Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Apr 2013PLD srlPLD srl was fined €100,000 by the Italian Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information.ITGaranteGDPR€100,000
29 Sept 2021Solera Italia s.r.l.Solera Italia s.r.l. was fined EUR 10,000 by the Garante for continuing to use an employee's email account after the employment ended. The authority found that the company did not provide proper information about this processing.ITGaranteGDPR€10,000
19 May 2010Roadhouse Grill Italia s.r.l.Roadhouse Grill Italia s.r.l. was fined 6,000 EUR by the Garante for failing to provide proper data protection notices to individuals through signage for its video surveillance system. The authority found a breach of data protection rules.ITGaranteGDPR€6,000
16 May 2018Paesano FrancescoPaesano Francesco was fined EUR 60,000 by the Garante for activating six phone cards without the consent of the individuals concerned. The case concerns a breach of data protection rules and the absence of a valid legal basis for processing.ITGaranteGDPR€60,000
08 Mar 2018Yahoo! Emea Limited oggi Oath (Emea) LimitedYahoo! Emea Limited, now Oath (Emea) Limited, was fined 160,000 EUR by the Garante. The authority found that the company failed to comply with a request to remove specific URLs containing personal information from Yahoo! Search.ITGaranteGDPR€160,000
09 Nov 2017Società Alberghi Circeo s.r.l.Società Alberghi Circeo s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company failed to appoint data processing officers for employees handling personal data, in breach of Article 33 of the Italian Data Protection Code.ITGaranteGDPR€10,000
16 Feb 2011Athena Research s.r.l.Athena Research s.r.l. was fined 6,000 EUR by the Garante for sending unsolicited commercial faxes without the recipients' explicit consent. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code.ITGaranteGDPR€6,000
23 Mar 2023Azienda 1 di SassariThe Garante imposed a fine of 4,000 EUR on Azienda 1 di Sassari for violations related to the processing of personal data, including health data. The authority found that adequate security measures were not in place for this processing.ITGaranteGDPR€4,000
10 Apr 2025Unione Montana Appennino Parma EstUnione Montana Appennino Parma Est was fined by the Italian supervisory authority, Garante, in the amount of EUR 8,000. The authority found a lack of required transparency in data processing and failure to carry out a data protection impact assessment for workplace video surveillance.ITGaranteGDPR€8,000
05 Mar 2015Comune di Acquarica del CapoThe Municipality of Acquarica del Capo was fined 10,000 EUR by the Garante for unlawfully publishing personal data revealing health information on its website. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€10,000
28 Apr 2022Società Ospedale San Raffaele s.r.l.The Garante fined Società Ospedale San Raffaele s.r.l. EUR 70,000 for making online medical reports accessible to other patients. The case involved a breach of personal data protection and confidentiality of health information.ITGaranteGDPR€70,000
19 Nov 2017Superbeton S.p.a.Superbeton S.p.a. was fined 20,000 EUR by the Garante for failing to properly notify the use of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations.ITGaranteGDPR€20,000
17 Nov 2010Azienda trasporti di MessinaAzienda trasporti di Messina was fined 20,000 EUR by the Garante for processing sensitive personal data without providing the required information notice and without obtaining consent from the data subjects. The case concerns breaches of core transparency and lawful-processing obligations.ITGaranteGDPR€20,000
07 May 2015Provincia di FrosinoneProvincia di Frosinone was fined for failing to update the Security Policy Document (DPS) for several years. The authority found this to be a breach of security measures required under the Italian Data Protection Code.ITGaranteGDPR€10,000
06 Apr 2017Regione AbruzzoThe Garante fined Regione Abruzzo EUR 20,000 for unlawfully publishing lists on its website that revealed candidates' health status. The case involved the disclosure of sensitive personal data relating to individuals with disabilities.ITGaranteGDPR€20,000
26 Apr 2018Comune di DerutaThe Municipality of Deruta was fined 10,000 EUR for unlawfully providing lists of personal data of residents born in 1994–1996 to a private educational institution. The recipient was not entitled to receive the data under public utility exceptions.ITGaranteGDPR€10,000
04 Dec 2014Antonio FrazzanoAntonio Frazzano was fined EUR 4,000 by the Garante for sending promotional faxes without the required information notice and without obtaining recipient consent. The case concerned violations of data protection and direct marketing rules.ITGaranteGDPR€4,000
17 Dec 2020Roma CapitaleRoma Capitale was fined 500,000 EUR by the Garante for violations related to the processing of personal data in the TuPassi system. The authority also identified shortcomings in the information provided to users.ITGaranteGDPR€500,000
29 Apr 2026Nuova Corrente S.r.l.Nuova Corrente S.r.l. was fined EUR 15,000 by the Garante for making promotional calls without a valid legal basis. The authority found this to be a breach of GDPR lawfulness principles.ITGaranteGDPR€15,000
23 Jul 2015Giuseppe De MartinoGiuseppe De Martino was fined EUR 2,400 by the Garante for failing to provide adequate information on the processing of personal data through a website form and a video surveillance system. The authority found a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400