Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Jan 2026Macelleria La Costata s.r.l.s.The Garante fined Macelleria La Costata s.r.l.s. EUR 1,500 for the non-compliant installation of a video surveillance system. The authority found a breach of GDPR Article 5, which sets out the core principles for personal data processing.ITGaranteGDPR€1,500
26 Mar 2026Ordine degli Avvocati di PiacenzaOrdine degli Avvocati di Piacenza was fined EUR 3,000 by the Garante for improper handling of disciplinary sanctions in its professional register. The authority found that the processing did not comply with data protection requirements.ITGaranteGDPR€3,000
17 Mar 2016Aurelia FevolaAurelia Fevola was fined by the Garante for collecting personal data through her website without providing users with the required information notice. This conduct breached the Italian Data Protection Code.ITGaranteGDPR€2,400
05 Aug 2022Cosmopol Security S.p.A.Cosmopol Security S.p.A. was fined EUR 20,000 by the Garante for failing to respond to a data subject's request to exercise GDPR rights. The case also involved not explaining the origin of the personal data after electronic invoices were received without any contractual relationship.ITGaranteGDPR€20,000
06 Jul 2023SUROVI (Surovi Ristorante indiano e kebab di Chowdhury Monika)The Garante fined SUROVI restaurant EUR 1,000 for operating a video surveillance system without the required privacy notice. The authority found this to be a breach of Article 13 of the GDPR.ITGaranteGDPR€1,000
07 Jul 2022Intesa Sanpaolo Vita S.p.a.Intesa Sanpaolo Vita S.p.a. was fined by the Garante EUR 20,000 for unlawfully disclosing personal data related to a life insurance policy to unauthorized third parties. The breach resulted from an operational error and raised concerns about personal data protection and access controls.ITGaranteGDPR€20,000
04 Dec 2025Istituto Comprensivo di Roverbella (Mantova)Istituto Comprensivo di Roverbella was fined EUR 1,000 by the Garante for breaches of data protection rules. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency in data processing.ITGaranteGDPR€1,000
27 Nov 2025Istituto Comprensivo “G. Falcone” Rende-Quattromiglia (CS)The Garante fined Istituto Comprensivo “G. Falcone” EUR 2,000 for breaches of data processing principles, including lawfulness, fairness, and transparency. The authority also found non-compliance with data processing agreements.ITGaranteGDPR€2,000
16 Jan 2025Comune di CoriThe Garante fined Comune di Cori EUR 2,000 for violations related to the processing of personal data in connection with the issuance of the “Dedicata a te” card. The case involved electronic payment cards provided by Poste Italiane.ITGaranteGDPR€2,000
15 Feb 2018APS Holding S.p.a.APS Holding S.p.a. was fined by the Garante 40,000 EUR for failing to properly notify the data processing activities linked to the geolocation of vehicles used in its car sharing service. The authority found that the notification obligations under the Italian data protection code were not met.ITGaranteGDPR€40,000
08 Jun 2023L’Editoriale Nazionale S.r.l.The Garante fined L’Editoriale Nazionale S.r.l. EUR 30,000 for publishing articles that breached privacy rules. The company disclosed personal and sensitive data relating to a deceased minor without showing that the information was essential.ITGaranteGDPR€30,000
12 Jan 2017Centro Studi Raffaello s.r.l.Centro Studi Raffaello s.r.l. was fined by the Garante for inadequate data protection measures and improper collection of consent for marketing purposes. The case indicates deficiencies in the company's personal data processing controls and compliance framework.ITGaranteGDPR€20,000
22 Sept 2011C.T.M. s.p.a.C.T.M. s.p.a. was fined 40,000 EUR by the Italian data protection authority, Garante. The case concerned the failure to formally designate data processors and a breach of minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€40,000
20 Mar 2008MO.MA. s.r.l.MO.MA. s.r.l. was fined by the Garante for failing to comply with a request to confirm the conformity of personal data processing. The authority found a breach of Article 164 of the Italian Data Protection Code.ITGaranteGDPR€4,000
24 Jan 2013Casa di cura Abano TermeCasa di cura Abano Terme was fined EUR 60,000 by the Garante for processing personal data without complying with the legal requirements and limits. The authority found a breach of Article 26 of the Italian Privacy Code.ITGaranteGDPR€60,000
14 Nov 2024Provvedimento del 14 novembre 2024 [10104860]Garante imposed a EUR 40,000 fine on a healthcare company for failing to update its security assessments in response to increased cyberattacks. The authority found a breach of GDPR Article 32 because technical and organizational measures were not adjusted to the changed risk level.ITGaranteGDPR€40,000
29 Mar 2018ARC Informazioni s.r.l.ARC Informazioni s.r.l. was fined 20,000 EUR by the Garante. The authority found that the company failed to notify data processing activities as required by the Italian Privacy Code.ITGaranteGDPR€20,000
16 Dec 2010Impresa individuale Iba MarinoImpresa individuale Iba Marino was fined by the Garante 6,000 EUR for collecting personal data through its website without providing adequate information to data subjects. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
20 Jun 2013Terme di Montecatini s.p.a.Terme di Montecatini s.p.a. was fined by the Garante in the amount of 10,000 EUR. The company processed personal and sensitive data of national health service patients undergoing spa treatments without obtaining consent, in breach of Article 23 of the Italian Data Protection Code.ITGaranteGDPR€10,000
11 Feb 2021Bonatti S.p.ABonatti S.p.A was fined EUR 40,000 by the Garante for violating data protection rules. The company improperly shared an employee's medical data with a third party.ITGaranteGDPR€40,000