Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Feb 2014Società Editrice Sud s.p.a.Società Editrice Sud s.p.a. was fined by the Garante in the amount of 16,800 EUR for using inadequate information notices on data collection forms. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€16,800
27 Jan 2021Azienda USL della RomagnaAzienda USL della Romagna was fined by the Garante 50,000 EUR for failing to implement procedures to prevent unauthorized disclosure of patients' health information. The authority found a breach of GDPR Article 9 on special categories of personal data.ITGaranteGDPR€50,000
14 Jun 2018Azienda Ospedaliera Pugliese CiaccioAzienda Ospedaliera Pugliese Ciaccio was fined EUR 16,000 by the Garante. The authority found that patients were not informed about data processing and that consent was not obtained for processing sensitive data, in breach of the Italian Data Protection Code.ITGaranteGDPR€16,000
26 Oct 2017M&M Centro analisi s.r.l.M&M Centro analisi s.r.l. was fined by the Garante 20,000 EUR for failing to notify the processing of sensitive health data. The obligation arose under the Italian Data Protection Code.ITGaranteGDPR€20,000
06 Jul 2023Comune di AvianoThe Garante fined Comune di Aviano EUR 3,000 for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found a breach of data minimization and transparency principles.ITGaranteGDPR€3,000
22 Jul 2021Regione LombardiaRegione Lombardia was fined by the Garante 200,000 EUR for publishing personal data on its website that could reveal individuals' economic and social hardship. The authority found that this breached GDPR transparency and data protection requirements.ITGaranteGDPR€200,000
15 May 2013Chen JingChen Jing was fined by the Italian Garante in the amount of EUR 2,400 for providing inadequate information about a video surveillance system at Ottimoda S.a.s. The case concerned a breach of the Italian Data Protection Code.ITGaranteGDPR€2,400
07 Apr 2016Comune di LizzanoComune di Lizzano was fined by the Garante for publishing personal data, including health information about a minor, on its online notice board. The authority found this to be a breach of data protection rules.ITGaranteGDPR€4,000
15 Dec 2022Giessegi Industria Mobili S.p.A.Giessegi Industria Mobili S.p.A. was fined by the Garante 50,000 EUR for unlawful processing of personal data. The company installed a device to track the geographical location of a vehicle used by an employee, in breach of GDPR requirements.ITGaranteGDPR€50,000
10 Apr 2025Acea EnergiaAcea Energia was fined EUR 3,000,000 by the Garante. The authority found unauthorized telemarketing activities and insufficient protection of databases against access by unauthorized agents.ITGaranteGDPR€3,000,000
22 May 2018C.R.M. S.r.l.C.R.M. S.r.l. was fined EUR 28,000 for using a biometric system to record employee attendance without prior notification to the Garante. The authority found this to be a breach of data protection rules.ITGaranteGDPR€28,000
18 Nov 201524 Media s.r.l.24 Media s.r.l. was fined EUR 4,000 by the Garante. The authority found that the company required mandatory consent for purposes beyond the original data collection intent, including promotional communications and sharing data with third parties.ITGaranteGDPR€4,000
24 Feb 2010ADEC Assistenza dentistica e cure odontoiatriche-ortodontiche s.r.l.ADEC Assistenza dentistica e cure odontoiatriche-ortodontiche s.r.l. was fined 6,000 EUR by the Garante. The authority found that personal data were processed through the website contact form without the required information notice, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
21 Mar 2013dr. Attilio Vincenzo PignatelliDr. Attilio Vincenzo Pignatelli was fined by the Garante EUR 2,400 for operating a video surveillance system without the required simplified notice and for failing to comply with data retention rules. The case concerned non-compliance with information duties and retention periods for recorded footage.ITGaranteGDPR€2,400
02 Jul 2020Istituto Comprensivo di Uggiano La ChiesaIstituto Comprensivo di Uggiano La Chiesa was fined €2,000 by the Garante for posting lists at the school entrance that included minors' names, dates of birth, addresses, phone numbers, and vaccination status. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€2,000
16 Dec 2009Casa di cura Villa Russo s.p.a.Casa di cura Villa Russo s.p.a. was fined by the Garante for processing personal data without proper notification. The authority found violations of articles 37 and 38 of the Italian Data Protection Code.ITGaranteGDPR€30,000
15 Nov 2012Gruppo Ro.Ri. s.r.l.The Garante fined Gruppo Ro.Ri. s.r.l. 24,000 EUR for inadequate data protection measures linked to its video surveillance systems. The company also failed to provide proper information to data subjects as required by the privacy code.ITGaranteGDPR€24,000
13 Jul 2016Xu Ja s.n.c.Xu Ja s.n.c. was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned failure to provide simplified information about video surveillance, as required under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
11 Apr 2019Vincall s.r.l.sVincall s.r.l.s was fined EUR 2,018,000 by the Garante for failing to provide required information to individuals contacted during telemarketing activities. The authority found this to be a breach of data protection rules.ITGaranteGDPR€2,018,000
26 Mar 2026PSK AD Network S.r.l.PSK AD Network S.r.l. was fined EUR 5,000 by the Garante. The case concerned the failure to respond to a data subject’s deletion request and the failure to provide information requested by the authority, in breach of Article 157 of the Codice.ITGaranteGDPR€5,000