BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Feb 2014 | Giuseppe IlacquaGiuseppe Ilacqua was fined for inadequate data protection measures related to a video surveillance system. The authority found insufficient employee notification and improper image retention practices. | IT | Garante | GDPR | €6,000 | ↗ |
| 20 Jul 2017 | Centro Laser s.r.l.Centro Laser s.r.l. was fined EUR 20,400 by the Garante for using inadequate password procedures and failing to provide required information on data processing to users. The case concerns breaches of data protection rules. | IT | Garante | GDPR | €20,400 | ↗ |
| 11 Jun 2015 | Allevi BortoloAllevi Bortolo was fined EUR 15,000 by the Garante for activating fourteen phone cards in the names of five individuals without their knowledge. The conduct breached data protection rules and led to supervisory enforcement. | IT | Garante | GDPR | €15,000 | ↗ |
| 21 Jul 2022 | Clio s.r.l.Clio s.r.l. was fined by the Italian Garante in the amount of 10,000 EUR for violations related to personal data processing. The case involved inadequate protection of whistleblower identities, in breach of the GDPR and national privacy code provisions. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jan 2010 | Casa di cura privata Di Lorenzo s.p.a.The private clinic Casa di cura privata Di Lorenzo s.p.a. was fined by the Garante for breaching data protection rules. The authority found that it failed to comply with notification obligations under the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 31 Jan 2019 | Comune di CataniaThe Municipality of Catania was fined EUR 6,000 by the Garante for unlawfully publishing personal data on its institutional website in connection with housing and rental assistance programs. The disclosed information included names, dates of birth, tax codes, and addresses. | IT | Garante | GDPR | €6,000 | ↗ |
| 06 Jul 2016 | Impresa Individuale Autosalone Ag. Car di Vitale AldoThe company collected personal data, including name and email address, through its website. It did not provide the required privacy notice, which breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 06 Jul 2023 | Provvedimento del 6 luglio 2023 [9925450The Garante imposed a EUR 2,000 fine on an individual for posting images of other people on social media without their consent. The authority found a breach of GDPR rights, including the rights to erasure and objection. | IT | Garante | GDPR | €2,000 | ↗ |
| 30 Jan 2014 | impresa individuale Otelma di Belelli Marco AmletoThe sole proprietorship Otelma di Belelli Marco Amleto was fined EUR 6,400 by the Garante for failing to implement minimum security measures when processing sensitive data via its website. The breaches included not appointing a data processor and not preparing a security program document. | IT | Garante | GDPR | €6,400 | ↗ |
| 14 Sept 2023 | Comune di San SeveroThe Municipality of San Severo was fined EUR 10,000 by the Garante for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 May 2014 | Concetta VivinoConcetta Vivino was fined by the Garante in the amount of EUR 2,400 for failing to provide adequate simplified information about the use of a video surveillance system. This constituted a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Nov 2014 | One Italia s.r.l.One Italia s.r.l. was fined €200,000 by the Garante for sending unsolicited promotional messages related to a value-added service. The authority found that proper consent and adequate information were not obtained, in breach of data protection rules. | IT | Garante | GDPR | €200,000 | ↗ |
| 11 Mar 2021 | dott. Gregorio GrecoDott. Gregorio Greco was fined 6,400 EUR by the Garante for failing to provide information to data subjects and for processing patients' health-related personal data without consent. The case concerns patient data and breaches of transparency and lawful basis requirements. | IT | Garante | GDPR | €6,400 | ↗ |
| 24 Apr 2024 | Dly S.r.l.Dly S.r.l. was fined by the Garante EUR 5,000 for deploying a non-compliant video surveillance system. The system recorded both customers and employees, in breach of data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 08 Feb 2007 | Comune di FirenzeGarante imposed a EUR 3,000 fine on Comune di Firenze for failing to provide adequate information to individuals about the processing of personal data through a video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 04 Aug 2025 | Linea Stampalibera Società Cooperativa r.l.The Garante imposed a EUR 2,000 fine on Linea Stampalibera Società Cooperativa r.l. for unlawfully disseminating personal data, including health information, on its online news site. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 09 Jun 2016 | Montanaro Auto s.r.l.Montanaro Auto s.r.l. was fined by the Garante in the amount of 4,800 EUR for failing to provide data subjects with information about data processing. The breach concerned a video surveillance system and a web form, in violation of the Italian Data Protection Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 16 Nov 2017 | Sarida s.r.l.Sarida s.r.l. was fined by the Italian Garante 10,000 EUR for inadequate security measures in the processing of personal data. The authority specifically noted insufficient password requirements for access to the company’s systems. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Apr 2026 | Consiglio Nazionale dei Periti Industriali e dei Periti Industriali LaureatiThe Consiglio Nazionale dei Periti Industriali e dei Periti Industriali Laureati was fined €3,000 by the Garante. The authority found that the organization failed to ensure transparency in data processing, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €3,000 | ↗ |
| 19 Sept 2013 | Estav Nordovest ToscanaEstav Nordovest Toscana was fined 10,000 EUR by the Garante. The violation concerned the unlawful publication of candidates' judicial data on its website during a recruitment process. | IT | Garante | GDPR | €10,000 | ↗ |