Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Jan 2021Azienda Ospedaliera San Pio di BeneventoAzienda Ospedaliera San Pio di Benevento was fined by the Garante 10,000 EUR for publishing employees’ personal data on its intranet without a proper legal basis. The case concerned unauthorized disclosure of personal data within the organization’s internal environment.ITGaranteGDPR€10,000
11 Dec 2008Eutelia S.p.A.Eutelia S.p.A. was fined by the Garante for processing personal data without providing the required privacy notice. The breach occurred during the activation of an unsolicited telephone service and concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€54,000
07 Feb 2013Primi sui Motori s.p.a.Primi sui Motori s.p.a. was fined €23,000 by the Garante for sending unsolicited promotional emails. The authority found that the company had not obtained prior, specific, and informed consent from the recipients.ITGaranteGDPR€23,000
15 Apr 2021Ordinanza ingiunzione - 15 aprile 2021The case concerned a breach of data protection rules by a healthcare entity. Consent for processing personal data for epidemiological research was obtained improperly.ITGaranteGDPR€5,000
18 Sept 2014Meridi s.r.l.Meridi s.r.l. was fined by the Garante 40,000 EUR for failing to provide adequate information about video surveillance and for not appointing data processing officers. The authority found a breach of data security measures.ITGaranteGDPR€40,000
22 Oct 2015Ferrara AdrianoFerrara Adriano was fined EUR 2,400 by the Garante. The authority found that the company used a video surveillance system without adequate notices for the individuals being recorded, in breach of data protection rules.ITGaranteGDPR€2,400
12 Nov 2014Areacom s.r.l.Areacom s.r.l. was fined by the Garante 16,000 EUR for collecting personal data through its website without providing the required privacy notice. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€16,000
03 May 2018Marconi RobertoMarconi Roberto, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum security measures to protect patients' personal and sensitive data were not adopted, allowing unauthorized access to the healthcare system.ITGaranteGDPR€10,000
17 May 2023Volkswagen Leasing GmbHVolkswagen Leasing GmbH was fined EUR 40,000 by the Garante for failing to adequately respond to a data access request. The authority found a breach of GDPR provisions on data subject rights.ITGaranteGDPR€40,000
13 May 2015Provincia di NapoliProvincia di Napoli was fined for unlawfully publishing personal data, including health information, on its institutional website. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
22 May 2018Alessandro SabatiniAlessandro Sabatini, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum personal data security measures were not implemented, which allowed unauthorized access to a health information system.ITGaranteGDPR€10,000
05 Sept 2013Huawei Technologies Italia S.r.lHuawei Technologies Italia S.r.l was fined EUR 30,000 by the Garante for breaching data protection rules. The company retained surveillance footage for 18 days, exceeding the permitted retention period.ITGaranteGDPR€30,000
18 Nov 2015Collegio professionale dei periti industriali di Roma e provinciaCollegio professionale dei periti industriali di Roma e provincia was fined 10,000 EUR by the Garante for unlawfully publishing judicial data on its website. The publication occurred during an election campaign.ITGaranteGDPR€10,000
02 Dec 2015Sea srlSea srl was fined EUR 2,400 by the Italian Garante. The case concerned the installation of a video surveillance system without providing the required privacy notice, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
11 May 2017Bianalisi s.p.a.Bianalisi s.p.a. was fined by the Italian data protection authority, Garante, for failing to update its notification concerning the processing of genetic data. The obligation arose under the Italian Privacy Code and was intended to ensure proper disclosure of sensitive data processing.ITGaranteGDPR€20,000
15 Oct 2020Comune di CollegnoComune di Collegno was fined by the Garante for failing to respond in time to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15.ITGaranteGDPR€2,000
28 Oct 2021dott.ssa GiglioA doctor was fined for improperly handling personal data, including medical prescriptions. The authority found breaches of GDPR Articles 5, 9, and 32 on processing principles, special-category data, and security measures.ITGaranteGDPR€10,000
13 Nov 2024Montini Group S.r.l.Montini Group S.r.l. was fined EUR 6,000 by the Garante. The case concerned contacting an employee’s general practitioner without consent, which breached GDPR rules on processing health data.ITGaranteGDPR€6,000
12 May 2022Zito Auto di Gianfranco ZitoThe company was fined for operating a video surveillance system that did not meet the information requirements under GDPR Article 13 and Article 114 of the Italian Privacy Code. The authority found that the required notices for monitored individuals were not properly provided.ITGaranteGDPR€3,000
07 May 2015Ordinanza ingiunzione - 7 maggio 2015 [4226113]The Garante imposed a EUR 2,400 fine on the company for providing an inadequate privacy notice on its website contact form. The breach concerned the requirements of the Italian Data Protection Code.ITGaranteGDPR€2,400