Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Apr 2023Suditaly Imprese Meridionali Soc. coop.The Garante imposed a 2,500 EUR fine on Suditaly Imprese Meridionali Soc. coop. for publishing detailed health data without the data subjects' consent. The case concerned Article 9 of the GDPR, which restricts processing of special categories of personal data.ITGaranteGDPR€2,500
27 Jan 2021Istituto Comprensivo Villanova D’AstiIstituto Comprensivo Villanova D’Asti was fined EUR 4,000 by the Garante for publishing personal data online. The disclosed information could reveal health status and economic-social conditions, breaching data minimization and transparency principles.ITGaranteGDPR€4,000
11 Jan 2023Commify Italia S.r.l.Commify Italia S.r.l. was fined by the Garante 80,000 EUR for violations related to the processing of personal data through its Skebby platform. The case involved inadequate data protection measures and unauthorized access that led to phishing attacks.ITGaranteGDPR€80,000
13 Jul 2016Istituto Scolastico Masterform s.r.l.Istituto Scolastico Masterform s.r.l. was fined EUR 2,400 by the Italian Garante. The company collected personal data through its website without providing users with the required privacy information, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
29 Apr 2025Energia Verde S.p.A.Energia Verde S.p.A. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a legal basis. The authority also found that the company did not adequately respond to data subjects' requests, indicating failures in data protection compliance.ITGaranteGDPR€100,000
24 Apr 2024I.N.P.A.S.The Garante imposed a fine on I.N.P.A.S. for violations related to the processing of employees' personal data, including sensitive data. The authority found that the processing did not ensure lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
21 Apr 2021Ministero dell’Istruzione, dell’Università e della Ricerca, Ufficio Scolastico Regionale per la Toscana, Ufficio VIII Ambito territoriale della provincia di LivornoThe Italian Ministry of Education was fined 3,000 EUR by the Garante. The case concerned personal data of teachers remaining accessible online in breach of GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
10 Mar 2016Il Desiderio s.a.s.Il Desiderio s.a.s. was fined EUR 2,400 by the Garante for failing to provide adequate simplified information about video surveillance. The breach concerned Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
11 Apr 2013Zeno VincoZeno Vinco was fined by the Garante for registering SIM cards to 36 individuals without their knowledge. The case involved a breach of data protection rules.ITGaranteGDPR€108,000
27 Jan 2021Comune di Cesano BosconeThe Municipality of Cesano Boscone was fined EUR 2,000 by the Garante for publishing personal data related to a disciplinary sanction on its website. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€2,000
17 Apr 2026The European House - Ambrosetti S.p.A.The European House - Ambrosetti S.p.A. was fined by Garante 85,000 EUR for a data breach. The incident involved unauthorized access and exfiltration of personal and authentication data affecting an unspecified number of individuals.ITGaranteGDPR€85,000
06 Nov 2014Comune di VeronellaComune di Veronella was fined by the Garante for unlawfully publishing personal data on its online notice board for longer than the legally permitted 15 days. This constituted a breach of data protection rules.ITGaranteGDPR€4,000
16 Jun 2022Deutsche Bank S.p.A.Deutsche Bank S.p.A. was fined EUR 20,000 by the Garante for unlawfully processing personal data. The bank reported an individual's name to CRIF S.p.A. without prior notice, which breached data protection rules.ITGaranteGDPR€20,000
10 Apr 2025Gioele MagaldiThe Garante fined Gioele Magaldi, the manager of a blog, EUR 4,000 for publishing defamatory articles. The authority found that the content contained false information and exceeded the limits of the right to report because it lacked social utility.ITGaranteGDPR€4,000
15 Feb 2018Auto Uno s.r.l.Auto Uno s.r.l. was fined EUR 30,000 by the Italian Garante. The case concerned improper management of a video surveillance system, including excessive retention of recorded images.ITGaranteGDPR€30,000
26 Mar 2026Provvedimento del 26 marzo 2026 [10241477]A doctor did not comply with a request to delete data and provided patients with incomplete information, which constituted a breach of GDPR Article 13. The Garante imposed a fine of EUR 2,000.ITGaranteGDPR€2,000
11 Sept 2025Provvedimento dell'11 settembre 2025 [10184252]A public entity was fined by the Garante EUR 500 for installing a video surveillance system in a public parking area without providing adequate information to data subjects. The authority found a breach of GDPR transparency and information obligations.ITGaranteGDPR€500
18 Sept 2008Suzuki Italia S.p.A.Suzuki Italia S.p.A. was fined for failing to provide the required privacy notice to individuals whose personal data was obtained from a third party. The breach was found under the Italian Data Protection Code.ITGaranteGDPR€45,000
18 Dec 2013Google Inc.Google Inc. was fined EUR 1 million by the Italian Data Protection Authority, Garante. The authority found that individuals were not adequately informed during data collection by Google cars for the Street View service.ITGaranteGDPR€1,000,000
12 Jan 2017Globo Vigilanza s.r.l.Globo Vigilanza s.r.l. was fined by the Garante EUR 12,000 for using a GPS tracking system on company vehicles without providing employees with the required information about the purposes of data processing. The case also involved the use of those data in disciplinary actions against employees.ITGaranteGDPR€12,000