Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Mar 2018Carriere Italia s.r.l.Carriere Italia s.r.l. was fined for processing personal data revealing health status without notifying the Garante. The authority also found that required information was not provided to data subjects in job advertisements.ITGaranteGDPR€10,400
11 Mar 2021Plurima s.r.l.Plurima s.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned unsolicited promotional calls made to individuals whose consent was not recorded in the consent database. This conduct breached GDPR requirements for marketing-related processing.ITGaranteGDPR€5,000
23 Nov 2017Famicord Italia s.r.l.Famicord Italia s.r.l. was fined by the Garante for processing personal data relating to health without notifying the authority. The company also collected personal data through its website without providing the required privacy notice.ITGaranteGDPR€22,400
23 Nov 2017Foschini Mauro e Banca Nazionale del Lavoro S.p.A.Foschini Mauro and Banca Nazionale del Lavoro S.p.A. were fined by the Garante 4,000 EUR for breaches of data protection rules. The case concerned non-compliance with provisions of the Italian Privacy Code.ITGaranteGDPR€4,000
07 Mar 2024Centro Riparazioni Piacentino S.p.A.Centro Riparazioni Piacentino S.p.A. was fined by the Garante for continuing to operate individual company accounts months after employment ended and for accessing messages without proper deletion. The authority also found inadequate information and insufficient access rights for former employees.ITGaranteGDPR€20,000
15 Dec 2022Assiteca S.p.A.Assiteca S.p.A. was fined EUR 120,000 by the Garante for violations related to the processing of personal data for marketing purposes. The authority also found inadequate responses to data subject requests. The case highlights the need for proper handling of individual rights and GDPR-compliant marketing practices.ITGaranteGDPR€120,000
02 Apr 2015Comune di FolloComune di Follo was fined for unlawfully communicating personal data of children under three years old to a private company. The authority found this breached Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
15 Apr 2021Ordine degli Avvocati di LagonegroOrdine degli Avvocati di Lagonegro was fined EUR 3,000 by the Garante for publishing the content of a PEC email on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
23 May 2019Ordinanza ingiunzione - 23 maggio 2019 [9124593]The Garante imposed a fine of EUR 1,250 for the loss of medical documentation related to a patient's health assessment. The records were not found in either paper or electronic form, which constituted a breach of data protection rules.ITGaranteGDPR€1,250
06 Oct 2022Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante in the amount of 10,000 EUR for failing to respond to a data access request. The authority found a breach of Article 15 of the GDPR.ITGaranteGDPR€10,000
19 Mar 2015Provincia di PisaProvincia di Pisa was fined €10,000 by the Garante. The authority found that employees at the employment center were not designated as data processing officers, resulting in insufficient security measures for handling personal data.ITGaranteGDPR€10,000
17 Dec 2020Comune di Santo Stefano BelboComune di Santo Stefano Belbo was fined for unlawfully disclosing personal data, including names and legal information, on its website without a proper legal basis. The case concerned the publication of data that should not have been made publicly available.ITGaranteGDPR€4,000
01 Dec 2022Comune di Reggio EmiliaThe Municipality of Reggio Emilia was fined 8,000 EUR by the Garante for unlawfully publishing personal data, including health information, of a former employee on its website. The case concerned an unauthorized disclosure of sensitive information in breach of data protection rules.ITGaranteGDPR€8,000
27 May 2021Intesa Sanpaolo s.p.a.Intesa Sanpaolo s.p.a. was fined by the Garante in the amount of 200,000 EUR for unlawfully communicating banking data to an unauthorized third party. The case concerned breaches of data protection principles, including lawfulness and restricted access to information.ITGaranteGDPR€200,000
20 Jun 2024Max & Mix Ferrara s.r.l.Max & Mix Ferrara s.r.l. was fined €5,000 by the Garante for operating a video surveillance system with 32 cameras without the required informational signage. The authority found this to be a breach of GDPR information obligations.ITGaranteGDPR€5,000
04 Jun 2025INTS Italia S.r.l.INTS Italia S.r.l. was fined 15,000 EUR by the Garante for failing to provide employees with adequate information on data protection and for not responding to data access requests. The authority found that the company breached core GDPR principles.ITGaranteGDPR€15,000
09 Jul 2020Wind Tre S.p.A.Wind Tre S.p.A. was fined by the Garante 16,729,600 EUR for carrying out promotional activities without ensuring that contacts respected the wishes of individuals who did not want to receive marketing communications. The case concerns GDPR requirements on consent and the right to object to direct marketing.ITGaranteGDPR€16,729,000
12 Feb 2015Enescu Georgiana OfeliaEnescu Georgiana Ofelia was fined 2,400 EUR by the Italian supervisory authority Garante. The case concerned failure to provide data subjects with the required information about video surveillance at the business premises, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
11 May 2017Laboratorio Villafranca sncLaboratorio Villafranca snc was fined EUR 20,000 by the Italian data protection authority, Garante. The case concerned a failure to properly notify data processing activities under the Italian data protection code.ITGaranteGDPR€20,000
16 Nov 2023Autostrade per l’Italia S.p.A.Autostrade per l’Italia S.p.A. was fined by the Garante 100,000 EUR for failing to respond to employees' requests for access and rectification of personal data linked to annual severance pay calculations. The case concerns a failure to meet obligations for handling data subject rights requests.ITGaranteGDPR€100,000