BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 May 2024 | Azienda Socio-sanitaria Territoriale RhodenseAzienda Socio-sanitaria Territoriale Rhodense was fined EUR 4,500 by the Garante for breaching GDPR Article 16. The case concerned data processing in the health sector, where strict compliance controls are required. | IT | Garante | GDPR | €4,500 | ↗ |
| 10 Nov 2022 | Comune di Cisterna di LatinaComune di Cisterna di Latina was fined 5,000 EUR by the Garante for violating data protection principles, including data minimization. Improper handling of personal data led to unauthorized access by third parties. | IT | Garante | GDPR | €5,000 | ↗ |
| 12 Feb 2026 | Based s.r.l.Based s.r.l. was fined by the Garante EUR 12,000 for providing an inadequate response to a data subject’s request for access to and deletion of email account data. The authority found that the company failed to comply with GDPR requirements on data subject rights. | IT | Garante | GDPR | €12,000 | ↗ |
| 13 Nov 2025 | Comune di OrteComune di Orte was fined EUR 6,000 by the Garante for installing surveillance cameras without ensuring the required transparency in data processing. The authority found breaches of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €6,000 | ↗ |
| 28 Apr 2022 | Istituto Nazionale Assicurazione Infortuni sul LavoroIstituto Nazionale Assicurazione Infortuni sul Lavoro was fined by the Garante EUR 20,000. The authority found that inadequate technical and organizational measures led to a data breach. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Feb 2018 | Transpe S.p.A.Transpe S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to notify the installation of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 17 Apr 2026 | Azienda USL ModenaAzienda USL Modena was fined by the Garante in the amount of 10,000 EUR for a data breach caused by a ransomware attack. The authority found a breach of GDPR data security obligations. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Dec 2014 | Enrico TecchioThe Garante fined Enrico Tecchio EUR 2,400 for failing to provide data subjects with information about the processing of personal data through a video surveillance system at a dental practice. The case concerned the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €2,400 | ↗ |
| 06 Jul 2023 | Regione SicilianaThe Garante fined Regione Siciliana EUR 7,000 for publishing personal data of numerous individuals, including sensitive employment-related information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €7,000 | ↗ |
| 23 Jun 2025 | Ordine delle Professioni Infermieristiche di ViterboThe Garante imposed a fine of EUR 10,000 on the Ordine delle Professioni Infermieristiche di Viterbo for breaches of data protection rules. The case concerned non-compliance with requirements governing the processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 03 Mar 2016 | Comune di Ischia di CastroThe Municipality of Comune di Ischia di Castro was fined 4,000 EUR by the Garante for unlawfully publishing personal data of jury members on its online notice board for longer than the legally permitted period. The case concerned a breach of data protection rules and retention limits. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jun 2017 | Bookingshow s.p.a.Bookingshow s.p.a. was fined EUR 62,000 by the Garante for unlawfully processing personal data. The company required mandatory consent for promotional purposes during online ticket purchases, which breached data processing rules. | IT | Garante | GDPR | €62,000 | ↗ |
| 08 Feb 2024 | Medtronic Italia S.p.a.Medtronic Italia S.p.a. was fined by the Garante in the amount of €300,000 for a data protection breach. The authority found inadequate technical and organizational measures that led to unauthorized disclosure of data. | IT | Garante | GDPR | €300,000 | ↗ |
| 10 Apr 2025 | Stefanelli FedericaThe Garante imposed a 45,000 EUR fine on Stefanelli Federica for processing personal data without proper consent in unauthorized call-center operations. The case also involved sensitive data, including payment method information, which could have led to unauthorized contract activations. | IT | Garante | GDPR | €45,000 | ↗ |
| 16 Jan 2026 | Associazione Turistica Pro Loco di CittarealeThe association unlawfully disclosed the personal data of 23 members by publishing it in a public notice and online. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €600 | ↗ |
| 06 Feb 2014 | Oreiade s.r.l.Oreiade s.r.l. was fined by the Garante for installing a video surveillance system at Hotel Blu Inn without adequate safeguards. The authority found a breach of data protection rules. | IT | Garante | GDPR | €24,400 | ↗ |
| 09 Jan 2014 | Giallooro s.r.lGiallooro s.r.l was fined EUR 2,400 by the Garante for collecting personal data through a website contact form without providing the required privacy notice. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 03 May 2018 | Pace MarinaPace Marina, a general practitioner, was fined by the Garante for failing to implement minimum security measures to protect patients’ personal and sensitive data. This failure allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Apr 2025 | Regione Emilia RomagnaThe Garante fined Regione Emilia Romagna EUR 15,000 for violations related to the processing of personal data for official statistical purposes. The authority found incorrect application of data protection principles and measures. | IT | Garante | GDPR | €15,000 | ↗ |
| 17 Apr 2026 | Provvedimento del 17 aprile 2026 [10254325]The supervisory authority found that a video surveillance system with 25 cameras operated without the required informational signage. The breach concerned GDPR information obligations. | IT | Garante | GDPR | €3,000 | ↗ |