Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Apr 2022Società Ospedale San Raffaele s.r.l.The Garante fined Società Ospedale San Raffaele s.r.l. EUR 70,000 for making online medical reports accessible to other patients. The case involved a breach of personal data protection and confidentiality of health information.ITGaranteGDPR€70,000
19 Nov 2017Superbeton S.p.a.Superbeton S.p.a. was fined 20,000 EUR by the Garante for failing to properly notify the use of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations.ITGaranteGDPR€20,000
17 Nov 2010Azienda trasporti di MessinaAzienda trasporti di Messina was fined 20,000 EUR by the Garante for processing sensitive personal data without providing the required information notice and without obtaining consent from the data subjects. The case concerns breaches of core transparency and lawful-processing obligations.ITGaranteGDPR€20,000
07 May 2015Provincia di FrosinoneProvincia di Frosinone was fined for failing to update the Security Policy Document (DPS) for several years. The authority found this to be a breach of security measures required under the Italian Data Protection Code.ITGaranteGDPR€10,000
06 Apr 2017Regione AbruzzoThe Garante fined Regione Abruzzo EUR 20,000 for unlawfully publishing lists on its website that revealed candidates' health status. The case involved the disclosure of sensitive personal data relating to individuals with disabilities.ITGaranteGDPR€20,000
26 Apr 2018Comune di DerutaThe Municipality of Deruta was fined 10,000 EUR for unlawfully providing lists of personal data of residents born in 1994–1996 to a private educational institution. The recipient was not entitled to receive the data under public utility exceptions.ITGaranteGDPR€10,000
04 Dec 2014Antonio FrazzanoAntonio Frazzano was fined EUR 4,000 by the Garante for sending promotional faxes without the required information notice and without obtaining recipient consent. The case concerned violations of data protection and direct marketing rules.ITGaranteGDPR€4,000
17 Dec 2020Roma CapitaleRoma Capitale was fined 500,000 EUR by the Garante for violations related to the processing of personal data in the TuPassi system. The authority also identified shortcomings in the information provided to users.ITGaranteGDPR€500,000
29 Apr 2026Nuova Corrente S.r.l.Nuova Corrente S.r.l. was fined EUR 15,000 by the Garante for making promotional calls without a valid legal basis. The authority found this to be a breach of GDPR lawfulness principles.ITGaranteGDPR€15,000
23 Jul 2015Giuseppe De MartinoGiuseppe De Martino was fined EUR 2,400 by the Garante for failing to provide adequate information on the processing of personal data through a website form and a video surveillance system. The authority found a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
12 Dec 2024Ambiente 2000 S.r.l.Ambiente 2000 S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company required employees to disclose passwords to their work email and files containing personal data, in breach of the GDPR.ITGaranteGDPR€20,000
21 Mar 2024Regione LazioThe Garante fined Regione Lazio EUR 120,000 for inadequate security measures that led to attempted unauthorized access to user accounts. The authority found a breach of GDPR requirements on data protection and processing security.ITGaranteGDPR€120,000
30 Jun 2011Porto di Tropea s.p.a.Porto di Tropea s.p.a. was fined by the Garante 10,000 EUR for failing to provide adequate information about video surveillance. The authority also found that data processors were not formally appointed for customer data collected through mooring contracts.ITGaranteGDPR€10,000
04 Apr 2019Ordinanza ingiunzione - 4 aprile 2019 [9117119]A municipal councillor was fined by the Garante for unlawfully disclosing personal data obtained from a document without legal justification. The authority found a breach of the principles of lawful processing and data protection.ITGaranteGDPR€4,000
10 Apr 2025Aliseo s.r.l.Aliseo s.r.l. was fined by the Garante for operating a video surveillance system without proper notice and for monitoring employees, including audio recording. The authority found the monitoring disproportionate to the stated security purpose.ITGaranteGDPR€5,000
09 Oct 2014Comune di UdineThe Municipality of Udine was fined 14,000 EUR by the Garante. The authority found that the Security Policy Document (DPS) had not been updated from 2005 to 2011, which breached data protection rules.ITGaranteGDPR€14,000
25 Feb 2016Associazione sportivo dilettantistica Feriolo Sporting ClubFeriolo Sporting Club was fined by the Garante 14,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority also found that recorded images were retained longer than permitted.ITGaranteGDPR€14,400
02 Apr 2015Ales Groupe Italia S.p.A.Ales Groupe Italia S.p.A. was fined EUR 20,000 by the Garante for violations related to data processing on its website. Users were asked to provide personal data without proper consent mechanisms.ITGaranteGDPR€20,000
12 Oct 2023S.T.A. Società Trattamento Acque s.r.l.S.T.A. Società Trattamento Acque s.r.l. was fined €75,000 by the Garante. The authority found a breach of Article 15 GDPR after the company failed to respond to an employee's request for access to professional training records.ITGaranteGDPR€75,000
27 Nov 2024Faro di RomaFaro di Roma was fined 15,000 EUR by the Garante for failing to comply with data protection rules. The case concerned the failure to honor requests for erasure and rectification of personal data linked to a judicial matter.ITGaranteGDPR€15,000