Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Feb 2007Asl Basso MoliseAsl Basso Molise was fined by the Garante for failing to notify its data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code.ITGaranteGDPR€10,000
29 Apr 2026dottoressa GuzzoThe Garante imposed a fine of EUR 5,000 on dottoressa Guzzo for unlawfully processing personal data by publishing images of a deceased minor without consent. The authority found that this breached core data protection principles.ITGaranteGDPR€5,000
18 Jul 2023Ermeslink di Giovanni Di StefanoThe Garante imposed a fine of EUR 5,000 on Ermeslink di Giovanni Di Stefano for improperly handling video surveillance data. The breach concerned data protection rules and could have affected all residents and non-residents of the Municipality of Modica.ITGaranteGDPR€5,000
11 Sept 2025Ente Parco Regionale Migliarino San Rossore MassaciuccoliEnte Parco Regionale Migliarino San Rossore Massaciuccoli was fined EUR 8,000 by the Garante for failing to implement adequate technical and organizational measures. The authority found that more personal data was processed than necessary, in breach of the GDPR and national data protection rules.ITGaranteGDPR€8,000
21 Feb 2013Terme Rosapepe s.a.s.Terme Rosapepe s.a.s. was fined EUR 4,800 by the Garante. The authority found that the company collected personal data through a website registration form without providing the required privacy notice, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€4,800
28 May 2026Regione Autonoma della SardegnaThe Garante fined Regione Autonoma della Sardegna EUR 3,000 for sharing disciplinary sanction information with unauthorized internal units. The authority found this breached the GDPR and national data protection rules.ITGaranteGDPR€3,000
06 Jun 2024Eni Plenitude S.p.A. Società BenefitEni Plenitude S.p.A. was fined by the Garante 6,419,631 EUR for making unsolicited promotional calls without prior consent. The company also used numbers listed in the Public Opposition Register, which constituted a breach of GDPR rules.ITGaranteGDPR€6,419,000
16 Nov 2023Amazon Italia Transport s.r.l.Amazon Italia Transport s.r.l. was fined €40,000 by the Garante for failing to respond to a former employee’s request for access to personal data. The authority found a breach of Article 15 GDPR.ITGaranteGDPR€40,000
05 Mar 2020Comune di San Giorgio JonicoComune di San Giorgio Jonico was fined by the Garante for publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€3,000
02 Apr 2015Regione CampaniaThe Garante fined Regione Campania EUR 4,000 for failing to provide requested information related to a disciplinary procedure. The authority found a breach of data protection rules.ITGaranteGDPR€4,000
07 Nov 2019Comune di TivoliThe Municipality of Tivoli was fined by the Italian data protection authority, Garante, for unlawfully publishing personal data on its institutional website. The publication also included information about a pending criminal proceeding, breaching the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€6,000
02 Mar 2011Skiarea Valchiavenna S.p.A.Skiarea Valchiavenna S.p.A. was fined EUR 12,000 by the Garante. The authority found that the company failed to provide the required data protection information to skiers using its facilities, in breach of Articles 13 and 161 of the Italian Data Protection Code.ITGaranteGDPR€12,000
15 Apr 2021Tiberia Assicurazioni s.a.s.Tiberia Assicurazioni s.a.s. was fined by the Garante 1,500 EUR for sending an insurance contract proposal by email without the recipient's consent. The authority found this to be a breach of GDPR Article 6.ITGaranteGDPR€1,500
04 Jun 2015Centrex srlCentrex srl was fined by the Garante for conducting telemarketing activities without prior informed consent from individuals. The case involved promotional calls to numbers listed in the public opposition registry.ITGaranteGDPR€4,000
13 May 2021Synlab Med srlSynlab Med srl was fined EUR 20,000 by the Garante. The authority found that personal data were improperly transmitted to an entity not competent to process them, breaching the principles of data minimization and integrity.ITGaranteGDPR€20,000
15 Dec 2022Azienda Universitaria Friuli CentraleAzienda Universitaria Friuli Centrale was fined EUR 55,000 by the Garante for processing personal data without a legal basis. The authority also found failures to provide instructions for data deletion and to stop unauthorized processing by Insiel spa.ITGaranteGDPR€55,000
29 Apr 2021Comune di Santa NinfaComune di Santa Ninfa was fined by the Garante 2,000 EUR for publishing a complainant’s personal data online. The publication also included detailed references to enforcement proceedings, which breached GDPR requirements.ITGaranteGDPR€2,000
15 Sept 2022Immobiliare Riscostruzione Meloria s.r.l.The company was fined by the Garante in the amount of 2,000 EUR for installing a video surveillance system without the required informational signage. This breached GDPR rules on transparency and the duty to inform individuals subject to monitoring.ITGaranteGDPR€2,000
27 Nov 2024Engineering Ingegneria Informatica S.p.A.The Garante imposed a fine of EUR 10,000 on Engineering Ingegneria Informatica S.p.A. for a data breach involving the Molise regional health portal. A system vulnerability allowed unauthorized access to personal data.ITGaranteGDPR€10,000
29 Apr 2026Pianeta s.r.l.Pianeta s.r.l. was fined by the Garante 34,000 EUR for unlawfully processing personal data linked to a loyalty card program. The data were used to initiate disciplinary action against an employee, which breached GDPR requirements.ITGaranteGDPR€34,000