Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jul 2015Impresa Edile di Alagna GiuseppeThe company was fined EUR 2,400 by the Garante for failing to provide the required privacy notice on its website. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
28 Apr 2022Direzione Didattica Statale 1° Circolo–EboliDirezione Didattica Statale 1° Circolo–Eboli was fined by the Garante 1,500 EUR for breaching the GDPR principles of lawfulness, fairness, and transparency in data processing. The case concerned improper processing of personal data under the GDPR.ITGaranteGDPR€1,500
20 Nov 2014Impresa costruzioni edili e stradali – dr. Ing. Michele Bianchi & C. - s.r.l.The company was fined by the Garante 2,400 EUR for failing to provide the required privacy notice to data subjects when collecting personal data through a web form on its website. The case concerned a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
10 Apr 2025Azienda Ospedaliera Universitaria Integrata VeronaAzienda Ospedaliera Universitaria Integrata Verona was fined by the Garante for failing to adequately protect personal data. After a ransomware attack, 612 GB of data was published on the dark web, indicating serious security shortcomings.ITGaranteGDPR€10,000
18 Jul 2023Università Telematica E-CampusUniversità Telematica E-Campus was fined EUR 75,000 by the Garante. The authority found that the university sent promotional SMS messages without consent and failed to respond to data deletion requests. These actions breached GDPR requirements.ITGaranteGDPR€75,000
11 Apr 2013Kihria S.r.l.Kihria S.r.l. was fined 2,400 EUR by the Garante for failing to provide adequate information about data collection through a website contact form. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
31 May 2018Autosat S.p.A.Autosat S.p.A. was fined by the Italian Garante in the amount of EUR 30,000 for breaches of data protection rules. The case concerned the handling of personal data and the security measures used in the company’s IT systems.ITGaranteGDPR€30,000
12 Nov 2015Giuseppina GhezziGiuseppina Ghezzi was fined by the Garante 26,000 EUR for registering 100 phone cards to an unaware third party. The required data protection information was not provided and consent was not obtained, constituting a breach of data protection law.ITGaranteGDPR€26,000
13 Feb 2007Asl Centro MoliseAsl Centro Molise was fined by the Garante for processing personal data, including genetic and biometric data, without the required notification. The breach concerned obligations under the Italian data protection code.ITGaranteGDPR€10,000
21 Mar 2024Imperatori Immobiliari s.r.l.The Garante fined Imperatori Immobiliari s.r.l. 4,000 EUR for operating a surveillance system without the required informational signage. The authority treated this as a breach of data protection rules.ITGaranteGDPR€4,000
13 Jul 2006Comune di NapoliThe Municipality of Naples was fined by the Garante in the amount of 2,582 EUR. The sanction resulted from failing to provide requested information and documents, which constituted a breach of data protection rules.ITGaranteGDPR€2,582
05 May 2016S.I.S Società Italiana Scommesse s.r.lS.I.S Società Italiana Scommesse s.r.l was fined EUR 2,400 by the Garante. The authority found that the company failed to provide adequate simplified information about its video surveillance system, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
18 Dec 2025Provvedimento del 18 dicembre 2025 [10210431]A professional sent a communication containing personal data to an institutional email address, which breached data protection rules. The Garante imposed a fine of EUR 1,000.ITGaranteGDPR€1,000
31 Jan 2019Istituto di Istruzione Superiore C.Istituto di Istruzione Superiore C. was fined EUR 4,000 by the Garante for publishing sensitive personal data, including health information, on its website. The conduct breached data protection requirements.ITGaranteGDPR€4,000
21 Jun 2018Azienda Semplice s.r.l.Azienda Semplice s.r.l. was fined by the Garante 16,000 EUR for unlawful processing of personal data used to place promotional calls to a private residential phone number without consent. The case concerns a lack of a lawful basis for marketing contact and a breach of data protection rules.ITGaranteGDPR€16,000
05 Jul 2017Klik s.r.l.Klik s.r.l. was fined EUR 30,000 by the Garante for retaining telephone traffic data for more than 24 months. The authority found this to be a breach of data protection rules.ITGaranteGDPR€30,000
12 Feb 2015Comune di JesiComune di Jesi was fined for unlawfully publishing personal data related to a public competition on its website without a legislative or regulatory basis. The authority found that this breached data protection rules.ITGaranteGDPR€4,000
14 Sept 2006De.Mo. s.r.l.De.Mo. s.r.l. was fined 3,000 EUR by the Garante for failing to provide the required information to data subjects under Article 13 of the Italian Data Protection Code. The breach occurred in connection with the company’s marketing activities.ITGaranteGDPR€3,000
28 Sept 2023Asl Napoli 3 SudThe Garante fined Asl Napoli 3 Sud EUR 30,000 for inadequate security measures that led to a data breach. The incident caused limited service disruption.ITGaranteGDPR€30,000
08 Jul 2015Perez s.r.l.Perez s.r.l. was fined by the Garante for failing to provide the required privacy notice to users whose personal data were collected through its website. This constituted a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400