Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 May 2023Grizzaffi Management S.r.l.Grizzaffi Management S.r.l. was fined by the Garante in the amount of 10,000 EUR for sending unsolicited promotional emails without recipient consent. The conduct breached GDPR rules on electronic marketing and consent for commercial communications.ITGaranteGDPR€10,000
23 Jan 2008Laboratorio di analisi cliniche Pasini MarioLaboratorio di analisi cliniche Pasini Mario was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code.ITGaranteGDPR€10,000
14 Jul 2011Il Tarì società consortile per azioniIl Tarì società consortile per azioni was fined €30,000 by the Garante for failing to provide adequate information and notification about the processing of personal data using biometric systems. The case concerned a breach of the Italian Data Protection Code.ITGaranteGDPR€30,000
29 Sept 2011Agenzia per le erogazioni in agricoltura (AGEA)The Italian Data Protection Authority fined Agenzia per le erogazioni in agricoltura (AGEA) EUR 40,000 for violations related to the processing of personal data within the National Agricultural Information System (Sian). The case concerned compliance of the processing activities with personal data protection requirements.ITGaranteGDPR€40,000
03 Oct 2013Eventi Doc di Myriam VallegraEventi Doc di Myriam Vallegra was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned failure to provide adequate information to data subjects, in breach of the Italian Privacy Code.ITGaranteGDPR€2,400
31 May 2018Mingardi Medical Center s.r.l.Mingardi Medical Center s.r.l. was fined by the Garante in the amount of EUR 86,000 for making unsolicited promotional calls. The conduct breached data protection rules governing telemarketing activities.ITGaranteGDPR€86,000
06 Sept 2012One Italia S.p.A.One Italia S.p.A. was fined €20,000 by the Garante for sending promotional MMS messages without obtaining prior consent from recipients. The conduct breached Articles 23 and 130 of the Italian Data Protection Code.ITGaranteGDPR€20,000
22 Nov 2012Synergo s.r.l.Synergo s.r.l. was fined by the Italian Garante for failing to notify the processing of sensitive health data. The case involved information on HIV status and infectious diseases, which should have been notified under the Italian data protection code.ITGaranteGDPR€40,000
02 Mar 2023Razmataz Live S.r.l.Razmataz Live S.r.l. was fined by the Garante 1,000 EUR for failing to take measures to mitigate or eliminate the consequences of a data protection breach linked to promotional activities. The authority also noted that informed consent for commercial communications was not ensured.ITGaranteGDPR€1,000
12 May 2022Singh Market S.r.l.The Garante fined Singh Market S.r.l. 2,000 EUR for operating a video surveillance system without the required informational signage. The authority found a breach of Article 13 GDPR.ITGaranteGDPR€2,000
29 Sept 2021GEDI News Network S.p.A.GEDI News Network S.p.A. was fined 30,000 EUR by the Garante for publishing personal data and detailed information about an individual involved in a workplace accident. The authority found a breach of data protection rules.ITGaranteGDPR€30,000
11 Jul 2013Patronato ENCALPatronato ENCAL was fined by the Garante 10,000 EUR for failing to implement minimum security measures in the assignment and use of authentication credentials for access to INPS databases. The breach concerned inadequate access control over systems containing sensitive data.ITGaranteGDPR€10,000
21 May 2025Menarini Silicon Biosystems SpAThe Garante imposed a 21,000 EUR fine on Menarini Silicon Biosystems SpA for violations related to personal data processing. The case involved inadequate safeguards in the use of algorithms to identify at-risk patients and online reports accessible to other patients.ITGaranteGDPR€21,000
11 Mar 2010Teleservizi s.r.l.Teleservizi s.r.l. was fined EUR 9,000 by the Garante for processing personal data without providing the required information to data subjects. The case concerned a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€9,000
06 Sept 2012Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined 34,000 EUR by the Garante. The authority found a breach of notification obligations under data protection rules.ITGaranteGDPR€34,000
19 Mar 2015Comune di MorinoComune di Morino was fined EUR 4,000 by the Garante for unlawfully disclosing the personal data of an individual applying for public housing to private entities without a legal basis. The authority found a breach of data protection rules.ITGaranteGDPR€4,000
16 Dec 2021Progetto Udire S.r.l.Progetto Udire S.r.l. was fined by the Garante 30,000 EUR. The authority found that the company sent unsolicited marketing communications without proper consent and failed to provide information on the origin of personal data when requested by the data subject.ITGaranteGDPR€30,000
19 Jul 2018BUTALI S.P.A.BUTALI S.P.A. was fined €16,000 by the Garante for activating a SIM card without providing the required privacy information and obtaining the customer’s specific consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€16,000
12 Feb 2026Acea Energia S.p.A.Acea Energia S.p.A. was fined by the Garante 2,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy supply contracts, indicating significant deficiencies in data quality controls.ITGaranteGDPR€2,000,000
12 Nov 2015Cantiere 21 s.r.l.Cantiere 21 s.r.l. was fined by the Garante in the amount of 2,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority treated this as a breach of privacy rules.ITGaranteGDPR€2,400