Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Oct 2025Franco SpellecchiaFranco Spellecchia was fined by the Garante for installing a video surveillance system around his residence without the required legal basis. The authority found that the setup breached GDPR rules, including the absence of a legitimate interest or authorization.ITGaranteGDPR€500
16 Dec 2021Centro di Medicina preventiva s.r.l.Centro di Medicina preventiva s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate measures to prevent unauthorized access to personal data. The deficiency resulted in a data breach.ITGaranteGDPR€10,000
14 Mar 2013Unitelma SapienzaUnitelma Sapienza was fined EUR 8,000 by the Garante for failing to provide information to data subjects and for not obtaining consent to process sensitive data. The violations occurred during online registration for university courses.ITGaranteGDPR€8,000
21 Jul 2022Stay Over s.r.l.Stay Over s.r.l. was fined by the Garante EUR 10,000 for a delayed and inadequate response to a data access request. The authority also found unlawful processing of a former employee's email account after employment ended.ITGaranteGDPR€10,000
08 Feb 2007RFI S.p.A.RFI S.p.A. was fined EUR 54,000 by the Garante for failing to provide the required data protection information to individuals covered by video surveillance at several train stations. The authority found a breach of data protection rules.ITGaranteGDPR€54,000
11 Apr 2013Teknoelettronica s.r.l.Teknoelettronica s.r.l. was fined EUR 6,000 by the Italian data protection authority, Garante. The company failed to provide the required privacy notice on its website, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
05 Mar 2020Azienda Sanitaria Locale di Ciriè, Chivasso e Ivrea (ASL TO4)ASL TO4 was fined by the Garante EUR 8,000 for unlawful data processing through video surveillance. The authority found that the required agreements with unions were not in place.ITGaranteGDPR€8,000
13 Mar 2025Comune di RoccarasoThe Garante fined Comune di Roccaraso EUR 2,000 for publishing personal data on a public notice board. The authority found breaches of GDPR Articles 5, 6 and 12, as well as Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€2,000
02 Jul 2020GTL s.r.l.GTL s.r.l. was fined EUR 3,000 by the Garante for failing to respond to an individual's data access request. The authority treated this as a breach of GDPR obligations.ITGaranteGDPR€3,000
13 Apr 2023Ordine degli Avvocati di AnconaThe Garante fined the Ordine degli Avvocati di Ancona 20,000 EUR for violations related to data processing transparency and security. The authority found incorrect privacy notices and non-compliance with GDPR principles.ITGaranteGDPR€20,000
12 Oct 2017Antea Service soc. coop.Antea Service soc. coop. was fined by the Garante 10,000 EUR for unlawfully processing biometric data of employees. The data were used to monitor workplace attendance. The case concerns a breach of personal data protection rules in an employment context.ITGaranteGDPR€10,000
17 Oct 2024AziendaThe company was fined for failing to implement adequate security measures, which led to a data breach affecting a large number of individuals. The case indicates insufficient protection of personal data and elevated risk to data subjects.ITGaranteGDPR€25,000
24 Jun 2011Azienda ospedaliera San Giuseppe Moscati (AOSGM)Azienda ospedaliera San Giuseppe Moscati was fined EUR 20,000 by the Garante. The authority found that the security program document was not updated and that minimum security measures were not adopted for the processing of health data.ITGaranteGDPR€20,000
08 May 2013Agro Informatica di Buracchi GinoAgro Informatica di Buracchi Gino was fined 32,000 EUR by the Garante for sending unsolicited promotional emails without prior explicit consent. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code.ITGaranteGDPR€32,000
18 Oct 2012Umbra Acque S.p.a.Umbra Acque S.p.a. was fined by the Garante 10,000 EUR for breaches of data protection rules. The authority found that the company failed to designate data processing officers and did not adopt minimum security measures for its video surveillance system.ITGaranteGDPR€10,000
21 May 2025Agenzia di Tutela della Salute, della Città Metropolitana di Milano, Servizio Prevenzione e Sicurezza Ambienti di Lavoro Milano Città NordAgenzia di Tutela della Salute was fined EUR 7,000 by the Garante for improperly sending medical reports and certificates. The authority found a breach of data protection rules.ITGaranteGDPR€7,000
11 Sept 2025Provvedimento dell'11 settembre 2025 [10184654]The decision imposes a fine on a healthcare company for cybersecurity-related breaches following a security incident involving patient data. The authority found non-compliance with Articles 25 and 32 GDPR.ITGaranteGDPR€8,000
25 Mar 2021GEDI News Network S.p.a.GEDI News Network S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The case concerned failure to comply with a request to delete personal data from an article about a 1998 legal case, which remained prejudicial because the outcome was not updated.ITGaranteGDPR€20,000
24 Jun 2021Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” di NovaraThe Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” in Novara was fined by the Garante EUR 2,000. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€2,000
11 Mar 2021Planet Group spaPlanet Group spa was fined EUR 80,000 by the Garante. The authority found that the company made unsolicited promotional calls without a proper legal basis, breaching GDPR rules on data processing and privacy by design.ITGaranteGDPR€80,000