Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Sept 2010Regione PugliaRegione Puglia was fined EUR 40,000 by the Italian data protection authority, Garante. The case concerned the online publication of sensitive health data relating to disabled individuals, in breach of data protection rules.ITGaranteGDPR€40,000
18 Mar 2010Alma s.r.l.Alma s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 10,000 EUR. The case concerned the processing of personal data without the notification required under the Italian Data Protection Code.ITGaranteGDPR€10,000
10 Jun 2020Comune di MontevagoComune di Montevago was fined by the Garante 2,000 EUR for the unlawful online publication of personal data without an appropriate legal basis. The case concerned a breach of the principles of lawful processing and data protection in the public disclosure of information online.ITGaranteGDPR€2,000
29 Sept 2011Jenius Communication sasJenius Communication sas was fined by the Garante 8,000 EUR for sending an unsolicited promotional email. The case concerns a breach of data protection rules governing marketing communications.ITGaranteGDPR€8,000
07 Apr 2022ISWEB S.p.A.ISWEB S.p.A. was fined EUR 40,000 by the Italian supervisory authority, Garante. The authority found that the company failed to properly regulate its relationship with the hosting service provider in relation to data processing for Azienda ospedaliera di Perugia, in breach of Article 28 GDPR.ITGaranteGDPR€40,000
17 Apr 2026Comune di CogoletoComune di Cogoleto was fined EUR 4,000 by the Garante for failing to ensure transparency in data processing. The authority also found that no data protection impact assessment had been carried out, breaching the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
31 May 2017Unit Contact s.r.l.Unit Contact s.r.l. was fined €32,000 by the Italian authority Garante. The case concerned unsolicited promotional calls made without the required information notice and without obtaining consent, in breach of data protection rules.ITGaranteGDPR€32,000
20 Jan 2012Manage Consulting International s.r.l.Manage Consulting International s.r.l. was fined by the Italian Garante in the amount of 10,400 EUR. The sanction concerned sending unsolicited promotional faxes without proper consent and required information.ITGaranteGDPR€10,400
01 Jun 2023Provvedimento del 1° giugno 2023 [9909889]The Garante imposed a 10,000 EUR fine on a healthcare center for incorrectly sending automatic SMS reminders to a patient due to a data misattribution error. The case concerned GDPR provisions on data processing and security.ITGaranteGDPR€10,000
24 Oct 2013Balangero SerenaBalangero Serena was fined by the Garante in the amount of 4,000 EUR for non-compliance with data protection rules in the use of surveillance cameras at Murphy's Bar. The authority found that privacy notices for individuals under surveillance were inadequate.ITGaranteGDPR€4,000
27 Jan 2021Roma CapitaleRoma Capitale was fined EUR 10,000 by the Garante for publishing the personal data of a minor and the minor’s mother on its official website without a proper legal basis. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€10,000
06 Dec 2011Composad s.r.l.Composad s.r.l. was fined by the Garante €26,000 for processing personal data collected through its website without properly appointing a data processor. The case concerned a breach of data protection rules and related organizational obligations.ITGaranteGDPR€26,000
09 Feb 2011Futurgroup s.r.l.Futurgroup s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 9,000. The case concerned the failure to provide timely information to the data subject as required by the data protection code.ITGaranteGDPR€9,000
11 Apr 2019AD Sphera Group s.r.l.AD Sphera Group s.r.l. was fined EUR 2,400 by the Garante for failing to provide the required privacy notice on its website. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
22 Jun 2016Istituto Maria Angelica Miliziano s.r.l.Istituto Maria Angelica Miliziano s.r.l. was fined by the Garante 2,400 EUR for collecting users’ personal data through its website without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
06 Jul 2023Romagna Dolciumi s.r.l.Romagna Dolciumi s.r.l. was fined by the Garante in the amount of €10,000 for failing to provide an employee with access to their personal data. The authority also found that the company engaged a private investigative agency to carry out defensive investigations without proper authorization, in breach of GDPR requirements.ITGaranteGDPR€10,000
27 Jan 2022Circolo culturale “Ruian”Circolo culturale “Ruian” was fined EUR 2,000 by the Garante for operating a video surveillance system in breach of data protection rules. The cameras were not properly signposted, which failed to meet the required information obligations toward monitored individuals.ITGaranteGDPR€2,000
13 Dec 2012Studio Immobiliare Conca D'Oro s.r.l.Studio Immobiliare Conca D'Oro s.r.l. was fined by the Garante 6,400 EUR for making promotional phone calls without providing the required information notice and without obtaining consent. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€6,400
05 Dec 2013Associazione culturale KoalaAssociazione culturale Koala was fined 30,000 EUR by the Italian Garante. The case concerned the installation of a fingerprint recognition system for user access without providing the required information to the supervisory authority.ITGaranteGDPR€30,000
21 Mar 2018Ordinanza ingiunzione - 21 marzo 2018 [9004702]The Garante imposed a EUR 92,000 fine on a medical professional for processing the personal data of 23 patients without the required consent. The authority found a breach of privacy and data protection rules.ITGaranteGDPR€92,000