Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 May 2021Comune di BolzanoThe Municipality of Bolzano was fined 84,000 EUR by the Garante for improper handling of employee internet navigation data. The authority found that personal data were systematically collected without adequate safeguards and in breach of data protection principles.ITGaranteGDPR€84,000
12 Nov 2015Croce Rosa Italiana s.r.l.Croce Rosa Italiana s.r.l. was fined for processing employee personal data using electronic tools for geolocation without adopting minimum security measures. The authority found a breach of Article 33 of the Italian Data Protection Code.ITGaranteGDPR€10,000
20 Jun 2024Provvedimento del 20 giugno 2024 [10105123]The Municipality of XX was fined for unlawfully disclosing personal and health data by publishing it on its Facebook page. The authority found that the public disclosure of this information breached data protection rules.ITGaranteGDPR€10,000
22 May 2018Calvanese RaffaelloCalvanese Raffaello, a general practitioner, was fined for failing to adopt minimum security measures to protect patients’ personal and sensitive data. The deficiencies allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
22 Oct 2015Liceo scientifico statale Plinio SenioreLiceo scientifico statale Plinio Seniore was fined EUR 10,400 by the Garante for processing biometric data and using video surveillance without providing adequate information to the data subjects. The authority found this conduct to be in breach of the Italian Data Protection Code.ITGaranteGDPR€10,400
18 Jul 2023Comune di ModicaThe Garante fined Comune di Modica EUR 45,000 for inadequate data protection measures linked to video surveillance in public areas. The issues affected a large number of individuals over an extended period, and those recorded were not properly informed.ITGaranteGDPR€45,000
13 Nov 2024Illumia S.p.A.Illumia S.p.A. was fined by the Italian data protection authority, Garante, for violations related to the processing of personal data for telemarketing purposes. The authority cited inadequate contractual arrangements with sub-processors and insufficient oversight of commercial partners.ITGaranteGDPR€678,000
20 Jul 2017S.I.T. s.r.l.S.I.T. s.r.l. was fined by the Garante in the amount of EUR 6,400 for unauthorized access to surveillance images and for processing customer data without proper notice to data subjects. The authority found that these actions breached data protection rules.ITGaranteGDPR€6,400
26 Feb 2026Dante Labs S.r.l.Dante Labs S.r.l. was fined EUR 600 by the Garante for failing to provide the results of a genetic test after receiving a customer's DNA sample. Despite multiple attempts by the customer to contact the company, the results were not delivered or explained.ITGaranteGDPR€600
29 May 2008Consulting S.p.A.Consulting S.p.A. was fined for collecting personal data through its website without providing adequate prior information. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
15 Dec 2022Edison Energia S.p.A.Edison Energia S.p.A. was fined for running promotional campaigns to non-customers without adequate checks on data lists supplied by third parties. The authority found breaches of GDPR requirements on data processing and consent.ITGaranteGDPR€4,900,000
17 Oct 2013Comune di AcirealeComune di Acireale was fined for failing to adopt minimum security measures and for not appointing data processing officers, as required by the Italian Data Protection Code. The case concerned basic organizational and security compliance failures.ITGaranteGDPR€10,000
24 Nov 2022STS Di Prisinzano s.r.l.STS Di Prisinzano s.r.l. was fined EUR 1,000 by the Garante for failing to provide a data subject with an adequate privacy notice during roadside assistance. The authority found a breach of Article 13 GDPR.ITGaranteGDPR€1,000
09 Mar 2023Banca Cambiano 1884 S.p.A.Banca Cambiano 1884 S.p.A. was fined by the Garante 10,000 EUR for failing to respond within the required timeframe to a data subject's request for access to personal data. The authority found a breach of GDPR Articles 15 and 12.ITGaranteGDPR€10,000
28 Apr 2022Il Sole 24 Ore S.p.a.Il Sole 24 Ore S.p.a. was fined by the Garante EUR 40,000 for publishing a court order containing the personal data of an adopted minor. The authority also found an incomplete and delayed response to a data access request.ITGaranteGDPR€40,000
18 Jul 2023Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest MilaneseThe Garante fined Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest Milanese 12,000 EUR for a data breach. Personal data was accessed without negative consequences for the data subjects. The organization took measures to prevent similar violations in the future.ITGaranteGDPR€12,000
15 Dec 2011Casa di cura Villa Domelia s.r.l.Casa di cura Villa Domelia s.r.l. was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code.ITGaranteGDPR€20,000
16 May 2018Greco LuigiGreco Luigi, a general practitioner, was fined for failing to implement minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
20 Oct 2022Comune di SalentoComune di Salento was fined for unlawful processing of personal data through video surveillance systems. The authority found that retention periods for surveillance images were not set and that free access to personal data was not ensured, breaching GDPR transparency and access rights.ITGaranteGDPR€12,000
26 Oct 2023Regione LombardiaThe Garante fined Regione Lombardia EUR 20,000 for improperly publishing the personal data of numerous workers online. The disclosed information also included health-related data, which breached privacy rules.ITGaranteGDPR€20,000