Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 May 2021Tempocasa S.p.A.Tempocasa S.p.A. was fined €120,000 by the Italian Garante. The authority found that the company made unsolicited promotional calls without the required consent, breaching GDPR rules on data processing and consent.ITGaranteGDPR€120,000
26 Apr 2018MTS s.r.l.s.MTS s.r.l.s. was fined EUR 76,000 by the Garante for making unsolicited promotional calls. The company also failed to respond to the authority's request for information, which constituted a data protection breach.ITGaranteGDPR€76,000
04 Oct 2012Ministero dell'Istruzione, dell'Università e della Ricerca - Direzione generale per l'università, lo studente e il diritto allo studio universitarioThe Ministry of Education, University and Research was fined by the Garante for unlawfully disclosing personal data on its website. The authority found no legal basis for the processing.ITGaranteGDPR€20,000
22 Jan 2015Istituto Nazionale Previdenza SocialeIstituto Nazionale Previdenza Sociale was fined EUR 44,000 by the Garante. The authority found that the required privacy notice was not provided to users, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€44,000
12 Feb 2026Unleadmited S.r.l.Unleadmited S.r.l. was fined EUR 5,000 by the Garante for violations linked to aggressive telemarketing practices. The authority found non-compliance with data protection requirements.ITGaranteGDPR€5,000
05 Sept 2013CURTIPETRIZZILANDIA S.a.sCURTIPETRIZZILANDIA S.a.s was fined by the Garante in the amount of 2,400 EUR for providing inadequate data protection information on its website booking form. The case concerned breaches of the information duties under the Italian Data Protection Code.ITGaranteGDPR€2,400
30 Jan 2020Liceo Nobel di Torre del GrecoLiceo Nobel di Torre del Greco was fined EUR 4,000 by the Garante for publishing a teacher ranking list on its website. The conduct breached GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
20 Mar 2008GS S.p.A.GS S.p.A. was fined for collecting personal data in connection with a loyalty card program without providing adequate notice to data subjects. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€54,000
13 Apr 2023Suditaly Imprese Meridionali Soc. coop.The Garante imposed a 2,500 EUR fine on Suditaly Imprese Meridionali Soc. coop. for publishing detailed health data without the data subjects' consent. The case concerned Article 9 of the GDPR, which restricts processing of special categories of personal data.ITGaranteGDPR€2,500
27 Jan 2021Istituto Comprensivo Villanova D’AstiIstituto Comprensivo Villanova D’Asti was fined EUR 4,000 by the Garante for publishing personal data online. The disclosed information could reveal health status and economic-social conditions, breaching data minimization and transparency principles.ITGaranteGDPR€4,000
11 Jan 2023Commify Italia S.r.l.Commify Italia S.r.l. was fined by the Garante 80,000 EUR for violations related to the processing of personal data through its Skebby platform. The case involved inadequate data protection measures and unauthorized access that led to phishing attacks.ITGaranteGDPR€80,000
13 Jul 2016Istituto Scolastico Masterform s.r.l.Istituto Scolastico Masterform s.r.l. was fined EUR 2,400 by the Italian Garante. The company collected personal data through its website without providing users with the required privacy information, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
29 Apr 2025Energia Verde S.p.A.Energia Verde S.p.A. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a legal basis. The authority also found that the company did not adequately respond to data subjects' requests, indicating failures in data protection compliance.ITGaranteGDPR€100,000
24 Apr 2024I.N.P.A.S.The Garante imposed a fine on I.N.P.A.S. for violations related to the processing of employees' personal data, including sensitive data. The authority found that the processing did not ensure lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
21 Apr 2021Ministero dell’Istruzione, dell’Università e della Ricerca, Ufficio Scolastico Regionale per la Toscana, Ufficio VIII Ambito territoriale della provincia di LivornoThe Italian Ministry of Education was fined 3,000 EUR by the Garante. The case concerned personal data of teachers remaining accessible online in breach of GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
10 Mar 2016Il Desiderio s.a.s.Il Desiderio s.a.s. was fined EUR 2,400 by the Garante for failing to provide adequate simplified information about video surveillance. The breach concerned Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
11 Apr 2013Zeno VincoZeno Vinco was fined by the Garante for registering SIM cards to 36 individuals without their knowledge. The case involved a breach of data protection rules.ITGaranteGDPR€108,000
27 Jan 2021Comune di Cesano BosconeThe Municipality of Cesano Boscone was fined EUR 2,000 by the Garante for publishing personal data related to a disciplinary sanction on its website. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€2,000
17 Apr 2026The European House - Ambrosetti S.p.A.The European House - Ambrosetti S.p.A. was fined by Garante 85,000 EUR for a data breach. The incident involved unauthorized access and exfiltration of personal and authentication data affecting an unspecified number of individuals.ITGaranteGDPR€85,000
06 Nov 2014Comune di VeronellaComune di Veronella was fined by the Garante for unlawfully publishing personal data on its online notice board for longer than the legally permitted 15 days. This constituted a breach of data protection rules.ITGaranteGDPR€4,000