Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Oct 2025Multimedia News Società CooperativaThe Garante fined Multimedia News Società Cooperativa EUR 20,000 for failing to provide a privacy notice and contact details for data requests on its website. The authority found this breached transparency obligations and data subject rights.ITGaranteGDPR€20,000
17 Sept 2020Scanshare s.r.l.Scanshare s.r.l. was fined by the Garante 60,000 EUR for inadequate technical and organizational measures in handling candidate data during a hospital recruitment process. The authority also found a breach of GDPR Article 13 because the required information was not provided to candidates.ITGaranteGDPR€60,000
10 Oct 2023ComuneThe Italian data protection authority fined a municipality EUR 12,000 for unlawfully publishing personal data online in access request registers. Documents in the transparency section of the municipal website exposed names, protocol numbers, and other sensitive details of hundreds of citizens.ITGarante per la protezione dei dati personaliGDPR€12,000
02 Feb 2019XX S.r.l.The company was fined EUR 4,000 by the Garante. The authority found that it processed personal data for promotional purposes without obtaining valid consent from the data subjects.ITGaranteGDPR€4,000
28 Jun 2018Autotrasporti Viviani s.r.l.Autotrasporti Viviani s.r.l. was fined by the Garante 8,000 EUR for failing to comply with notification obligations related to the geolocation system installed on its transport vehicles. The case concerned missing required notices regarding the processing of data.ITGaranteGDPR€8,000
12 Jun 2014H3g s.p.a.H3g s.p.a. was fined EUR 75,000 by the Garante for violations related to customer profiling without the required consent. The case concerned personal data processing that did not comply with data protection requirements.ITGaranteGDPR€75,000
14 Nov 2024Comune di Torre AnnunziataThe Garante imposed a EUR 2,000 fine on Comune di Torre Annunziata for failing to communicate the contact details of its Data Protection Officer. This obligation arises under Article 37(7) GDPR and is intended to ensure the supervisory authority can reach the DPO.ITGaranteGDPR€2,000
06 Feb 2020Liceo Artistico Statale di NapoliLiceo Artistico Statale di Napoli was fined EUR 4,000 by the Garante for publishing an outdated teacher ranking on its institutional website. The authority found this breached GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
24 Nov 2022Areti S.p.A.Areti S.p.A. was fined EUR 1,000,000 by the Garante for incorrectly labeling a customer as a “defaulting client” based on inaccurate and outdated data. The issue may have affected up to 16,743 other individuals, indicating a broader data processing failure.ITGaranteGDPR€1,000,000
24 Jul 2014Easy Call srlEasy Call srl was fined EUR 112,000 by the Garante for making unsolicited promotional calls. The company contacted individuals listed in the opposition register, breaching data protection rules.ITGaranteGDPR€112,000
20 Mar 2014SIGE S.p.a.SIGE S.p.a. was fined by the Italian data protection authority, Garante, in the amount of €14,400. The case concerned a video surveillance system that retained images longer than permitted under the Garante's guidelines.ITGaranteGDPR€14,400
29 May 2008Target informatica di Rebosio GiancarloThe sole proprietorship Target informatica di Rebosio Giancarlo was fined EUR 1,549 by the Garante. The sanction concerned sending unsolicited promotional emails without providing the required information notice to the data subjects, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€1,549
02 Oct 2019Tgroup s.r.l.Tgroup s.r.l. was fined 6,400 EUR by the Italian data protection authority, Garante. The case concerned the activation of a SIM card without the user's knowledge, which breached data protection rules.ITGaranteGDPR€6,400
01 Mar 2018Ministero dell’Istruzione, dell’Università e della RicercaThe Ministry of Education, University and Research was fined €16,000 by the Garante for violations related to the handling of personal data in the implementation of the “Carta docente” application. The case concerned deficiencies in the way user data was processed within the service.ITGaranteGDPR€16,000
23 Oct 2025Franco SpellecchiaFranco Spellecchia was fined by the Garante for installing a video surveillance system around his residence without the required legal basis. The authority found that the setup breached GDPR rules, including the absence of a legitimate interest or authorization.ITGaranteGDPR€500
16 Dec 2021Centro di Medicina preventiva s.r.l.Centro di Medicina preventiva s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate measures to prevent unauthorized access to personal data. The deficiency resulted in a data breach.ITGaranteGDPR€10,000
14 Mar 2013Unitelma SapienzaUnitelma Sapienza was fined EUR 8,000 by the Garante for failing to provide information to data subjects and for not obtaining consent to process sensitive data. The violations occurred during online registration for university courses.ITGaranteGDPR€8,000
21 Jul 2022Stay Over s.r.l.Stay Over s.r.l. was fined by the Garante EUR 10,000 for a delayed and inadequate response to a data access request. The authority also found unlawful processing of a former employee's email account after employment ended.ITGaranteGDPR€10,000
08 Feb 2007RFI S.p.A.RFI S.p.A. was fined EUR 54,000 by the Garante for failing to provide the required data protection information to individuals covered by video surveillance at several train stations. The authority found a breach of data protection rules.ITGaranteGDPR€54,000
11 Apr 2013Teknoelettronica s.r.l.Teknoelettronica s.r.l. was fined EUR 6,000 by the Italian data protection authority, Garante. The company failed to provide the required privacy notice on its website, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000