BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Apr 2014 | Torre Marina s.r.l.Torre Marina s.r.l. was fined €2,400 by the Italian Garante. The case concerned the collection of personal data through its websites without the required information notice under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 16 May 2018 | Ierardi TeresaIerardi Teresa, a general practitioner, was fined by the Garante for failing to adopt minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Apr 2013 | Tel. Com. s.r.l.Tel. Com. s.r.l. was fined EUR 36,000 by the Garante for registering numerous phone cards to unaware third parties. The company failed to provide the required information on data processing, which breached privacy rules. | IT | Garante | GDPR | €36,000 | ↗ |
| 13 Sept 2007 | Comune di MoncalieriComune di Moncalieri was fined by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the notification obligation under Article 37 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Jun 2015 | Azienda Ospedaliera Ospedale di Circolo Fondazione MacchiAzienda Ospedaliera Ospedale di Circolo Fondazione Macchi was fined by the Garante 4,000 EUR for processing sensitive personal data without obtaining written consent. This breached the Italian Data Protection Code. The case highlights the need for a valid legal basis before processing special-category data. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Jan 2019 | Istituto Statale di Istruzione Superiore “Guglielmo Marconi”Istituto Statale di Istruzione Superiore “Guglielmo Marconi” was fined by the Garante €4,000 for unlawfully processing personal data. The school published teacher rankings on its website that disclosed health information, breaching privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 May 2008 | Circolo privato 'Astoria'The private club “Astoria” was fined 3,000 EUR by the Garante for failing to provide the required data protection notice to individuals identified through its video surveillance system. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 17 Jul 2024 | Selectra S.p.A.Selectra S.p.A. was fined EUR 80,000 by the Garante for unlawfully accessing and retaining a former employee's email account after the end of the collaboration. The authority found that the company's conduct breached data protection rules. | IT | Garante | GDPR | €80,000 | ↗ |
| 18 Jul 2023 | Cat s.r.l.The Garante imposed a EUR 10,000 fine on Cat s.r.l. for operating a video surveillance system near waste bins in breach of the principles of lawfulness, fairness, and transparency. The case concerned the data of residents and non-residents of the Comune di Modica. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Jun 2013 | Terme di Agnano s.p.a.Terme di Agnano s.p.a. was fined EUR 16,000 by the Garante for processing personal and sensitive data of individuals undergoing thermal treatments without the required notice and consent. The authority also found that personal data of job applicants were processed without providing the mandatory information notice. | IT | Garante | GDPR | €16,000 | ↗ |
| 13 May 2015 | Comune di LandrianoComune di Landriano was fined for processing personal data of children enrolling in the municipal nursery without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 27 Mar 2025 | Comune di Palma di MontechiaroThe Municipality of Comune di Palma di Montechiaro was fined EUR 3,000 by the Italian data protection authority, Garante. The sanction concerned the failure to communicate the contact details of its Data Protection Officer to the authority, as required by Article 37 GDPR. | IT | Garante | GDPR | €3,000 | ↗ |
| 14 Jan 2021 | Comune di Falconara MarittimaComune di Falconara Marittima was fined EUR 10,000 by the Garante for violating data protection principles. The authority found improper processing of personal data in a disciplinary context, including breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Apr 2018 | Broker & Broker s.r.l.Broker & Broker s.r.l. was fined EUR 340,000 by the Italian authority Garante. The case concerned the registration of numerous phone cards to third parties without their knowledge or consent, which breached data protection rules. | IT | Garante | GDPR | €340,000 | ↗ |
| 12 Nov 2014 | Associazione sportiva dilettantistica Sport Fashion (A.S.D. Sport Fashion)The sports association was fined by the Garante 10,000 EUR for processing clients' biometric data without the required information and consent. The authority found this to be a breach of privacy rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Feb 2026 | Ministero dell’Economia e delle FinanzeThe Ministry of Economy and Finance was fined 12,000 EUR by Garante for inadequate control measures over the data processor. The authority found breaches of GDPR Articles 3, 5 and 6, as well as Article 2-ter of the Italian Privacy Code. | IT | Garante | GDPR | €12,000 | ↗ |
| 13 May 2021 | ATS di Bergamo, Agenzia di Tutela della saluteATS di Bergamo was fined by the Garante 20,000 EUR for violations involving the improper handling of sensitive health data. The case concerned the use of email to transmit data, which did not provide an adequate level of protection. | IT | Garante | GDPR | €20,000 | ↗ |
| 18 Jun 2015 | Martino MarangellaMartino Marangella was fined EUR 2,400 by the Garante for failing to provide simplified information about the use of a video surveillance system. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 26 Feb 2026 | Flamel S.r.l.Flamel S.r.l. was fined by the Garante 15,000 EUR for carrying out promotional activities without a legal basis. The company used phone numbers not registered with the ROC, affecting the data of more than 500 individuals. | IT | Garante | GDPR | €15,000 | ↗ |
| 17 Dec 2020 | Comune di LuinoComune di Luino was fined EUR 10,000 by the Garante for unlawfully disclosing personal data online. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €10,000 | ↗ |