Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 May 2023Volkswagen Leasing GmbHVolkswagen Leasing GmbH was fined EUR 40,000 by the Garante for failing to adequately respond to a data access request. The authority found a breach of GDPR provisions on data subject rights.ITGaranteGDPR€40,000
13 May 2015Provincia di NapoliProvincia di Napoli was fined for unlawfully publishing personal data, including health information, on its institutional website. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
22 May 2018Alessandro SabatiniAlessandro Sabatini, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum personal data security measures were not implemented, which allowed unauthorized access to a health information system.ITGaranteGDPR€10,000
05 Sept 2013Huawei Technologies Italia S.r.lHuawei Technologies Italia S.r.l was fined EUR 30,000 by the Garante for breaching data protection rules. The company retained surveillance footage for 18 days, exceeding the permitted retention period.ITGaranteGDPR€30,000
18 Nov 2015Collegio professionale dei periti industriali di Roma e provinciaCollegio professionale dei periti industriali di Roma e provincia was fined 10,000 EUR by the Garante for unlawfully publishing judicial data on its website. The publication occurred during an election campaign.ITGaranteGDPR€10,000
02 Dec 2015Sea srlSea srl was fined EUR 2,400 by the Italian Garante. The case concerned the installation of a video surveillance system without providing the required privacy notice, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
11 May 2017Bianalisi s.p.a.Bianalisi s.p.a. was fined by the Italian data protection authority, Garante, for failing to update its notification concerning the processing of genetic data. The obligation arose under the Italian Privacy Code and was intended to ensure proper disclosure of sensitive data processing.ITGaranteGDPR€20,000
15 Oct 2020Comune di CollegnoComune di Collegno was fined by the Garante for failing to respond in time to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15.ITGaranteGDPR€2,000
28 Oct 2021dott.ssa GiglioA doctor was fined for improperly handling personal data, including medical prescriptions. The authority found breaches of GDPR Articles 5, 9, and 32 on processing principles, special-category data, and security measures.ITGaranteGDPR€10,000
13 Nov 2024Montini Group S.r.l.Montini Group S.r.l. was fined EUR 6,000 by the Garante. The case concerned contacting an employee’s general practitioner without consent, which breached GDPR rules on processing health data.ITGaranteGDPR€6,000
12 May 2022Zito Auto di Gianfranco ZitoThe company was fined for operating a video surveillance system that did not meet the information requirements under GDPR Article 13 and Article 114 of the Italian Privacy Code. The authority found that the required notices for monitored individuals were not properly provided.ITGaranteGDPR€3,000
07 May 2015Ordinanza ingiunzione - 7 maggio 2015 [4226113]The Garante imposed a EUR 2,400 fine on the company for providing an inadequate privacy notice on its website contact form. The breach concerned the requirements of the Italian Data Protection Code.ITGaranteGDPR€2,400
12 Mar 2026Liceo Scientifico MorgagniLiceo Scientifico Morgagni was fined by the Garante for violations related to the processing of sensitive data. The authority cited inadequate security measures in the protection of those data.ITGaranteGDPR€2,000
06 Jul 2016La Fourchette (Italy) s.r.l.La Fourchette (Italy) s.r.l. was fined EUR 10,000 by the Garante. The authority found that the company collected personal data for promotional purposes without obtaining specific consent from users.ITGaranteGDPR€10,000
17 Apr 2014Gambero Rosso Holding s.p.a.Gambero Rosso Holding s.p.a. was fined by the Italian data protection authority, Garante, for sending promotional emails without prior explicit consent from recipients. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code.ITGaranteGDPR€16,000
22 May 2013Romulus PopescuRomulus Popescu was fined EUR 16,000 by the Garante. The sanction concerned sending unsolicited promotional communications to a minor without proper consent.ITGaranteGDPR€16,000
12 Apr 2012Alitalia – Compagnia Aerea Italiana s.p.a.Alitalia was fined by the Garante for inadequate data protection measures and for failing to provide proper information to customers during call center interactions. The authority found that these practices breached Italian data protection law.ITGaranteGDPR€120,000
26 Mar 2026Eni S.p.A.Eni S.p.A. was fined 96,000 EUR by the Garante for publishing personal data on its website, including dates of birth and addresses, without proper masking. The authority found this breached GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€96,000
05 Jun 2014Comune di TerniThe Garante fined Comune di Terni €4,000 for publishing personal data on its website for longer than the legally permitted 15 days. The authority found this to be a breach of data protection rules.ITGaranteGDPR€4,000
09 Oct 2014People & Communication s.r.l.People & Communication s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The case concerned the sending of pre-recorded promotional phone calls without obtaining the required consent from recipients.ITGaranteGDPR€20,000