Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Jul 2006Mediatec-Mr s.r.l.Mediatec-Mr s.r.l. was fined by the Garante for sending unsolicited promotional emails without providing the required information on data processing. The authority found a breach of the information obligation under data protection law.ITGaranteGDPR€1,549
10 Dec 2015Nuovo Pic Nic s.r.l.Nuovo Pic Nic s.r.l. was fined 2,400 EUR by the Garante for failing to provide adequate simplified information about its video surveillance system. The authority treated this as a breach of data protection rules.ITGaranteGDPR€2,400
26 Jun 2014Sudmetal s.r.l.Sudmetal s.r.l. was fined for using an integrated video surveillance system that allowed images from workplaces to be viewed without the required safeguards. The authority found this to be a breach of privacy regulations.ITGaranteGDPR€12,000
10 Mar 2011Gruppo Guide Italia s.r.l.Gruppo Guide Italia s.r.l. was fined 8,000 EUR by the Garante for publishing personal data without authorization in a guide. The case concerned a breach of data protection rules.ITGaranteGDPR€8,000
12 Sept 2013Comune di MantovaThe Municipality of Mantua was fined by the Garante for unlawfully disseminating personal data through its online services without a proper legal basis. The authority found a breach of Article 19 of the Italian Data Protection Code.ITGaranteGDPR€10,000
20 Nov 2008XYThe entity was fined by the Garante in the amount of 4,000 EUR for failing to respond to a request for information concerning unsolicited promotional emails. The case concerned non-compliance with data protection obligations.ITGaranteGDPR€4,000
04 Oct 2012American Express Services Europe LimitedAmerican Express Services Europe Limited was fined by the Garante EUR 40,000 for making promotional calls without the data subject's consent. The case concerns a breach of privacy rules governing telephone marketing.ITGaranteGDPR€40,000
14 Nov 2024D’Anna Assicurazioni S.r.l.D’Anna Assicurazioni S.r.l. was fined by the Garante 5,000 EUR for sending unsolicited promotional emails despite the recipient’s objection. The authority found this breached GDPR rules on data subject rights and transparency.ITGaranteGDPR€5,000
31 Jan 2019Istituto Scolastico Superiore “Andrea Mantegna”Istituto Scolastico Superiore “Andrea Mantegna” was fined by the Garante €4,000 for unlawfully publishing personal data on its institutional website. The disclosure included health information about teaching staff, which is sensitive personal data.ITGaranteGDPR€4,000
30 Jun 2011New Stereo In srlNew Stereo In srl was fined by the Garante 15,000 EUR for unlawful processing of personal data. The case concerned the activation of two unsolicited phone cards, in breach of Article 157 of the Italian Data Protection Code.ITGaranteGDPR€15,000
02 Feb 2019Ordinanza ingiunzione - 2 febbraio 2019 [9100784]The Garante imposed an administrative fine for violating data protection rules. The case concerned retaining surveillance footage for longer than the permitted 7 days.ITGaranteGDPR€11,940
17 Apr 2026Carlo Maria Antonio ParisiThe Garante fined Carlo Maria Antonio Parisi, owner of the online newspaper “giornalistitalia.it”, EUR 2,500. The authority found inadequate technical and organizational measures to support data subject rights and delays in handling requests without undue delay.ITGaranteGDPR€2,500
24 Jul 2014Intermatica Holding s.r.l.Intermatica Holding s.r.l. was fined by the Italian Garante for failing to adopt minimum security measures. The company used passwords of seven characters instead of the required eight, breaching Article 33 of the Italian Data Protection Code.ITGaranteGDPR€4,000
16 Sept 2021Consorzio di Bonifica dell’OristaneseConsorzio di Bonifica dell’Oristanese was fined EUR 5,000 by the Garante for publishing a disciplinary measure on its website that included an employee’s health information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€5,000
10 Jun 2021Ministero dell’InternoThe Italian Data Protection Authority fined Ministero dell’Interno EUR 75,000 for posting videos on social media that breached data protection rules. The footage related to a criminal case was shared by the police and contained violent content, which was found inconsistent with data protection principles.ITGaranteGDPR€75,000
04 Jul 2024Comune di TrevisoThe Garante fined Comune di Treviso EUR 7,000 for failing to adopt internal measures governing data processing in connection with the TrevisoSicura application. The authority also found that the municipality incorrectly assumed the role of data processor instead of properly defining its data protection responsibilities.ITGaranteGDPR€7,000
04 Apr 2007Azienda sanitaria locale di PescaraAzienda sanitaria locale di Pescara was fined €10,000 by the Garante for breaching data protection rules. The case involved improper handling of sensitive personal data, including genetic and health information, without the required notification to the authority.ITGaranteGDPR€10,000
28 May 2020Azienda Teatro del GiglioAzienda Teatro del Giglio was fined 6,000 EUR by the Garante for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€6,000
26 Sept 2024CI & DI Food s.r.l.CI & DI Food s.r.l. was fined by the Garante 4,000 EUR for failing to respond to an employee’s request to access personal data related to employment. The request included work attendance records.ITGaranteGDPR€4,000
21 Apr 2021Isinc S.r.l.s.Isinc S.r.l.s. was fined 20,000 EUR by the Garante for sending promotional emails using personal data taken from public databases without proper consent. The authority found this conduct to be in breach of GDPR Article 5.ITGaranteGDPR€20,000