Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
25 Nov 2015Massimo GeraciMassimo Geraci was fined by the Garante for failing to provide adequate simplified information about the use of a video surveillance system. The authority found a breach of data protection requirements.ITGaranteGDPR€2,400
04 Dec 2014R. Nautica s.r.l.R. Nautica s.r.l. was fined by the Garante 2,400 EUR for failing to provide the required privacy notice to individuals whose personal data was collected through a web form. The conduct breached Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
04 Apr 2013Discotape di Filippin Angelo & C. sncDiscotape di Filippin Angelo & C. snc was fined EUR 12,000 by the Garante. The case concerned registering numerous phone cards to an individual without their knowledge and failing to provide the required information notice.ITGaranteGDPR€12,000
26 Jan 2017Comune di Roma CapitaleComune di Roma Capitale was fined EUR 10,000 by the Garante for unlawfully publishing personal data of disabled individuals on its website. The case concerned a breach of data protection rules and required removal of the disclosed information.ITGaranteGDPR€10,000
30 Oct 2014Xiao Bin JiangXiao Bin Jiang was fined EUR 2,400 by the Garante. The violation concerned the failure to provide data subjects with the required information about the processing of personal data through a video surveillance system at a commercial establishment.ITGaranteGDPR€2,400
20 Jun 2024Provvedimento del 20 giugno 2024 [10037411]The Garante imposed a fine on a healthcare entity for delays in providing preoperative photographs. The delay affected the complainant's legal position in ongoing proceedings.ITGaranteGDPR€4,000
21 Feb 2013Stefano Giovanni MaulluStefano Giovanni Maullu was fined by the Garante in the amount of 16,000 EUR for sending unsolicited political SMS messages. The authority also found that the required data protection information was not provided.ITGaranteGDPR€16,000
14 Jan 2021Poliambulatorio Talenti S.r.l.Poliambulatorio Talenti S.r.l. was fined €2,000 by the Italian supervisory authority, Garante. The case concerned the improper handling of a data access request, which constitutes a breach of GDPR Article 5.ITGaranteGDPR€2,000
02 Feb 2017Euro Comunication System s.r.l.Euro Comunication System s.r.l. was fined EUR 1,260,000 by the Garante. The authority found that funds were transferred without obtaining consent for data processing and that transactions were split to avoid detection, breaching AML rules.ITGaranteGDPR€1,260,000
17 Sept 2020Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The Garante imposed an EUR 80,000 fine on Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli” for a data breach involving sensitive health data. The incident occurred during a platform maintenance period, indicating insufficient safeguards around processing.ITGaranteGDPR€80,000
02 Apr 2015Comune di MontefrancoComune di Montefranco was fined EUR 4,000 by the Garante. The authority found that the role of Mercurio service s.r.l. was not properly regulated, although it processed personal data relating to traffic violations without proper authorization.ITGaranteGDPR€4,000
26 Nov 2020Ministero dell’InternoThe Ministry of the Interior was fined by the Garante for the unauthorized dissemination of video and images related to a police incident. The authority found a breach of GDPR rules governing the processing of personal data.ITGaranteGDPR€60,000
18 Apr 2018Comune di San GeminiComune di San Gemini was fined EUR 10,000 by the Garante for unlawfully transmitting personal data of residents born in 1994–1996 to a school. The conduct breached data protection rules.ITGaranteGDPR€10,000
14 Dec 2017Salvatore AloiSalvatore Aloi was fined EUR 120,000 by the Italian Garante. The case concerned the processing of personal data of 12 individuals without consent, by activating phone cards in their names without authorization.ITGaranteGDPR€120,000
05 Mar 2015Comune di AcateComune di Acate was fined by the Garante for unlawfully publishing personal data revealing health information on its institutional website. The case concerned a breach of data protection rules and the confidentiality of sensitive data.ITGaranteGDPR€10,000
27 May 2021Società e Salute S.p.a.Società e Salute S.p.a. was fined by the Garante EUR 10,000 for a data breach involving the mishandling of personal data, including health information. The authority found violations of GDPR Articles 5 and 9.ITGaranteGDPR€10,000
28 Oct 2021OTTO s.r.l.OTTO s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 2,000 EUR. The case concerned a video surveillance system operated without the required privacy notice, which constitutes a breach of Article 13 GDPR.ITGaranteGDPR€2,000
23 Oct 2025Comune di AvolaThe Garante fined Comune di Avola 2,000 EUR for failing to provide the Authority with the Data Protection Officer’s contact details. The breach concerned the obligation under Article 37(7) GDPR.ITGaranteGDPR€2,000
21 Jan 2016Alfonso EspositoAlfonso Esposito, a gynecologist, was fined by the Garante for processing clients’ personal data for medical purposes without obtaining their consent. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
05 Jul 2017Istituto Auxologico ItalianoIstituto Auxologico Italiano was fined EUR 10,000 by the Garante for failing to implement adequate technical and organizational measures to protect sensitive personal data. The breach concerned the control and security of personal data contained in medical records, in violation of the Italian Data Protection Code.ITGaranteGDPR€10,000