Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jun 2020UniCredit S.p.A.UniCredit S.p.A. was fined by Garante EUR 600,000 for a data breach. The incident involved unauthorized access to personal data of about 762,000 individuals after an intrusion using credentials of employees from an external partner.ITGaranteGDPR€600,000
12 Mar 2026Domiziana GiorgianniThe Garante imposed a EUR 2,000 fine on Domiziana Giorgianni for failing to implement adequate technical and organizational measures to support data subject rights. The authority also found that requests were not handled without undue delay.ITGaranteGDPR€2,000
15 Mar 2018Studio Silver Consulting S.r.l.s.Studio Silver Consulting S.r.l.s. was fined EUR 30,000 by the Garante for violations related to the processing of personal data in its debt management activities. The case concerned improper handling of personal data in the context of debt collection operations.ITGaranteGDPR€30,000
15 Jan 2015Zoccatelli MichelaZoccatelli Michela was fined EUR 2,400 by the Garante for failing to provide information to individuals applying for membership in the private Aquila Club. The authority treated this as a breach of data protection rules.ITGaranteGDPR€2,400
01 Dec 2022Regione CampaniaRegione Campania was fined by the Garante in the amount of EUR 10,000 for unauthorized access to personal data. The case concerned breaches of GDPR requirements on data protection and security measures.ITGaranteGDPR€10,000
12 Feb 2015Comune di CalatabianoComune di Calatabiano was fined 10,000 EUR by the Garante for unlawfully publishing personal data revealing health conditions on its institutional website. The conduct breached privacy rules governing the processing and disclosure of sensitive data.ITGaranteGDPR€10,000
18 Sept 2008Eurolaurea Caserta s.r.l.Eurolaurea Caserta s.r.l. was fined EUR 3,000 by the Garante. The authority found that the company failed to provide data subjects with the information required under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
06 Nov 2014Comune di GerenzanoThe Municipality of Gerenzano was fined 4,000 EUR by the Garante for failing to appoint a socially useful worker as a data processor. The authority found this breached the minimum security measures required under the data protection code.ITGaranteGDPR€4,000
20 Sept 2012Casa di cura privata Montevergine s.p.a.The private clinic Montevergine was fined 50,000 EUR by the Garante. The authority found that it processed employees' biometric data for attendance tracking without first notifying the supervisory authority.ITGaranteGDPR€50,000
22 Feb 2024Coop Italia Società CooperativaCoop Italia Società Cooperativa was fined by the Garante 90,000 EUR for unlawfully processing personal data for marketing purposes without proper consent. The authority found a breach of GDPR principles, including Article 5.ITGaranteGDPR€90,000
26 Mar 2026Comune di XXThe Garante fined Comune di XX EUR 5,000 for breaches of lawfulness, fairness, transparency, and data minimization. It also found failures to implement data protection by design and by default.ITGaranteGDPR€5,000
14 Apr 2023Green Network S.p.a.Green Network S.p.a. was fined by the Garante for illegal telemarketing practices in the energy sector. The authority found a breach of data protection principles.ITGaranteGDPR€237,000
14 Jan 2021Azienda Ospedaliera San Pio di BeneventoAzienda Ospedaliera San Pio di Benevento was fined by the Garante 10,000 EUR for publishing employees’ personal data on its intranet without a proper legal basis. The case concerned unauthorized disclosure of personal data within the organization’s internal environment.ITGaranteGDPR€10,000
11 Dec 2008Eutelia S.p.A.Eutelia S.p.A. was fined by the Garante for processing personal data without providing the required privacy notice. The breach occurred during the activation of an unsolicited telephone service and concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€54,000
07 Feb 2013Primi sui Motori s.p.a.Primi sui Motori s.p.a. was fined €23,000 by the Garante for sending unsolicited promotional emails. The authority found that the company had not obtained prior, specific, and informed consent from the recipients.ITGaranteGDPR€23,000
15 Apr 2021Ordinanza ingiunzione - 15 aprile 2021The case concerned a breach of data protection rules by a healthcare entity. Consent for processing personal data for epidemiological research was obtained improperly.ITGaranteGDPR€5,000
18 Sept 2014Meridi s.r.l.Meridi s.r.l. was fined by the Garante 40,000 EUR for failing to provide adequate information about video surveillance and for not appointing data processing officers. The authority found a breach of data security measures.ITGaranteGDPR€40,000
22 Oct 2015Ferrara AdrianoFerrara Adriano was fined EUR 2,400 by the Garante. The authority found that the company used a video surveillance system without adequate notices for the individuals being recorded, in breach of data protection rules.ITGaranteGDPR€2,400
12 Nov 2014Areacom s.r.l.Areacom s.r.l. was fined by the Garante 16,000 EUR for collecting personal data through its website without providing the required privacy notice. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€16,000
03 May 2018Marconi RobertoMarconi Roberto, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum security measures to protect patients' personal and sensitive data were not adopted, allowing unauthorized access to the healthcare system.ITGaranteGDPR€10,000