Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
18 Mar 2018Cristiano PanepintoCristiano Panepinto was fined €26,000 by the Garante for sending promotional emails without obtaining users’ free and specific consent. The conduct breached Article 130 of the Italian Privacy Code.ITGaranteGDPR€26,000
09 Dec 2010Bios s.p.a.Bios s.p.a. was fined by the Italian Garante for failing to provide adequate and timely information about the processing of personal data through a video surveillance system. The conduct breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
25 Jun 2015Azienda di Servizi per la persona "Carlo Pezzani" di VogheraThe company published the personal data of five guests on its website without a legal basis. This breached privacy rules and led to a fine imposed by the Garante.ITGaranteGDPR€4,000
15 Nov 2012Dusty s.r.l.Dusty s.r.l. was fined by the Italian Garante 66,000 EUR for implementing a biometric data collection system for employee attendance without properly appointing data processing officers and without obtaining the required consent. The authority found violations of several provisions of the data protection code.ITGaranteGDPR€66,000
12 Feb 2015Aloisio AngeloAloisio Angelo was fined EUR 25,000 by the Italian data protection authority, Garante. The case involved activating 15 phone cards in the names of 5 individuals without their knowledge, which breached data protection rules.ITGaranteGDPR€25,000
17 Dec 2015Caaf Cgil Sardegna srlCaaf Cgil Sardegna srl was fined by the Garante 12,000 EUR for failing to provide the required privacy notice on its website. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€12,000
02 Dec 2021La Duomo S.r.l.s.La Duomo S.r.l.s. was fined EUR 20,000 by the Garante for sending unsolicited promotional SMS messages without valid consent. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€20,000
20 Oct 2022Comune di Calvi RisortaThe Municipality of Comune di Calvi Risorta was fined 2,000 EUR by the Garante. The sanction resulted from a delayed response to the supervisory authority's request for information, which breached data protection rules.ITGaranteGDPR€2,000
29 Nov 2018Wind Tre S.p.A.Wind Tre S.p.A. was fined EUR 600,000 by the Garante for unsolicited promotional calls and SMS. The authority found breaches of several provisions of the Italian Data Protection Code.ITGaranteGDPR€600,000
10 Nov 2022Conservatorio di Musica S. Cecilia di RomaThe Conservatorio di Musica S. Cecilia di Roma was fined €6,000 by the Garante. The authority found unlawful processing of personal data contained in an audio/video recording used in disciplinary proceedings against a student without a lawful basis.ITGaranteGDPR€6,000
18 Sept 2014Blue Dream Hotel s.r.l.Blue Dream Hotel s.r.l. was fined EUR 2,400 by the Garante for processing personal data related to job applications without providing the required privacy notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
29 Apr 2025Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.Versilmagra Immobiliare was fined EUR 2,000 by the Garante. The authority found that the company sent unsolicited communications via WhatsApp without proper consent and did not facilitate the exercise of data subject rights.ITGaranteGDPR€2,000
13 Jul 2016Gruppo Nadine s.r.l.Gruppo Nadine s.r.l. was fined by the Garante in the amount of 2,400 EUR for inadequate notices in its surveillance system. The notices did not include the name of the data controller, contrary to the privacy code requirements.ITGaranteGDPR€2,400
13 Jul 2006Ministero dell'istruzione (Ufficio regionale per la Campania)The Campania Regional Office of the Ministry of Education was fined by the Garante for failing to provide requested information and documents. The authority found this to be a breach of data protection rules.ITGaranteGDPR€2,582
29 Apr 2021Comune di TriesteComune di Trieste was fined for the unauthorized disclosure of personal data relating to individuals involved in accidents, including names, damage details, and compensation amounts. The data was improperly accessible, constituting a breach of GDPR requirements.ITGaranteGDPR€45,000
11 Feb 2021Azienda Unità Sanitaria Locale di ParmaAzienda Unità Sanitaria Locale di Parma was fined by the Garante €10,000 for improper handling of sensitive personal data. The violation was linked to an occasional malfunction of its IT system, which led to improper data processing.ITGaranteGDPR€10,000
28 Feb 2019Casinò di Venezia Meeting & Dining S.r.l.Casinò di Venezia Meeting & Dining S.r.l. was fined EUR 4,000 by the Garante. The authority found that adequate security measures had not been implemented, in breach of Article 33 of the Italian Privacy Code.ITGaranteGDPR€4,000
27 Jan 2021Powerplay S.r.l.Powerplay S.r.l. was fined by the Garante for making unsolicited promotional calls despite the recipient's clear request not to receive further communications. The company failed to place the number on a blacklist, which breached data protection rules.ITGaranteGDPR€20,000
06 Dec 2012Assicurazioni Generali s.p.a.Assicurazioni Generali s.p.a. was fined 40,000 EUR by the Garante for making an unsolicited promotional phone call. The call was placed despite the recipient's prior objection to the processing of personal data for marketing purposes.ITGaranteGDPR€40,000
01 Sept 2022Liceo Statale "Edoardo Amaldi” di Alzano LombardoLiceo Statale “Edoardo Amaldi” was fined EUR 4,000 by the Garante for violations related to the processing of personal data, including sensitive data. The authority found that the processing lacked a proper legal basis and adequate safeguards.ITGaranteGDPR€4,000