BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Jan 2024 | Libero Consorzio comunale di CaltanissettaLibero Consorzio comunale di Caltanissetta was fined by the Garante EUR 2,000 for breaching Article 37(7) of the GDPR. The decision also orders publication of the sanction on the authority’s website. | IT | Garante | GDPR | €2,000 | ↗ |
| 22 Feb 2024 | Unica s.r.l.s.Unica s.r.l.s. was fined by the Garante EUR 2,000 for using a facial recognition system to record employee attendance without a proper legal basis. The authority found that the processing of biometric data breached GDPR requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Feb 2025 | Energia Pulita S.r.l.Energia Pulita S.r.l. was fined EUR 300,000 by the Garante for making unsolicited marketing calls without a valid legal basis. The authority found a breach of GDPR Article 5. | IT | Garante | GDPR | €300,000 | ↗ |
| 07 Mar 2013 | Greentel Soc. Coop.Greentel Soc. Coop. was fined by the Garante 10,400 EUR for sending promotional communications by fax without providing adequate information or obtaining explicit consent. The authority found violations of Articles 13 and 130 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,400 | ↗ |
| 23 Apr 2015 | Comune di CastelplanioComune di Castelplanio was fined by the Garante for publishing personal data, including names, on its online notice board. This conduct breached privacy regulations. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jan 2015 | Comune di RealmonteComune di Realmonte was fined by the Garante for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 Oct 2019 | Partito Democratico, Coordinamento Metropolitano di FirenzePartito Democratico, Coordinamento Metropolitano di Firenze was fined by the Garante €4,000 for a data protection breach. The incident resulted from a cyber attack on its website that exposed personal data of party members. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Jun 2014 | Ministero della GiustiziaThe Ministry of Justice was fined for unlawfully publishing personal data on its institutional website without a legal basis. The disclosure included names, dates of birth, and tax codes, in breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Jan 2018 | ATAM S.p.A. – Azienda territoriale Arezzo Mobilità S.p.A.ATAM S.p.A. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned failures to meet notification obligations related to a geolocation system used to track vehicles. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 May 2016 | Polo scolastico paritario Scuola Domani s.r.l.The private school Polo scolastico paritario Scuola Domani s.r.l. was fined EUR 2,400 by the Garante. The authority found that the website did not provide the required privacy information to users submitting inquiries or job applications. | IT | Garante | GDPR | €2,400 | ↗ |
| 08 Oct 2015 | Amministrazione provinciale di PordenoneAmministrazione provinciale di Pordenone was fined 4,000 EUR by the Garante. The authority found that the annual Security Programmatic Document was not updated by the required deadline, breaching data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 11 Nov 2021 | Comune di Varano BorghiComune di Varano Borghi was fined EUR 1,000 by the Garante for unlawfully publishing personal data online. The authority found a breach of GDPR principles of data minimization and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 04 Nov 2010 | Casa di Cura Tortorella S.p.aCasa di Cura Tortorella S.p.a was fined by the Garante for failing to notify certain data processing activities and for providing inadequate information to data subjects. The case concerns breaches of the Italian Data Protection Code and points to deficiencies in basic notification and transparency obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 18 Dec 2025 | LTL S.p.A.LTL S.p.A. was fined 40,000 EUR by the Garante for unlawfully maintaining access to an ex-employee’s email account after termination. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 Apr 2025 | Energia Pulita S.r.l.Energia Pulita S.r.l. was fined by the Garante for improper handling of personal data in telemarketing activities. The authority also noted failure to cooperate with the supervisory authority and incorrect identification of roles in data processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Jul 2021 | Regione CalabriaThe Garante imposed a 10,000 EUR fine on Regione Calabria for publishing personal data on its website. The conduct breached GDPR rules on lawful processing and protection of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Oct 2021 | TPER Trasporto Passeggeri Emilia Romagna S.p.A.TPER Trasporto Passeggeri Emilia Romagna S.p.A. was fined by the Garante EUR 30,000 for violations related to the processing of personal data of call center employees. The case involved potential unauthorized monitoring and insufficient data protection measures. | IT | Garante | GDPR | €30,000 | ↗ |
| 02 Apr 2015 | Schioppetti RaffaellaSchioppetti Raffaella was fined by the Italian data protection authority, Garante, in the amount of 15,000 EUR. The sanction concerned activating phone cards in individuals' names without their knowledge, which breached data protection rules. | IT | Garante | GDPR | €15,000 | ↗ |
| 23 May 2024 | Green Land African MinimarketThe Garante fined Green Land African Minimarket EUR 1,000 for improper use of a video surveillance system. The system captured areas beyond the company's premises and recorded employees without meeting the required legal conditions. | IT | Garante | GDPR | €1,000 | ↗ |
| 10 Apr 2025 | Provvedimento del 10 aprile 2025 [10144184]A healthcare organization was fined after an employee accessed a patient's health dossier without authorization. The case highlights a breach of data protection rules in the healthcare sector. | IT | Garante | GDPR | €18,000 | ↗ |