Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Sept 2025G.Villa S.r.l.G.Villa S.r.l. was fined by the Garante EUR 22,500 for sending unsolicited promotional emails to an address not disclosed for marketing purposes. The company also failed to respond to the data subject's request for access to and deletion of personal data.ITGaranteGDPR€22,500
30 Jan 2020Comune di ColledaraComune di Colledara was fined EUR 4,000 by the Garante for publishing personal data in the provisional ranking of a competition on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
06 Feb 2014Regione PugliaRegione Puglia was fined EUR 20,000 by the Italian data protection authority, Garante. The breach involved unlawfully publishing health data of individuals with disabilities on its institutional website.ITGaranteGDPR€20,000
27 Mar 2025Comune di MilazzoThe Garante fined the Comune di Milazzo €3,600 for failing to provide adequate data protection information on its website. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€3,600
29 Apr 2009Altea Servizi s.r.l.Altea Servizi s.r.l. was fined for processing personal data without providing the required information notice, in connection with sending promotional faxes without consent. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
25 Nov 2021Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The hospital was fined by the Garante 50,000 EUR for unlawfully publishing on its website the personal data of participants in a competitive procedure, including health data. The authority found a breach of data protection principles.ITGaranteGDPR€50,000
17 Apr 2014SSTC srlSSTC srl was fined EUR 66,000 by the Italian authority Garante. The case concerned telemarketing activities carried out without the prior consent of the contacted individuals, in breach of data protection rules.ITGaranteGDPR€66,000
13 Dec 2018Ordinanza ingiunzione - 13 dicembre 2018 [9124641]The sole proprietorship acting as an agent for Western Union carried out unauthorized money transfers using personal data without consent. The authority found a breach of data protection rules and imposed a EUR 8,000 fine.ITGaranteGDPR€8,000
11 Feb 2021Comando generale del Corpo delle Capitanerie di porto-Guardia CostieraThe Garante imposed a €5,000 fine on the Comando generale del Corpo delle Capitanerie di porto-Guardia Costiera for inadequate data protection measures. The breach resulted in the unlawful disclosure of personal data on its website.ITGaranteGDPR€5,000
23 Sept 2010Regione PugliaRegione Puglia was fined EUR 40,000 by the Italian data protection authority, Garante. The case concerned the online publication of sensitive health data relating to disabled individuals, in breach of data protection rules.ITGaranteGDPR€40,000
18 Mar 2010Alma s.r.l.Alma s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 10,000 EUR. The case concerned the processing of personal data without the notification required under the Italian Data Protection Code.ITGaranteGDPR€10,000
10 Jun 2020Comune di MontevagoComune di Montevago was fined by the Garante 2,000 EUR for the unlawful online publication of personal data without an appropriate legal basis. The case concerned a breach of the principles of lawful processing and data protection in the public disclosure of information online.ITGaranteGDPR€2,000
29 Sept 2011Jenius Communication sasJenius Communication sas was fined by the Garante 8,000 EUR for sending an unsolicited promotional email. The case concerns a breach of data protection rules governing marketing communications.ITGaranteGDPR€8,000
07 Apr 2022ISWEB S.p.A.ISWEB S.p.A. was fined EUR 40,000 by the Italian supervisory authority, Garante. The authority found that the company failed to properly regulate its relationship with the hosting service provider in relation to data processing for Azienda ospedaliera di Perugia, in breach of Article 28 GDPR.ITGaranteGDPR€40,000
17 Apr 2026Comune di CogoletoComune di Cogoleto was fined EUR 4,000 by the Garante for failing to ensure transparency in data processing. The authority also found that no data protection impact assessment had been carried out, breaching the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
31 May 2017Unit Contact s.r.l.Unit Contact s.r.l. was fined €32,000 by the Italian authority Garante. The case concerned unsolicited promotional calls made without the required information notice and without obtaining consent, in breach of data protection rules.ITGaranteGDPR€32,000
20 Jan 2012Manage Consulting International s.r.l.Manage Consulting International s.r.l. was fined by the Italian Garante in the amount of 10,400 EUR. The sanction concerned sending unsolicited promotional faxes without proper consent and required information.ITGaranteGDPR€10,400
01 Jun 2023Provvedimento del 1° giugno 2023 [9909889]The Garante imposed a 10,000 EUR fine on a healthcare center for incorrectly sending automatic SMS reminders to a patient due to a data misattribution error. The case concerned GDPR provisions on data processing and security.ITGaranteGDPR€10,000
24 Oct 2013Balangero SerenaBalangero Serena was fined by the Garante in the amount of 4,000 EUR for non-compliance with data protection rules in the use of surveillance cameras at Murphy's Bar. The authority found that privacy notices for individuals under surveillance were inadequate.ITGaranteGDPR€4,000
27 Jan 2021Roma CapitaleRoma Capitale was fined EUR 10,000 by the Garante for publishing the personal data of a minor and the minor’s mother on its official website without a proper legal basis. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€10,000