Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Apr 2022Educationest s.r.l.Educationest s.r.l. was fined EUR 1,000 by the Italian data protection authority, Garante. The case concerned the unlawful disclosure of an employee’s pregnancy status to third parties via email, in breach of data protection rules.ITGaranteGDPR€1,000
06 Jun 2018MP Tuscolana s.r.l.MP Tuscolana s.r.l. was fined EUR 20,000 by the Garante for the unauthorized activation of two phone cards without the consent of the individuals concerned. The case indicates a failure to obtain valid consent before activating the services.ITGaranteGDPR€20,000
22 May 2018Luigi PagnanelliLuigi Pagnanelli, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
04 Jul 2024Postel S.p.A.Postel S.p.A. was fined by the Garante EUR 900,000 for a data breach following a ransomware attack. The attack exploited vulnerabilities in the Microsoft Exchange platform, resulting in unauthorized access to data and publication on the dark web.ITGaranteGDPR€900,000
07 Mar 2024Hotel Milano di Foschi Eros e Righini Rina & C. SncThe Garante fined Hotel Milano EUR 3,000 for improper installation of surveillance cameras. The cameras captured public streets and third-party properties, and the informational signage was inadequate.ITGaranteGDPR€3,000
13 May 2015Ottodue s.r.l.Ottodue s.r.l. was fined EUR 12,000 by the Garante for retaining surveillance footage for 98 days. This exceeded the 7-day retention limit set out in the video surveillance guidelines.ITGaranteGDPR€12,000
27 Mar 2025Provvedimento del 27 marzo 2025 [10140216]The Garante fined Powerfit, Soleo, and Zero Due Villa for sending promotional SMS messages without the recipients’ consent. The messages also did not provide an opt-out mechanism, which breached GDPR requirements.ITGaranteGDPR€6,000
26 Feb 2020Comune di Fogliano RedipugliaThe Municipality of Comune di Fogliano Redipuglia was fined by the Garante for unlawfully publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€6,000
05 Feb 2015Comune di BellizziComune di Bellizzi was fined for unlawfully publishing sensitive personal data revealing health information on its institutional website. The conduct breached privacy rules governing the processing and disclosure of sensitive data.ITGaranteGDPR€10,000
27 Nov 2024Comune di Motta Sant'AnastasiaThe Garante imposed a EUR 10,000 fine on Comune di Motta Sant'Anastasia for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper processing of personal data.ITGaranteGDPR€10,000
11 Feb 2016Anteprima Group srlAnteprima Group srl was fined EUR 6,400 by the Garante. The case concerned an unsolicited promotional call made without prior information to the recipient and without obtaining consent.ITGaranteGDPR€6,400
01 Apr 2009Casa di cura Sant'Antonio s.p.a.Casa di cura Sant'Antonio s.p.a. was fined by the Italian data protection authority, Garante. The case concerned processing personal data without the required notification under the Italian Data Protection Code.ITGaranteGDPR€10,000
01 Jun 2023Thin SrlThin Srl was fined EUR 15,000 by the Garante for breaching the GDPR principles of lawfulness, fairness, and transparency in data processing. The case concerned processing activities linked to a medical project.ITGaranteGDPR€15,000
22 Oct 2015Comune di ZagariseComune di Zagarise was fined for processing employees’ biometric data without notifying the Garante and without requesting prior verification. The authority found violations of Articles 17 and 37 of the Codice.ITGaranteGDPR€12,000
24 Sept 2015Acquapark di Milillo Rosa & C. s.a.s.Acquapark di Milillo Rosa & C. s.a.s. was fined EUR 6,400 by the Garante for collecting personal data without providing the required information notice and for publishing user photos without consent. The case concerns failures to meet transparency obligations and lawful processing requirements.ITGaranteGDPR€6,400
03 Apr 2014Robianton s.r.l.Robianton s.r.l. was fined by the Garante in the amount of 2,400 EUR. The authority found that the company failed to provide the simplified information required by the data protection code and the rules on video surveillance.ITGaranteGDPR€2,400
06 Jul 2016Sorec s.r.l.Sorec s.r.l. was fined EUR 4,000 by the Garante for inadequate password security in its data processing systems. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€4,000
15 Jan 2020TIM S.p.A.TIM S.p.A. was fined by the Garante for making unauthorized promotional calls. The authority found that the company failed to ensure adequate consent and accountability measures under data protection rules.ITGaranteGDPR€27,802,000
06 Oct 2022Alpha Exploration Co. Inc.Alpha Exploration Co. Inc. was fined by the Garante EUR 2,000,000 for violations related to data processing practices on its social media platform, Clubhouse. The case concerned irregularities in the way user data was processed.ITGaranteGDPR€2,000,000
21 Feb 2013American Express Services Europe LimitedAmerican Express Services Europe Limited was fined EUR 60,000 by the Garante. The authority found that the security program document was not updated in line with the technical rules on minimum security measures.ITGaranteGDPR€60,000