Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Mar 2011Sestrieres S.p.A.Sestrieres S.p.A. was fined by the Italian Garante for failing to provide adequate information to individuals about the processing of their personal data when using ski lift turnstiles. The authority found a breach of data protection rules.ITGaranteGDPR€12,000
12 Feb 2026Depurazione Acqua S.r.l.Depurazione Acqua S.r.l. was fined by the Garante for carrying out promotional activities without a valid legal basis. The case concerns GDPR breaches related to data processing and consent.ITGaranteGDPR€15,000
13 Sept 2007Asl San Severo (Foggia 1)Asl San Severo (Foggia 1) was fined by the Garante for processing personal data, including genetic and biometric data, without proper compliance with data protection rules. The case indicates insufficient legal basis and safeguards for the handling of sensitive data.ITGaranteGDPR€10,000
12 Sept 2013European Group Sae, Italian Business GuaranteeEuropean Group Sae was fined EUR 12,800 by the Garante. The authority found that the company sent unsolicited promotional faxes without proper information or consent, in breach of privacy rules.ITGaranteGDPR€12,800
12 Nov 2014Yueming LiYueming Li was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned a failure to provide data subjects with the required information about the processing of personal data through a video surveillance system at Sala VLT Video Lottery 999 in Milan.ITGaranteGDPR€2,400
14 Sept 2006Asl 21 di Casale MonferratoThe Garante fined Asl 21 di Casale Monferrato 10,000 EUR for processing genetic and health data without the required notification. The authority found a breach of the Italian Privacy Code.ITGaranteGDPR€10,000
21 Mar 2013Pologest s.r.l.Pologest s.r.l. was fined by the Garante €6,400 for sending unsolicited promotional communications by fax. The conduct breached data protection rules governing marketing communications.ITGaranteGDPR€6,400
22 Feb 2024Blue Work s.r.l.Blue Work s.r.l. was fined EUR 6,000 by the Garante for unlawful processing of biometric data using facial recognition for employee attendance tracking. The authority found that the same purpose could have been achieved through less intrusive means.ITGaranteGDPR€6,000
14 Mar 2013Casa di cura Parco dei Tigli S.a.s. di Alessandro Borgherini & Co.The Garante fined Casa di cura Parco dei Tigli S.a.s. 2,400 EUR for providing inadequate data protection information on its website. The conduct breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
23 Dec 2010Altea Servizi s.r.l.Altea Servizi s.r.l. was fined by the Garante in the amount of 12,000 EUR. The authority found two violations for failing to provide timely information to data subjects as required by Article 13 of the Italian Data Protection Code.ITGaranteGDPR€12,000
26 Mar 2015Comune di Santa NinfaComune di Santa Ninfa was fined EUR 4,000 by the Garante for unlawfully publishing personal data on its institutional website. The data remained available for longer than the legally permitted 15 days, constituting a data protection breach.ITGaranteGDPR€4,000
16 Mar 2017Obiettivo Ferrari s.r.l.Obiettivo Ferrari s.r.l. was fined by the Garante €16,000 for making an unsolicited promotional call. The company did not provide the required data protection information or obtain consent from the recipient.ITGaranteGDPR€16,000
27 May 2021Tempocasa S.p.A.Tempocasa S.p.A. was fined €120,000 by the Italian Garante. The authority found that the company made unsolicited promotional calls without the required consent, breaching GDPR rules on data processing and consent.ITGaranteGDPR€120,000
26 Apr 2018MTS s.r.l.s.MTS s.r.l.s. was fined EUR 76,000 by the Garante for making unsolicited promotional calls. The company also failed to respond to the authority's request for information, which constituted a data protection breach.ITGaranteGDPR€76,000
04 Oct 2012Ministero dell'Istruzione, dell'Università e della Ricerca - Direzione generale per l'università, lo studente e il diritto allo studio universitarioThe Ministry of Education, University and Research was fined by the Garante for unlawfully disclosing personal data on its website. The authority found no legal basis for the processing.ITGaranteGDPR€20,000
22 Jan 2015Istituto Nazionale Previdenza SocialeIstituto Nazionale Previdenza Sociale was fined EUR 44,000 by the Garante. The authority found that the required privacy notice was not provided to users, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€44,000
12 Feb 2026Unleadmited S.r.l.Unleadmited S.r.l. was fined EUR 5,000 by the Garante for violations linked to aggressive telemarketing practices. The authority found non-compliance with data protection requirements.ITGaranteGDPR€5,000
05 Sept 2013CURTIPETRIZZILANDIA S.a.sCURTIPETRIZZILANDIA S.a.s was fined by the Garante in the amount of 2,400 EUR for providing inadequate data protection information on its website booking form. The case concerned breaches of the information duties under the Italian Data Protection Code.ITGaranteGDPR€2,400
30 Jan 2020Liceo Nobel di Torre del GrecoLiceo Nobel di Torre del Greco was fined EUR 4,000 by the Garante for publishing a teacher ranking list on its website. The conduct breached GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
20 Mar 2008GS S.p.A.GS S.p.A. was fined for collecting personal data in connection with a loyalty card program without providing adequate notice to data subjects. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€54,000