BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Apr 2025 | Comune di NoliComune di Noli was fined EUR 2,000 by the Garante for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found a breach of data minimization because unauthorized access to unredacted images was possible through an online portal. | IT | Garante | GDPR | €2,000 | ↗ |
| 11 Jan 2024 | Provincia di CatanzaroThe Garante fined Provincia di Catanzaro EUR 2,000 for violations of data protection obligations under Article 37 GDPR. The case concerned non-compliance with requirements related to the designation of a data protection officer. | IT | Garante | GDPR | €2,000 | ↗ |
| 25 Feb 2016 | COF Lanzo Hospital SpaCOF Lanzo Hospital Spa was fined by the Garante for failing to respond to an information request concerning the handling of patient medical records. The authority found a breach of Article 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Dec 2014 | Manca FedericoManca Federico was fined by the Garante in the amount of EUR 2,400 for failing to provide the required information to data subjects when collecting personal data through a web form on his website. The case concerns a breach of transparency and information duties in online data collection. | IT | Garante | GDPR | €2,400 | ↗ |
| 29 Nov 2018 | Istituto Nazionale Previdenza Sociale (INPS)INPS was fined for processing the personal data of 12.6 million private workers using automated software without prior verification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 13 Nov 2024 | Istituto Nazionale della Previdenza SocialeThe Italian Data Protection Authority fined Istituto Nazionale della Previdenza Sociale (INPS) EUR 40,000 for violations related to the processing of personal data for official statistics. The authority found that the processing did not comply with core data protection principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 21 Sept 2017 | Unidata s.p.a.Unidata s.p.a. was fined EUR 36,000 by the Garante for failing to implement adequate security measures for personal data processing. The authority noted, among other issues, the use of passwords shorter than eight characters, which breached data protection requirements. | IT | Garante | GDPR | €36,000 | ↗ |
| 08 Mar 2018 | Riacetech S.r.l.Riacetech S.r.l. was fined for failing to notify the Garante about the installation of a biometric data processing system for employees. The case concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Jan 2015 | Iper Market Yi-Gou s.r.l.Iper Market Yi-Gou s.r.l. was fined EUR 6,000 by the Italian supervisory authority, Garante. The case concerned the failure to provide the required information to data subjects about personal data processing through a video surveillance system. | IT | Garante | GDPR | €6,000 | ↗ |
| 01 Jun 2016 | Liceo Scientifico di Stato G. BattagliniLiceo Scientifico di Stato G. Battaglini was fined by the Garante 10,400 EUR for processing staff biometric data without providing the required information. The authority also found that the processing had not been notified as required by law. | IT | Garante | GDPR | €10,400 | ↗ |
| 17 Jul 2024 | Hera Comm S.p.A.Hera Comm S.p.A. was fined by the Garante 5,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy contracts and insurance policies with forged signatures. | IT | Garante | GDPR | €5,000,000 | ↗ |
| 14 Sept 2006 | Centro diagnostico Helios s.n.c.Centro diagnostico Helios s.n.c. was fined for failing to notify the processing of sensitive health data, including HIV status and other medical conditions. The authority treated this as a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Apr 2018 | Azienda Ospedaliera Sant’Andrea di RomaAzienda Ospedaliera Sant’Andrea di Roma was fined 32,000 EUR by the Garante for violations related to the processing of personal data in healthcare services. The case concerned deficiencies in consent handling and patient information forms. | IT | Garante | GDPR | €32,000 | ↗ |
| 07 May 2015 | V.V.S. s.r.l. Viaggi Vacanze Soggiorni StudioV.V.S. s.r.l. was fined by the Italian data protection authority, Garante, in the amount of €2,400. The case concerned the collection of personal data through website forms without providing the required privacy notice, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 10 Jun 2021 | Foodinho s.r.l.Foodinho s.r.l. was fined by the Garante EUR 2,600,000 for violations in the processing of riders’ personal data. The authority cited insufficient data minimization, inadequate privacy by design measures, and automated decision-making without proper human intervention. | IT | Garante | GDPR | €2,600,000 | ↗ |
| 26 Jul 2017 | Istituto scolastico "A. Mantegna"Istituto scolastico "A. Mantegna" was fined by the Garante for unlawfully publishing students’ personal data, including sensitive information, on its website without a legal basis. The case concerned a breach of lawfulness and data minimization requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 08 May 2013 | Business Services s.r.lBusiness Services s.r.l was fined EUR 6,400 by the Garante. The case concerned the sending of promotional faxes without the required information and without obtaining explicit consent from recipients. | IT | Garante | GDPR | €6,400 | ↗ |
| 14 Jan 2021 | Azienda Usl di BolognaAzienda Usl di Bologna was fined by the Garante 18,000 EUR for violations related to personal data protection in the healthcare sector. The case concerned irregularities in the processing of patient data, which breached data protection requirements. | IT | Garante | GDPR | €18,000 | ↗ |
| 23 Oct 2025 | Zephiromedia S.r.l.Zephiromedia S.r.l. was fined EUR 30,000 by the Garante for sending unsolicited promotional emails. The authority also found that recipients were not given an effective way to unsubscribe or exercise their rights. | IT | Garante | GDPR | €30,000 | ↗ |
| 01 Oct 2015 | Comune di Loiri Porto San PaoloThe Municipality of Comune di Loiri Porto San Paolo was fined by the Garante 10,000 EUR for publishing personal data on its website that revealed health status. The case involved unlawful disclosure of sensitive data in breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |