through a video surveillance system at a commercial establishment.ITGaranteGDPR€2,400
20 Jun 2024Provvedimento del 20 giugno 2024 [10037411]The Garante imposed a fine on a healthcare entity for delays in providing preoperative photographs. The delay affected the complainant's legal position in ongoing proceedings.ITGaranteGDPR€4,000
21 Feb 2013Stefano Giovanni MaulluStefano Giovanni Maullu was fined by the Garante in the amount of 16,000 EUR for sending unsolicited political SMS messages. The authority also found that the required data protection information was not provided.ITGaranteGDPR€16,000
14 Jan 2021Poliambulatorio Talenti S.r.l.Poliambulatorio Talenti S.r.l. was fined €2,000 by the Italian supervisory authority, Garante. The case concerned the improper handling of a data access request, which constitutes a breach of GDPR Article 5.ITGaranteGDPR€2,000