BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Jun 2021 | aiComply S.r.l.aiComply S.r.l. was fined by the Garante in the amount of EUR 20,000 for failing to implement adequate security measures. In particular, it did not use a secure network protocol, which created a risk to the confidentiality and integrity of personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Mar 2023 | La Risorsa Umana.it s.r.l.La Risorsa Umana.it s.r.l. was fined EUR 40,000 by the Garante for monitoring employee email communications without providing proper information to employees. The authority found that this conduct breached GDPR requirements on transparency of processing and data security. | IT | Garante | GDPR | €40,000 | ↗ |
| 24 Mar 2022 | Brav s.r.l.Brav s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate technical and organizational security measures. The issue concerned data processing linked to the management of contraventions by the local police of the Municipality of Genoa. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Sept 2012 | Policlinico Sassarese s.p.a.Policlinico Sassarese s.p.a. was fined EUR 64,000 by the Garante for inadequate data protection measures. The authority cited insufficient video surveillance notices and missing consent documentation for the processing of sensitive data. | IT | Garante | GDPR | €64,000 | ↗ |
| 15 Mar 2018 | Istituto Tecnico Statale Commerciale e per Geometri Masullo ThetiIstituto Tecnico Statale Commerciale e per Geometri Masullo Theti was fined by the Garante €12,000 for operating a video surveillance system without the required authorization. The case concerns a breach of privacy and personal data protection rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 05 Oct 2017 | Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante for publishing a regional council resolution on its website that contained personal evaluations and information about an employee. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 04 Apr 2019 | Bill Size s.r.l.Bill Size s.r.l. was fined by the Garante in the amount of EUR 16,000 for registering phone cards to individuals without their consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 13 Nov 2024 | Thermogen S.r.l.Thermogen S.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The conduct breached the GDPR and national privacy laws. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Oct 2015 | Zhang SuliZhang Suli was fined by the Garante in the amount of EUR 2,400 for operating a video surveillance system at her beauty and massage center without the required privacy notice. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 24 Jan 2013 | Gruppo Finelco s.p.a.Gruppo Finelco s.p.a. was fined EUR 52,000 by the Garante for processing personal data without providing adequate information to data subjects. The company also failed to notify the Garante about profiling activities carried out through its websites. | IT | Garante | GDPR | €52,000 | ↗ |
| 26 Jul 2018 | Associazione MEVALAUTE ONLUSThe association was fined by the Garante for sending unsolicited PEC communications. The authority found that personal data were processed without consent, in breach of data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |
| 28 Apr 2022 | Comune di Monte Sant’AngeloThe Municipality of Monte Sant’Angelo was fined 3,000 EUR by the Garante for breaching data protection principles. The authority found that personal data had been made accessible online in violation of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €3,000 | ↗ |
| 08 Jun 2023 | Liguria News S.r.l.Liguria News S.r.l. was fined by Garante EUR 10,000 for publishing an article that breached privacy rules. The article disclosed personal and sensitive information about individuals involved in the reported incident, including a minor. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2026 | Lex Iuris S.r.l.Lex Iuris S.r.l. was fined by the Garante in the amount of 15,000 EUR for sending unsolicited promotional emails. The authority also found that the company failed to respond to data access requests, breaching transparency and data subject rights obligations. | IT | Garante | GDPR | €15,000 | ↗ |
| 22 May 2018 | De Nittis MicheleDe Nittis Michele, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This deficiency allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2026 | Velletri ServiziVelletri Servizi was fined EUR 2,500 by the Garante for inadequate technical and organizational measures in data processing. The authority found that the company did not meet the requirements of GDPR Article 32. | IT | Garante | GDPR | €2,500 | ↗ |
| 09 Jun 2016 | Angela BellavitaAngela Bellavita was fined EUR 2,400 by the Italian Garante. The case concerned the collection of personal data, including name, surname, and email address, through a website contact form without providing users with adequate information. | IT | Garante | GDPR | €2,400 | ↗ |
| 20 Mar 2008 | Professioni didattiche moderne-P.D.M. s.r.l.P.D.M. s.r.l. was fined for failing to comply with a request to communicate the conformity of personal data processing. The authority found a breach of Article 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 May 2008 | G. & T. Design Comunication s.r.l.G. & T. Design Comunication s.r.l. was fined €4,000 by the Garante for failing to provide the requested information on the acquisition and processing of an email address. The authority treated this as a breach of data protection requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Jul 2023 | Maximum International Corp. S.r.l.The Garante fined Maximum International Corp. S.r.l. 5,000 EUR for making promotional calls without consent and for failing to respond to data access and deletion requests. The case concerns breaches of personal data processing rules and data subject rights. | IT | Garante | GDPR | €5,000 | ↗ |