Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Sept 2021GEDI News Network S.p.A.GEDI News Network S.p.A. was fined 30,000 EUR by the Garante for publishing personal data and detailed information about an individual involved in a workplace accident. The authority found a breach of data protection rules.ITGaranteGDPR€30,000
11 Jul 2013Patronato ENCALPatronato ENCAL was fined by the Garante 10,000 EUR for failing to implement minimum security measures in the assignment and use of authentication credentials for access to INPS databases. The breach concerned inadequate access control over systems containing sensitive data.ITGaranteGDPR€10,000
21 May 2025Menarini Silicon Biosystems SpAThe Garante imposed a 21,000 EUR fine on Menarini Silicon Biosystems SpA for violations related to personal data processing. The case involved inadequate safeguards in the use of algorithms to identify at-risk patients and online reports accessible to other patients.ITGaranteGDPR€21,000
11 Mar 2010Teleservizi s.r.l.Teleservizi s.r.l. was fined EUR 9,000 by the Garante for processing personal data without providing the required information to data subjects. The case concerned a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€9,000
06 Sept 2012Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined 34,000 EUR by the Garante. The authority found a breach of notification obligations under data protection rules.ITGaranteGDPR€34,000
19 Mar 2015Comune di MorinoComune di Morino was fined EUR 4,000 by the Garante for unlawfully disclosing the personal data of an individual applying for public housing to private entities without a legal basis. The authority found a breach of data protection rules.ITGaranteGDPR€4,000
16 Dec 2021Progetto Udire S.r.l.Progetto Udire S.r.l. was fined by the Garante 30,000 EUR. The authority found that the company sent unsolicited marketing communications without proper consent and failed to provide information on the origin of personal data when requested by the data subject.ITGaranteGDPR€30,000
19 Jul 2018BUTALI S.P.A.BUTALI S.P.A. was fined €16,000 by the Garante for activating a SIM card without providing the required privacy information and obtaining the customer’s specific consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€16,000
30 Apr 2026Intesa SanpaoloItaly’s data protection authority, Garante, fined Intesa Sanpaolo EUR 31.8 million. The sanction concerned serious failures in security and access management for personal data.ITGarante per la protezione dei dati personaliGDPR€31,800,000
12 Feb 2026Acea Energia S.p.A.Acea Energia S.p.A. was fined by the Garante 2,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy supply contracts, indicating significant deficiencies in data quality controls.ITGaranteGDPR€2,000,000
12 Nov 2015Cantiere 21 s.r.l.Cantiere 21 s.r.l. was fined by the Garante in the amount of 2,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority treated this as a breach of privacy rules.ITGaranteGDPR€2,400
07 Mar 2024Giuliana VinziThe Garante fined Giuliana Vinzi, owner of Rocky Bar, 2,000 EUR for operating video surveillance without the required notices to data subjects. The authority also found that authorization from the Labor Inspectorate was missing, resulting in a GDPR breach.ITGaranteGDPR€2,000
24 Sept 2015Lo.Gi.Ma. s.r.lLo.Gi.Ma. s.r.l was fined 4,800 EUR by the Italian Garante. The company collected personal data through its website without providing the required privacy notice, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€4,800
15 Jan 2015Comune di PloagheComune di Ploaghe was fined by the Garante for unlawfully publishing personal data on its website beyond the legally permitted period. The authority found a breach of data protection rules.ITGaranteGDPR€4,000
04 Jul 2013Global ResearchGlobal Research was fined EUR 12,800 by the Garante for sending unsolicited promotional faxes without the required information and consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€12,800
07 May 2015Nappo Nicola JolandaNappo Nicola Jolanda was fined EUR 45,000 by the Garante for activating 37 phone cards in the names of 15 individuals without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€45,000
19 Sept 2013Cooperativa di servizi AggregoCooperativa di servizi Aggrego was fined €6,400 by the Garante. The case concerned the sending of unsolicited promotional faxes without prior consent, in breach of data protection rules.ITGaranteGDPR€6,400
05 Mar 2015Comune di CapaccioComune di Capaccio was fined for unlawfully publishing sensitive personal data revealing health conditions on its institutional website. The authority found this to be a breach of privacy and data protection rules.ITGaranteGDPR€10,000
07 Feb 2013Edipro s.a.s.Edipro s.a.s. was fined by the Garante in the amount of EUR 100,000 for violations related to unsolicited telemarketing. The authority also cited the indiscriminate collection and communication of personal data.ITGaranteGDPR€100,000
09 Jun 2022Cribis Credit Management s.r.l.Cribis Credit Management s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company unjustifiably communicated debtor information to third parties, in breach of GDPR Article 5.ITGaranteGDPR€10,000