Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Mar 2013Università Telematica San Raffaele RomaUniversità Telematica San Raffaele Roma was fined by the Garante EUR 6,000 for providing inadequate data protection information through its enrollment and information request forms on its website. The case concerned a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€6,000
31 May 2018IDEASORRISO S.R.L.IDEASORRISO S.R.L. was fined by the Garante EUR 86,000 for making unsolicited promotional calls without the recipients’ consent. The case concerned data protection rules applicable to telemarketing activities.ITGaranteGDPR€86,000
23 Feb 2023Ediscom S.p.A.Ediscom S.p.A. was fined by the Garante 300,000 EUR for lacking clarity and transparency when obtaining user consent for marketing purposes. The authority also found that data was processed despite objections from data subjects.ITGaranteGDPR€300,000
16 Jan 2026Born S.r.l.Born S.r.l. was fined by the Garante 15,000 EUR for making unsolicited promotional calls to numbers listed in the Public Register of Oppositions. The conduct breached data protection rules governing telephone marketing and the right to object.ITGaranteGDPR€15,000
21 Mar 2013Compu & Games srlCompu & Games srl was fined EUR 54,000 by the Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information.ITGaranteGDPR€54,000
22 May 2018Pettirossi AngeloDr Pettirossi Angelo was fined by the Garante for failing to implement minimum security measures for personal data protection. The breach allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
22 Feb 2018FAMAS S.R.L.FAMAS S.R.L. was fined by the Garante for using a biometric system based on fingerprint recognition to record employee attendance without a proper legal basis. The case concerned the processing of biometric data in an employment context, where specific lawful grounds are required.ITGaranteGDPR€30,000
15 Oct 2015Ordinanza ingiunzione - 15 ottobre 2015 [4703503]A fine was imposed for activating 85 SIM cards in the names of 31 people without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€93,000
10 Nov 2022Comune di Villafranca di VeronaThe Comune di Villafranca di Verona was fined 4,000 EUR by the Garante for breaching data protection principles. The authority found that personal data linked to a sensitive private matter was improperly disclosed online.ITGaranteGDPR€4,000
16 Sept 2021Istituto per Ciechi Ardizzone GioeniIstituto per Ciechi Ardizzone Gioeni was fined by the Garante EUR 5,000 for failing to provide adequate data protection information about the activation of a video surveillance system. The case involved vulnerable guests, including blind and visually impaired persons, who were not properly informed about the processing of their personal data.ITGaranteGDPR€5,000
16 Jan 2014Hu ShaozengHu Shaozeng was fined EUR 2,400 by the Garante. The breach concerned failure to provide the simplified information required by the data protection code when operating a video surveillance system in a commercial establishment.ITGaranteGDPR€2,400
02 Jul 2020Regione CampaniaRegione Campania was fined EUR 4,000 by the Garante. The authority found a breach of the data minimization principle after personal data was published online without a proper legal basis.ITGaranteGDPR€4,000
31 Mar 2016Zhu XiaozhenZhu Xiaozhen was fined by the Garante for failing to provide the simplified information required under the data protection code and the video surveillance rules. The surveillance system was operated without proper notice to the individuals concerned.ITGaranteGDPR€2,400
28 May 2026Comune di SciaccaComune di Sciacca was fined EUR 6,000 by the Garante for violations related to the processing and dissemination of personal data in the public sector. The case concerned improper handling of personal data within public administration activities.ITGaranteGDPR€6,000
16 Dec 2009Polisportiva Eschilo 1 società sportiva dilettantistica a r.l.Polisportiva Eschilo 1 was fined EUR 10,000 by the Italian Garante. The case concerned processing biometric data without prior notification to the supervisory authority, which breached data protection rules.ITGaranteGDPR€10,000
09 May 2024Unicredit S.p.a.Unicredit S.p.a. was fined EUR 30,000 by the Garante for failing to respond to a personal data access request submitted by an heir. The authority found a breach of GDPR Article 15 and the Italian privacy code.ITGaranteGDPR€30,000
29 Nov 2012G & W Invest s.r.l.G & W Invest s.r.l. was fined €30,000 by the Italian data protection authority, Garante. The case concerned processing biometric data without timely notification, in breach of the Italian Data Protection Code.ITGaranteGDPR€30,000
27 Mar 2014Casa di cura Scarnati srlCasa di cura Scarnati srl was fined €10,000 by the Garante. The authority found that the company failed to properly designate, in writing, the employees authorized to process personal data.ITGaranteGDPR€10,000
21 Sept 2017AMI S.p.A.AMI S.p.A. was fined by the Garante for installing electronic monitoring and localization devices on public transport vehicles without proper notification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€40,000
26 May 2022Intesa Sanpaolo S.p.A.Intesa Sanpaolo S.p.A. was fined EUR 100,000 by the Garante for unlawfully disclosing personal banking data to unauthorized third parties. The case concerned a breach of data protection rules and required review of the bank’s data-sharing controls.ITGaranteGDPR€100,000