Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 May 2018Parnofiello AntonellaParnofiello Antonella, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to a healthcare system.ITGaranteGDPR€10,000
06 Jul 2006Selework s.a.s.Selework s.a.s. was fined EUR 258 by the Garante for failing to provide candidates with adequate information about the processing of their personal data in job advertisements. The authority found a breach of Article 13 of the Codice Privacy.ITGaranteGDPR€258
26 Feb 2026Depac Società Cooperativa Sociale a r.l.Depac Società Cooperativa Sociale a r.l. was fined by the Garante EUR 15,000 for unauthorized processing of employees' biometric data. The case concerned the collection and storage of fingerprint data without proper consent or a valid legal basis.ITGaranteGDPR€15,000
18 Jul 2023Provvedimento del 18 luglio 2023 [9935503]A complaint was filed with the Garante concerning a surveillance system installed by an individual that may have captured footage of a public street. The authority found a GDPR breach and imposed a fine of EUR 400.ITGaranteGDPR€400
06 Jul 2006Korallina Tours s.r.l.Korallina Tours s.r.l. was fined EUR 2,582 by the Garante for sending unsolicited promotional emails. The case concerns a breach of data protection obligations, including the duty to provide information to the authority under applicable law.ITGaranteGDPR€2,582
15 Dec 2022Comune di BraccianoComune di Bracciano was fined EUR 6,000 by the Garante for violations related to the processing of personal data. The case involved failures to comply with data protection principles and improper legal bases for processing.ITGaranteGDPR€6,000
11 Jun 2015Quotidiano Il Tempo s.r.l.Quotidiano Il Tempo s.r.l. was fined by the Garante EUR 8,400 for processing personal data without providing adequate information to subscribers. The authority also found that the company used a video surveillance system without the simplified notice required under privacy rules.ITGaranteGDPR€8,400
08 May 2014Telextra s.r.l.Telextra s.r.l. was fined by the Garante for processing personal data from electronic communication operators' databases without consent. The authority also found non-compliance with previous orders and data protection requirements.ITGaranteGDPR€300,000
09 May 2018Ditta individuale “La Scuola della Salute di Francesco Parisi”The Garante imposed a 15,000 EUR fine on Ditta individuale “La Scuola della Salute di Francesco Parisi” for providing inadequate privacy information to clients and for related consent issues. The conduct was found to violate provisions of the privacy code.ITGaranteGDPR€15,000
27 Apr 2023Provvedimento del 27 aprile 2023 [9896468]A fine of EUR 400 was imposed for improper use of a video surveillance system that captured images of a public street without the required authorization. The case concerned a breach of personal data processing rules in the context of video monitoring.ITGaranteGDPR€400
23 May 2024Ordine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di MateraOrdine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di Matera was fined 3,500 EUR by the Garante. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization, in the handling of personal data.ITGaranteGDPR€3,500
17 Jul 2025Juna S.r.l.Juna S.r.l. was fined €25,000 by the Garante for making repeated unwanted and fraudulent promotional calls to individuals. The conduct breached data protection principles, including lawful and fair processing requirements.ITGaranteGDPR€25,000
13 Feb 2007Asl Alto MoliseAsl Alto Molise was fined 10,000 EUR by the Garante for failing to notify data processing activities related to health diagnosis, treatment, and prevention within the required timeframe. The breach violated the Italian Data Protection Code.ITGaranteGDPR€10,000
09 Oct 2025Ordine delle Professioni Infermieristiche di PisaOrdine delle Professioni Infermieristiche di Pisa was fined by the Garante 16,000 EUR for breaches of data protection principles. The authority cited non-compliance with lawfulness, fairness, transparency, and data minimization requirements.ITGaranteGDPR€16,000
27 Jun 2013REY2MOND S.n.c. di Reymond Luciano & C.REY2MOND S.n.c. was fined EUR 4,800 by the Garante for collecting personal data through online forms without providing the required privacy notice. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€4,800
31 Jan 2013Edizioni associative srlEdizioni associative srl was fined EUR 16,000 by the Garante. The authority found that the company sent unsolicited promotional emails without proper consent, breaching data protection rules.ITGaranteGDPR€16,000
15 Apr 2021Società triveneta di chirurgiaSocietà triveneta di chirurgia was fined EUR 2,000 by the Garante for processing personal data without meeting the requirements of lawfulness, fairness, and transparency. The authority also found a breach of the data minimization principle.ITGaranteGDPR€2,000
15 Jun 2017Azienda Policlinico Umberto IAzienda Policlinico Umberto I was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate data processing officers and provide them with the necessary instructions, breaching minimum security measures under the Italian Data Protection Code.ITGaranteGDPR€10,000
22 Jun 2023Autostrade per l’Italia S.p.A.Autostrade per l’Italia S.p.A. was fined by the Garante EUR 1,000,000 for violations linked to an application that processed users’ personal data. The app was used to handle refunds of highway ticket costs for delays caused by construction works.ITGaranteGDPR€1,000,000
13 May 2021Artemisia s.p.a.Artemisia s.p.a. was fined EUR 100,000 by the Garante for GDPR breaches in data processing. The violations concerned consent, information notices, and the handling of health data.ITGaranteGDPR€100,000