Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Dec 2020Comune di Santo Stefano BelboComune di Santo Stefano Belbo was fined for unlawfully disclosing personal data, including names and legal information, on its website without a proper legal basis. The case concerned the publication of data that should not have been made publicly available.ITGaranteGDPR€4,000
01 Dec 2022Comune di Reggio EmiliaThe Municipality of Reggio Emilia was fined 8,000 EUR by the Garante for unlawfully publishing personal data, including health information, of a former employee on its website. The case concerned an unauthorized disclosure of sensitive information in breach of data protection rules.ITGaranteGDPR€8,000
27 May 2021Intesa Sanpaolo s.p.a.Intesa Sanpaolo s.p.a. was fined by the Garante in the amount of 200,000 EUR for unlawfully communicating banking data to an unauthorized third party. The case concerned breaches of data protection principles, including lawfulness and restricted access to information.ITGaranteGDPR€200,000
20 Jun 2024Max & Mix Ferrara s.r.l.Max & Mix Ferrara s.r.l. was fined €5,000 by the Garante for operating a video surveillance system with 32 cameras without the required informational signage. The authority found this to be a breach of GDPR information obligations.ITGaranteGDPR€5,000
04 Jun 2025INTS Italia S.r.l.INTS Italia S.r.l. was fined 15,000 EUR by the Garante for failing to provide employees with adequate information on data protection and for not responding to data access requests. The authority found that the company breached core GDPR principles.ITGaranteGDPR€15,000
09 Jul 2020Wind Tre S.p.A.Wind Tre S.p.A. was fined by the Garante 16,729,600 EUR for carrying out promotional activities without ensuring that contacts respected the wishes of individuals who did not want to receive marketing communications. The case concerns GDPR requirements on consent and the right to object to direct marketing.ITGaranteGDPR€16,729,000
12 Feb 2015Enescu Georgiana OfeliaEnescu Georgiana Ofelia was fined 2,400 EUR by the Italian supervisory authority Garante. The case concerned failure to provide data subjects with the required information about video surveillance at the business premises, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
11 May 2017Laboratorio Villafranca sncLaboratorio Villafranca snc was fined EUR 20,000 by the Italian data protection authority, Garante. The case concerned a failure to properly notify data processing activities under the Italian data protection code.ITGaranteGDPR€20,000
16 Nov 2023Autostrade per l’Italia S.p.A.Autostrade per l’Italia S.p.A. was fined by the Garante 100,000 EUR for failing to respond to employees' requests for access and rectification of personal data linked to annual severance pay calculations. The case concerns a failure to meet obligations for handling data subject rights requests.ITGaranteGDPR€100,000
20 Oct 2022Istituto di Istruzione Superiore “G. Renda” di Polistena, Reggio CalabriaIstituto di Istruzione Superiore “G. Renda” was fined EUR 900 by the Garante for unlawfully processing personal data. The school published sensitive information about an employee’s contract termination without a legal basis, breaching GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€900
29 Apr 2021Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante in the amount of 4,000 EUR for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization because personal data remained accessible online for an extended period.ITGaranteGDPR€4,000
22 Jan 2015Francesco Saverio ManesFrancesco Saverio Manes was fined by the Garante EUR 2,400 for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system at the cultural club “K2”. The case concerned the absence of mandatory notices for individuals captured by the CCTV system.ITGaranteGDPR€2,400
16 Jan 2014Bios Marx s.r.l.Bios Marx s.r.l. was fined by the Italian Garante in the amount of EUR 16,000 for providing an inadequate privacy notice during a medical initiative. The authority also found that personal data were shared with third parties without obtaining specific consent.ITGaranteGDPR€16,000
05 May 2011Mondolibri s.p.a.Mondolibri s.p.a. was fined EUR 8,000 by the Garante for collecting personal email addresses through its website without providing adequate information to the data subjects. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€8,000
07 Mar 2024Ministero della saluteThe Italian Ministry of Health was fined EUR 100,000 by the Garante for inadequate data protection and communication measures in the National Health Information System. The authority found breaches of GDPR requirements on data security and breach notification.ITGaranteGDPR€100,000
16 Dec 2021Enel Energia S.p.a.Enel Energia S.p.a. was investigated for improper promotional contacts, including contacts to individuals with reserved numbers or registered in the ROP. The authority also challenged making access to online services conditional on consent to marketing and profiling.ITGaranteGDPR€26,513,000
10 Nov 2022Doctolib SrlDoctolib Srl was fined EUR 40,000 by the Italian Garante for violations linked to insufficient transparency in the online information provided to patients. The case concerned, in particular, how consent for processing health data was obtained.ITGaranteGDPR€40,000
16 Nov 2017S.T.E.A.T. S.p.a.S.T.E.A.T. S.p.a. was fined by the Garante for failing to properly notify the installation of electronic monitoring and localization devices on public transport buses. The authority found a breach of data protection notification obligations.ITGaranteGDPR€20,000
17 Dec 2015G.I.T. s.a.sG.I.T. s.a.s was fined 4,800 EUR by the Garante. The authority found that the company failed to provide adequate simplified information for its video surveillance system and did not give the required notice when collecting personal data through its website.ITGaranteGDPR€4,800
12 Sept 2024Ordine delle Professioni Infermieristiche di TriesteThe Garante fined the Ordine delle Professioni Infermieristiche di Trieste EUR 4,000 for breaches of data protection rules. The case involved improper disclosure of data to third parties and a failure to provide adequate information to data subjects.ITGaranteGDPR€4,000