Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Jul 2016Ordine degli Ingegneri della Provincia di CasertaOrdine degli Ingegneri della Provincia di Caserta was fined by the Garante for failing to respond to requests for information about the processing of employees’ sensitive personal data. The authority found this to be a breach of data protection rules.ITGaranteGDPR€4,000
31 Aug 2023Ordine degli Avvocati di XXThe Garante fined the Ordine degli Avvocati di XX EUR 8,000 for unlawfully disclosing personal data without a legal basis. The authority found breaches of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€8,000
15 Apr 2021Ordine degli Avvocati di RomaOrdine degli Avvocati di Roma was fined €2,000 by the Garante for a significant delay in responding to a data subject access request. The case highlights a failure to meet the required timelines for handling access requests under data protection rules.ITGaranteGDPR€2,000
26 Mar 2026Ordine degli Avvocati di PiacenzaOrdine degli Avvocati di Piacenza was fined EUR 3,000 by the Garante for improper handling of disciplinary sanctions in its professional register. The authority found that the processing did not comply with data protection requirements.ITGaranteGDPR€3,000
23 Oct 2025Ordine degli Avvocati di LatinaOrdine degli Avvocati di Latina was fined EUR 15,000 by the Garante for unlawful, incorrect, and non-transparent processing of personal data. The authority also found a failure to ensure data minimization.ITGaranteGDPR€15,000
15 Apr 2021Ordine degli Avvocati di LagonegroOrdine degli Avvocati di Lagonegro was fined EUR 3,000 by the Garante for publishing the content of a PEC email on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
13 Apr 2023Ordine degli Avvocati di AnconaThe Garante fined the Ordine degli Avvocati di Ancona 20,000 EUR for violations related to data processing transparency and security. The authority found incorrect privacy notices and non-compliance with GDPR principles.ITGaranteGDPR€20,000
17 Dec 2020Ordine degli Assistenti Sociali della Regione LazioOrdine degli Assistenti Sociali della Regione Lazio was fined EUR 2,000 by the Garante. The authority found that the entity failed to respond to a request for access to personal data, which is a breach of GDPR Article 15.ITGaranteGDPR€2,000
23 May 2024Ordine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di MateraOrdine degli Architetti Pianificatori Paesaggisti e Conservatori della Provincia di Matera was fined 3,500 EUR by the Garante. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization, in the handling of personal data.ITGaranteGDPR€3,500
09 Jan 2014Ordinanza ingiunzione - 9 gennaio 2014 [4785574]The Garante imposed a fine of EUR 4,000 for sending promotional emails without prior valid consent from recipients. The case concerns a breach of data protection rules and electronic marketing requirements.ITGaranteGDPR€4,000
07 May 2015Ordinanza ingiunzione - 7 maggio 2015 [4226113]The Garante imposed a EUR 2,400 fine on the company for providing an inadequate privacy notice on its website contact form. The breach concerned the requirements of the Italian Data Protection Code.ITGaranteGDPR€2,400
04 Apr 2019Ordinanza ingiunzione - 4 aprile 2019 [9117119]A municipal councillor was fined by the Garante for unlawfully disclosing personal data obtained from a document without legal justification. The authority found a breach of the principles of lawful processing and data protection.ITGaranteGDPR€4,000
03 May 2018Ordinanza ingiunzione - 3 maggio 2018 [9023941]A fine of EUR 20,000 was imposed for failing to notify the Garante about the processing of geolocation data collected through GPS devices. The case concerns a breach of the Italian Data Protection Code.ITGaranteGDPR€20,000
02 Jul 2015Ordinanza ingiunzione - 2 luglio 2015 [4337649]The condominium administrator did not respond to requests for information related to a data protection complaint. Garante imposed a fine of EUR 4,000 for violating data protection rules.ITGaranteGDPR€4,000
02 Feb 2019Ordinanza ingiunzione - 2 febbraio 2019 [9100784]The Garante imposed an administrative fine for violating data protection rules. The case concerned retaining surveillance footage for longer than the permitted 7 days.ITGaranteGDPR€11,940
28 Jul 2022Ordinanza ingiunzione - 28 luglio 2022 [9813385]The Garante imposed a fine of EUR 1,000 on the website administrator for failing to remove or de-index a page containing a Corriere della Sera article about a judicial case involving the complainant's father. The authority found a violation of the right to be forgotten.ITGaranteGDPR€1,000
25 Nov 2021Ordinanza ingiunzione - 25 novembre 2021 [9733002]A healthcare professional was fined by the Garante EUR 30,000 for unlawfully disclosing a patient's personal data, including unpaid medical bills and health information, to third parties. The authority found that the processing lacked a legal basis and breached the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€30,000
23 May 2019Ordinanza ingiunzione - 23 maggio 2019 [9124593]The Garante imposed a fine of EUR 1,250 for the loss of medical documentation related to a patient's health assessment. The records were not found in either paper or electronic form, which constituted a breach of data protection rules.ITGaranteGDPR€1,250
22 May 2018Ordinanza ingiunzione - 22 maggio 2018 [9037459]A general practitioner failed to implement minimum security measures to protect patients' personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
22 May 2018Ordinanza ingiunzione - 22 maggio 2018 [9027240]A general practitioner was fined for failing to adopt minimum security measures in a health information system. The deficiencies allowed unauthorized access to the data.ITGaranteGDPR€10,000