Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 May 2026Comune di Mirabella ImbaccariComune di Mirabella Imbaccari was fined for disclosing personal data online without a legal basis and for violating the data minimization principle. The authority also found that the municipality had failed to appoint a Data Protection Officer and to communicate the DPO’s contact details to the supervisory authority.ITGaranteGDPR€1,800
14 Jun 2019Facebook Ireland Ltd e Facebook Italy s.r.l.Facebook Ireland Ltd and Facebook Italy s.r.l. were fined EUR 1,000,000 by the Garante for violations involving the unauthorized sharing of user data with the application “Thisisyourdigitallife”. The case affected approximately 214,020 users.ITGaranteGDPR€1,000,000
28 May 2015Tex97 s.r.l.Tex97 s.r.l. was fined EUR 20,000 by the Italian data protection authority, Garante. The company retained customers' telephone traffic data for more than 24 months, in breach of Article 132 of the Italian Data Protection Code.ITGaranteGDPR€20,000
03 Oct 2013Forum Sport Center società sportiva dilettantistica S.r.l.Forum Sport Center società sportiva dilettantistica S.r.l. was fined by the Italian Garante in the amount of €8,400. The sanction concerned inadequate data protection notices for personal data collection and video surveillance systems.ITGaranteGDPR€8,400
04 Oct 2011Il Marmo s.r.l.Il Marmo s.r.l. was fined by the Garante in the amount of 10,000 EUR for failing to provide the required privacy notice on its website, specifically in the contact form. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€10,000
22 Jul 2021Flowbird s.r.l.Flowbird s.r.l. was fined EUR 30,000 by the Garante for processing personal data through parking meters in Rome without a legal basis. The authority also found that the company failed to maintain a record of processing activities.ITGaranteGDPR€30,000
02 Dec 2021Ica s.r.l.Ica s.r.l. was fined by the Garante EUR 30,000 for failing to implement adequate security measures in its online traffic-fine payment service. The weakness allowed unauthorized access to the personal data of fined citizens.ITGaranteGDPR€30,000
29 Sept 2011Enterprise Service s.r.l.Enterprise Service s.r.l. was fined by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The company also failed to provide the required information notice under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€10,000
22 May 2018Ordinanza ingiunzione - 22 maggio 2018 [9037459]A general practitioner failed to implement minimum security measures to protect patients' personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
30 Dec 2011Dike Giuridica s.r.l.Dike Giuridica s.r.l. was fined by the Garante in the amount of 10,400 EUR for sending unsolicited commercial emails without prior explicit consent from recipients. The authority also found that the required privacy notice was not provided, in breach of the Italian data protection code.ITGaranteGDPR€10,400
25 Jan 2018Scaramuzza MarioScaramuzza Mario was fined EUR 140,000 by the Garante for the unauthorized activation of multiple payment cards using personal data without the consent of the individuals concerned. The case indicates a breach of lawful processing requirements and the absence of a valid legal basis.ITGaranteGDPR€140,000
05 Apr 2018I Tel s.r.l.I Tel s.r.l. was fined EUR 230,000 by the Italian data protection authority, Garante. The case concerned the registration of phone cards to 23 individuals without their consent, in breach of data protection rules.ITGaranteGDPR€230,000
18 Jul 2023Nicola PetrolitoThe Garante imposed a EUR 400 fine on Nicola Petrolito for operating a video surveillance system that captured areas owned by third parties and public passageways. The authority found that the required informational signage was missing, constituting a GDPR breach.ITGaranteGDPR€400
11 Apr 2013Green Paradise S.r.l.Green Paradise S.r.l. was fined 2,400 EUR by the Garante. The authority found that the company collected personal data through its website without providing the required privacy notice, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
25 Sept 2025Comune di Isola del Gran Sasso d’ItaliaThe Garante fined the Comune di Isola del Gran Sasso d’Italia EUR 3,000 for unlawfully publishing personal data on its institutional website, including information related to criminal proceedings. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
01 Feb 2018Car City Club s.r.l.Car City Club s.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to designate data processors among its employees, which breached data protection rules.ITGaranteGDPR€20,000
17 Apr 2026Comune di Mazara del ValloThe Garante fined Comune di Mazara del Vallo 6,000 EUR for violations related to the online publication of personal data. The case concerned the improper disclosure of personal information through online publication.ITGaranteGDPR€6,000
04 Jun 2015Direzione Casa Circondariale di BariDirezione Casa Circondariale di Bari was fined €10,000 by the Garante for unlawfully processing sensitive data. The authority found that it collected, stored, and communicated the names of participants in a union demonstration without initiating any disciplinary proceedings, in breach of data protection law.ITGaranteGDPR€10,000
02 Mar 2017Trilogy s.r.l.Trilogy s.r.l. was fined EUR 48,000 by the Garante for making unsolicited marketing calls. The authority found that the company failed to provide the required information and did not obtain consent, in breach of the Italian Data Protection Code.ITGaranteGDPR€48,000
19 Feb 2015Comune di MesoracaComune di Mesoraca was fined by the Garante for unlawfully publishing sensitive personal data revealing health conditions on its institutional website. The case involved unauthorized disclosure of medical information made publicly accessible.ITGaranteGDPR€10,000