Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Jun 2022Deutsche Bank S.p.A.Deutsche Bank S.p.A. was fined EUR 20,000 by the Garante for unlawfully processing personal data. The bank reported an individual's name to CRIF S.p.A. without prior notice, which breached data protection rules.ITGaranteGDPR€20,000
10 Apr 2025Gioele MagaldiThe Garante fined Gioele Magaldi, the manager of a blog, EUR 4,000 for publishing defamatory articles. The authority found that the content contained false information and exceeded the limits of the right to report because it lacked social utility.ITGaranteGDPR€4,000
15 Feb 2018Auto Uno s.r.l.Auto Uno s.r.l. was fined EUR 30,000 by the Italian Garante. The case concerned improper management of a video surveillance system, including excessive retention of recorded images.ITGaranteGDPR€30,000
26 Mar 2026Provvedimento del 26 marzo 2026 [10241477]A doctor did not comply with a request to delete data and provided patients with incomplete information, which constituted a breach of GDPR Article 13. The Garante imposed a fine of EUR 2,000.ITGaranteGDPR€2,000
11 Sept 2025Provvedimento dell'11 settembre 2025 [10184252]A public entity was fined by the Garante EUR 500 for installing a video surveillance system in a public parking area without providing adequate information to data subjects. The authority found a breach of GDPR transparency and information obligations.ITGaranteGDPR€500
18 Sept 2008Suzuki Italia S.p.A.Suzuki Italia S.p.A. was fined for failing to provide the required privacy notice to individuals whose personal data was obtained from a third party. The breach was found under the Italian Data Protection Code.ITGaranteGDPR€45,000
18 Dec 2013Google Inc.Google Inc. was fined EUR 1 million by the Italian Data Protection Authority, Garante. The authority found that individuals were not adequately informed during data collection by Google cars for the Street View service.ITGaranteGDPR€1,000,000
12 Jan 2017Globo Vigilanza s.r.l.Globo Vigilanza s.r.l. was fined by the Garante EUR 12,000 for using a GPS tracking system on company vehicles without providing employees with the required information about the purposes of data processing. The case also involved the use of those data in disciplinary actions against employees.ITGaranteGDPR€12,000
10 Jun 2020UniCredit S.p.A.UniCredit S.p.A. was fined by Garante EUR 600,000 for a data breach. The incident involved unauthorized access to personal data of about 762,000 individuals after an intrusion using credentials of employees from an external partner.ITGaranteGDPR€600,000
12 Mar 2026Domiziana GiorgianniThe Garante imposed a EUR 2,000 fine on Domiziana Giorgianni for failing to implement adequate technical and organizational measures to support data subject rights. The authority also found that requests were not handled without undue delay.ITGaranteGDPR€2,000
15 Mar 2018Studio Silver Consulting S.r.l.s.Studio Silver Consulting S.r.l.s. was fined EUR 30,000 by the Garante for violations related to the processing of personal data in its debt management activities. The case concerned improper handling of personal data in the context of debt collection operations.ITGaranteGDPR€30,000
15 Jan 2015Zoccatelli MichelaZoccatelli Michela was fined EUR 2,400 by the Garante for failing to provide information to individuals applying for membership in the private Aquila Club. The authority treated this as a breach of data protection rules.ITGaranteGDPR€2,400
01 Dec 2022Regione CampaniaRegione Campania was fined by the Garante in the amount of EUR 10,000 for unauthorized access to personal data. The case concerned breaches of GDPR requirements on data protection and security measures.ITGaranteGDPR€10,000
12 Feb 2015Comune di CalatabianoComune di Calatabiano was fined 10,000 EUR by the Garante for unlawfully publishing personal data revealing health conditions on its institutional website. The conduct breached privacy rules governing the processing and disclosure of sensitive data.ITGaranteGDPR€10,000
18 Sept 2008Eurolaurea Caserta s.r.l.Eurolaurea Caserta s.r.l. was fined EUR 3,000 by the Garante. The authority found that the company failed to provide data subjects with the information required under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
06 Nov 2014Comune di GerenzanoThe Municipality of Gerenzano was fined 4,000 EUR by the Garante for failing to appoint a socially useful worker as a data processor. The authority found this breached the minimum security measures required under the data protection code.ITGaranteGDPR€4,000
20 Sept 2012Casa di cura privata Montevergine s.p.a.The private clinic Montevergine was fined 50,000 EUR by the Garante. The authority found that it processed employees' biometric data for attendance tracking without first notifying the supervisory authority.ITGaranteGDPR€50,000
22 Feb 2024Coop Italia Società CooperativaCoop Italia Società Cooperativa was fined by the Garante 90,000 EUR for unlawfully processing personal data for marketing purposes without proper consent. The authority found a breach of GDPR principles, including Article 5.ITGaranteGDPR€90,000
26 Mar 2026Comune di XXThe Garante fined Comune di XX EUR 5,000 for breaches of lawfulness, fairness, transparency, and data minimization. It also found failures to implement data protection by design and by default.ITGaranteGDPR€5,000
14 Apr 2023Green Network S.p.a.Green Network S.p.a. was fined by the Garante for illegal telemarketing practices in the energy sector. The authority found a breach of data protection principles.ITGaranteGDPR€237,000