Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Aug 2014Compass ExpoCompass Expo was fined EUR 10,000 by the HDPA for sending unsolicited electronic communications without recipients' consent. The authority found a breach of Article 11 of Law 3471/2006.GRHDPAePrivacy€10,000
09 Nov 2023Complete Marketing Services LtdBetween 8 June 2021 and 4 February 2022, Complete Marketing Services Ltd instigated 242,497 unsolicited direct marketing calls in breach of PECR. The ICO became aware of the matter after complaints about live marketing calls relating to road traffic accidents and personal injury claims were reported via the TPS.GBICOePrivacy€172,000
06 Dec 2011Composad s.r.l.Composad s.r.l. was fined by the Garante €26,000 for processing personal data collected through its website without properly appointing a data processor. The case concerned a breach of data protection rules and related organizational obligations.ITGaranteGDPR€26,000
11 Oct 2023COM. PROP. ***COMUNIDAD.1The entity installed surveillance cameras oriented toward public roads without prior administrative authorization. This breached data protection rules and resulted in a fine by the AEPD.ESAEPDGDPR€1,000
21 Mar 2013Compu & Games srlCompu & Games srl was fined EUR 54,000 by the Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information.ITGaranteGDPR€54,000
10 Oct 2023ComuneThe Italian data protection authority fined a municipality EUR 12,000 for unlawfully publishing personal data online in access request registers. Documents in the transparency section of the municipal website exposed names, protocol numbers, and other sensitive details of hundreds of citizens.ITGarante per la protezione dei dati personaliGDPR€12,000
17 Oct 2024ComuneThe Garante fined Comune EUR 8,000 for breaches of GDPR Articles 5, 6 and 9, and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data in the context of public employment and administrative transparency.ITGaranteGDPR€8,000
05 Mar 2015Comune di AcateComune di Acate was fined by the Garante for unlawfully publishing personal data revealing health information on its institutional website. The case concerned a breach of data protection rules and the confidentiality of sensitive data.ITGaranteGDPR€10,000
02 Apr 2015Comune di AccianoComune di Acciano was fined 4,000 EUR by the Garante for unlawfully processing personal data by keeping a council resolution online beyond the legally permitted period. The case concerned non-compliance with data protection rules on retention and publication limits.ITGaranteGDPR€4,000
17 Oct 2013Comune di AcirealeComune di Acireale was fined for failing to adopt minimum security measures and for not appointing data processing officers, as required by the Italian Data Protection Code. The case concerned basic organizational and security compliance failures.ITGaranteGDPR€10,000
05 Mar 2015Comune di Acquarica del CapoThe Municipality of Acquarica del Capo was fined 10,000 EUR by the Garante for unlawfully publishing personal data revealing health information on its website. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€10,000
27 Apr 2023Comune di AdelfiaThe Garante fined Comune di Adelfia EUR 8,000 for violations related to the publication of personal data on its institutional website. The data were later removed.ITGaranteGDPR€8,000
21 Jan 2016Comune di AdriaComune di Adria was fined EUR 4,000 by the Garante for unlawfully disclosing personal data of third parties. The authority sent photographic results to a complainant that contained data relating to other individuals, breaching data protection rules.ITGaranteGDPR€4,000
27 Apr 2011Comune di AdroThe Municipality of Adro was fined 15,000 EUR by the Italian supervisory authority Garante. The case concerned the publication of employees’ personal data, including health information, in a periodical.ITGaranteGDPR€15,000
26 May 2022Comune di AfragolaComune di Afragola was fined EUR 10,000 by the Garante for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. The authority found that personal data had been handled improperly.ITGaranteGDPR€10,000
12 Mar 2015Comune di Alì TermeComune di Alì Terme was fined for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy rules and the protection of sensitive personal data.ITGaranteGDPR€10,000
12 Feb 2026Comune di AnconaThe Garante fined Comune di Ancona EUR 3,000 for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found that no proper contract was in place with a data processor, in breach of GDPR Articles 5 and 28.ITGaranteGDPR€3,000
23 Apr 2015Comune di AostaComune di Aosta was fined for publishing personal data that revealed health information on its website. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€10,000
23 Oct 2025Comune di Arcinazzo RomanoThe Garante fined Comune di Arcinazzo Romano 4,500 EUR for unlawfully processing personal data through a video system. The system was used to verify tax compliance for waste disposal, in breach of the principles of lawfulness, fairness, transparency, and purpose limitation.ITGaranteGDPR€4,500
26 Feb 2020Comune di AstiComune di Asti was fined EUR 8,000 by the Garante for unlawfully publishing personal data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€8,000