Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Jul 2017InvalsiInvalsi was fined EUR 40,000 by the Italian Garante for unlawful processing of personal data. The case concerned the online publication of files containing disaggregated student personal data, including sensitive information.ITGaranteGDPR€40,000
06 Jun 2024Drivalia Leasys Rent S.p.A.Drivalia Leasys Rent S.p.A. was fined by Garante 250,000 EUR for denying a car rental voucher to a customer listed on a blacklist. The authority found insufficient transparency in data processing and a lack of proper legal basis and consent under GDPR.ITGaranteGDPR€250,000
09 Jul 2020Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 800,000 by the Garante for irregularities in the processing of customer data. The violations concerned SIM card activation, promotional use of data, inadequate security measures, and improper data retention.ITGaranteGDPR€800,000
25 Jan 2018Trivenet s.r.l.Trivenet s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company retained call data longer than permitted under data protection rules.ITGaranteGDPR€40,000
17 Jul 2024Azienda ULSS n. 14The Garante fined Azienda ULSS n. 14 EUR 22,000 for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies resulted in a data breach involving sensitive health data.ITGaranteGDPR€22,000
17 Dec 2020Azienda Unità Sanitaria Locale Toscana Sud EstAzienda Unità Sanitaria Locale Toscana Sud Est was fined for processing personal data without proper safeguards. The authority also found that patient data was shared without anonymization, in breach of GDPR requirements.ITGaranteGDPR€100,000
21 Apr 2011Azienda USL della Valle D'AostaAzienda USL della Valle D'Aosta was fined for processing personal data during phone bookings without providing the required information notice and for failing to update the security program document. The authority found these actions breached data protection rules.ITGaranteGDPR€20,000
09 May 2018Amiu S.p.a.Amiu S.p.a. was fined by the Garante 20,000 EUR for improper processing of personal data through its video surveillance systems. The authority found that the company failed to properly designate data processing personnel and to implement adequate data protection measures.ITGaranteGDPR€20,000
07 May 2015Zampino Giuseppe GiovanniZampino Viaggi, operated by Zampino Giuseppe Giovanni, was fined 2,400 EUR by the Garante. The authority found that personal data were collected through the website without the required privacy notice, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
27 Apr 2011Comune di AdroThe Municipality of Adro was fined 15,000 EUR by the Italian supervisory authority Garante. The case concerned the publication of employees’ personal data, including health information, in a periodical.ITGaranteGDPR€15,000
10 Dec 2015Aruba s.p.a.Aruba s.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 40,000. The case concerned the sending of promotional emails without obtaining the required consent, in breach of articles 23 and 130 of the Italian data protection code.ITGaranteGDPR€40,000
19 Mar 2015Liceo Statale "Farnesina"Liceo Statale Farnesina was fined EUR 4,000 by the Garante for unlawfully publishing lists of student names on its institutional website without a legal basis. The conduct breached data protection rules.ITGaranteGDPR€4,000
09 Jan 2014Goldenbridge s.r.l.Goldenbridge s.r.l. was fined EUR 2,400 by the Garante for failing to provide the required privacy notice when collecting personal data through a website contact form. The authority found this to be a breach of the Italian data protection rules.ITGaranteGDPR€2,400
17 Jan 2008Assioma selezione e sviluppo s.r.l.Assioma selezione e sviluppo s.r.l. was fined by the Garante in the amount of 10,000 EUR for failing to comply with data protection notification requirements. The breach concerned Article 163 of the Italian Data Protection Code.ITGaranteGDPR€10,000
13 Feb 2014Zheng SuigenZheng Suigen was fined by the Italian data protection authority, Garante, in the amount of EUR 2,400. The case concerned inadequate information about the use of a video surveillance system, which breached privacy rules.ITGaranteGDPR€2,400
15 May 2013You & Me di Borille FabrizoYou & Me di Borille Fabrizo was fined EUR 4,000 by the Italian Garante. The sanction concerned the failure to respond to requests for information about surveillance cameras, which breached data protection rules.ITGaranteGDPR€4,000
15 Dec 2022Scuola Statale Secondaria di I^ grado “Bianco-Pascoli”, di Fasano (BR)The school was fined by the Garante 3,000 EUR for violations in the processing of personal data, including minors' health information. The authority found that the processing lacked a proper legal basis and sufficient transparency.ITGaranteGDPR€3,000
20 Feb 2014Paola ZorzoloPaola Zorzolo was fined for failing to provide adequate privacy information in the video surveillance system at her gaming hall. The authority found a breach of privacy and data protection rules.ITGaranteGDPR€2,400
23 Mar 2017Azienda Sanitaria ULSS 6 di VicenzaAzienda Sanitaria ULSS 6 di Vicenza was fined by the Garante 10,000 EUR for unlawfully communicating an individual's health data to the Comune di Arcugnano without proper authorization. The case involved a breach of lawful processing rules and safeguards for special-category data.ITGaranteGDPR€10,000
17 Oct 2024Serfin 97 S.r.l.Serfin 97 S.r.l. was fined EUR 60,000 by the Garante for unlawful processing of personal data. The company used a third party’s email address to contact a debtor for debt recovery purposes, which breached data protection rules.ITGaranteGDPR€60,000