Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Apr 2025Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.Versilmagra Immobiliare was fined EUR 2,000 by the Garante. The authority found that the company sent unsolicited communications via WhatsApp without proper consent and did not facilitate the exercise of data subject rights.ITGaranteGDPR€2,000
13 Jul 2016Gruppo Nadine s.r.l.Gruppo Nadine s.r.l. was fined by the Garante in the amount of 2,400 EUR for inadequate notices in its surveillance system. The notices did not include the name of the data controller, contrary to the privacy code requirements.ITGaranteGDPR€2,400
13 Jul 2006Ministero dell'istruzione (Ufficio regionale per la Campania)The Campania Regional Office of the Ministry of Education was fined by the Garante for failing to provide requested information and documents. The authority found this to be a breach of data protection rules.ITGaranteGDPR€2,582
29 Apr 2021Comune di TriesteComune di Trieste was fined for the unauthorized disclosure of personal data relating to individuals involved in accidents, including names, damage details, and compensation amounts. The data was improperly accessible, constituting a breach of GDPR requirements.ITGaranteGDPR€45,000
11 Feb 2021Azienda Unità Sanitaria Locale di ParmaAzienda Unità Sanitaria Locale di Parma was fined by the Garante €10,000 for improper handling of sensitive personal data. The violation was linked to an occasional malfunction of its IT system, which led to improper data processing.ITGaranteGDPR€10,000
28 Feb 2019Casinò di Venezia Meeting & Dining S.r.l.Casinò di Venezia Meeting & Dining S.r.l. was fined EUR 4,000 by the Garante. The authority found that adequate security measures had not been implemented, in breach of Article 33 of the Italian Privacy Code.ITGaranteGDPR€4,000
27 Jan 2021Powerplay S.r.l.Powerplay S.r.l. was fined by the Garante for making unsolicited promotional calls despite the recipient's clear request not to receive further communications. The company failed to place the number on a blacklist, which breached data protection rules.ITGaranteGDPR€20,000
06 Dec 2012Assicurazioni Generali s.p.a.Assicurazioni Generali s.p.a. was fined 40,000 EUR by the Garante for making an unsolicited promotional phone call. The call was placed despite the recipient's prior objection to the processing of personal data for marketing purposes.ITGaranteGDPR€40,000
01 Sept 2022Liceo Statale "Edoardo Amaldi” di Alzano LombardoLiceo Statale “Edoardo Amaldi” was fined EUR 4,000 by the Garante for violations related to the processing of personal data, including sensitive data. The authority found that the processing lacked a proper legal basis and adequate safeguards.ITGaranteGDPR€4,000
08 Mar 2018Carriere Italia s.r.l.Carriere Italia s.r.l. was fined for processing personal data revealing health status without notifying the Garante. The authority also found that required information was not provided to data subjects in job advertisements.ITGaranteGDPR€10,400
11 Mar 2021Plurima s.r.l.Plurima s.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned unsolicited promotional calls made to individuals whose consent was not recorded in the consent database. This conduct breached GDPR requirements for marketing-related processing.ITGaranteGDPR€5,000
23 Nov 2017Famicord Italia s.r.l.Famicord Italia s.r.l. was fined by the Garante for processing personal data relating to health without notifying the authority. The company also collected personal data through its website without providing the required privacy notice.ITGaranteGDPR€22,400
23 Nov 2017Foschini Mauro e Banca Nazionale del Lavoro S.p.A.Foschini Mauro and Banca Nazionale del Lavoro S.p.A. were fined by the Garante 4,000 EUR for breaches of data protection rules. The case concerned non-compliance with provisions of the Italian Privacy Code.ITGaranteGDPR€4,000
07 Mar 2024Centro Riparazioni Piacentino S.p.A.Centro Riparazioni Piacentino S.p.A. was fined by the Garante for continuing to operate individual company accounts months after employment ended and for accessing messages without proper deletion. The authority also found inadequate information and insufficient access rights for former employees.ITGaranteGDPR€20,000
15 Dec 2022Assiteca S.p.A.Assiteca S.p.A. was fined EUR 120,000 by the Garante for violations related to the processing of personal data for marketing purposes. The authority also found inadequate responses to data subject requests. The case highlights the need for proper handling of individual rights and GDPR-compliant marketing practices.ITGaranteGDPR€120,000
02 Apr 2015Comune di FolloComune di Follo was fined for unlawfully communicating personal data of children under three years old to a private company. The authority found this breached Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
15 Apr 2021Ordine degli Avvocati di LagonegroOrdine degli Avvocati di Lagonegro was fined EUR 3,000 by the Garante for publishing the content of a PEC email on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
23 May 2019Ordinanza ingiunzione - 23 maggio 2019 [9124593]The Garante imposed a fine of EUR 1,250 for the loss of medical documentation related to a patient's health assessment. The records were not found in either paper or electronic form, which constituted a breach of data protection rules.ITGaranteGDPR€1,250
06 Oct 2022Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante in the amount of 10,000 EUR for failing to respond to a data access request. The authority found a breach of Article 15 of the GDPR.ITGaranteGDPR€10,000
19 Mar 2015Provincia di PisaProvincia di Pisa was fined €10,000 by the Garante. The authority found that employees at the employment center were not designated as data processing officers, resulting in insufficient security measures for handling personal data.ITGaranteGDPR€10,000