BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Mar 2017 | Cigno d’Argento s.r.l.Cigno d’Argento s.r.l. was fined by the Garante 36,000 EUR for data protection violations. The case concerned the improper use of video surveillance systems without the required authorization. | IT | Garante | GDPR | €36,000 | ↗ |
| 07 May 2015 | Comune di GenovaThe Municipality of Genoa was fined by the Garante for unlawfully keeping personal and judicial data on its institutional website beyond the legally permitted period. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 30 Nov 2023 | Limit Call S.r.l.s.Limit Call S.r.l.s. was fined by the Italian supervisory authority, Garante, in the amount of €60,000. The case concerned a failure to respond to an information request linked to unsolicited phone calls made without consent, which breached data protection rules. | IT | Garante | GDPR | €60,000 | ↗ |
| 08 May 2013 | Profile 2100 srlProfile 2100 srl was fined EUR 10,400 by the Garante for sending unsolicited promotional communications by fax without valid consent. The case concerned a breach of data protection rules and direct marketing requirements. | IT | Garante | GDPR | €10,400 | ↗ |
| 12 Feb 2026 | Provvedimento del 12 febbraio 2026 [10226120]The Garante imposed a fine of EUR 1,500 for unlawful processing of personal data through a video surveillance system at a commercial establishment. The cameras captured public streets and private residences, and the data subjects were not properly notified. | IT | Garante | GDPR | €1,500 | ↗ |
| 16 Sept 2021 | Università Commerciale “Luigi Bocconi” di MilanoUniversità Commerciale “Luigi Bocconi” di Milano was fined EUR 150,000 by the Garante for data protection breaches during remote exams. The authority found an insufficient legal basis, inadequate transparency, and weak security measures for transfers of data to the USA. | IT | Garante | GDPR | €150,000 | ↗ |
| 29 Oct 2020 | Gaypa s.r.l.Gaypa s.r.l. was fined EUR 20,000 by the Garante for continuing to use a personalized email account of a former employee after the employment ended. The authority found this conduct inconsistent with GDPR principles of lawfulness and purpose limitation. | IT | Garante | GDPR | €20,000 | ↗ |
| 28 Jul 2016 | Comune di San Lorenzo NuovoComune di San Lorenzo Nuovo was fined EUR 4,000 by the Garante for unlawfully publishing the list of court jurors online for longer than legally permitted. This resulted in unauthorized disclosure of personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 26 Mar 2026 | Comune di CassinoComune di Cassino was fined for unlawfully publishing personal data online. The case concerns a breach of data protection rules and indicates a need to review procedures for publishing public information. | IT | Garante | GDPR | €2,500 | ↗ |
| 21 Mar 2012 | Solar Energy Group s.p.aSolar Energy Group s.p.a was fined by the Garante 32,000 EUR for processing personal data collected through online forms without providing the required information or obtaining consent. The authority found breaches of Articles 13 and 23 of the Italian Privacy Code. | IT | Garante | GDPR | €32,000 | ↗ |
| 24 Feb 2010 | Alampi Carmela & C. s.n.c. di Sapone GiovannaThe company was fined for processing personal data through a video surveillance system without providing the required simplified and detailed information to data subjects. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale di PiacenzaAzienda sanitaria locale di Piacenza was fined for failing to notify the Garante about processing data relating to health and sexual life. The authority treated this as a breach of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Apr 2023 | Comune di AdelfiaThe Garante fined Comune di Adelfia EUR 8,000 for violations related to the publication of personal data on its institutional website. The data were later removed. | IT | Garante | GDPR | €8,000 | ↗ |
| 31 Mar 2016 | avv. Gioacchino GenchiAvv. Gioacchino Genchi was fined by the Italian Garante for creating a database containing personal data, including phone traffic data. The database was accessible to his collaborators, which breached data protection rules. | IT | Garante | GDPR | €192,000 | ↗ |
| 19 Dec 2024 | Comune di BresciaThe Garante fined the Municipality of Brescia EUR 10,000 for violations related to the processing of personal data at a cemetery. The case concerned the unauthorized disclosure of individuals’ identities. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Apr 2013 | Zhang CanpingZhang Canping was fined by the Garante in the amount of EUR 2,400 for failing to provide the required data protection notice under Article 13 of the Italian Data Protection Code. The violation concerned Hotel Paola. | IT | Garante | GDPR | €2,400 | ↗ |
| 10 Nov 2022 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante. The authority found that promotional contacts were made without the required information and without obtaining the data subject’s consent, in breach of GDPR requirements. | IT | Garante | GDPR | €500,000 | ↗ |
| 09 Oct 2014 | CISPEL Lombardia Services s.r.l.CISPEL Lombardia Services s.r.l. was fined by the Garante for failing to provide the required data protection information to job applicants. The authority also found that personal data was shared with third parties without the data subjects' consent. | IT | Garante | GDPR | €16,000 | ↗ |
| 11 Feb 2021 | Azienda Sanitaria Locale n. 2 Lanciano-Vasto-ChietiAzienda Sanitaria Locale n. 2 Lanciano-Vasto-Chieti was fined by the Garante 6,500 EUR for violations related to the processing of health data. The нарушения led to a data breach incident. | IT | Garante | GDPR | €6,500 | ↗ |
| 15 Sept 2022 | Bper Banca S.p.A.Bper Banca S.p.A. was fined by the Garante for a delayed and inadequate response to requests for deletion of personal data. The authority found breaches of GDPR Articles 12 and 17. | IT | Garante | GDPR | €10,000 | ↗ |