BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Jun 2018 | Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined by the Garante €20,000 for sharing access credentials among employees. The authority found this to be a breach of data protection rules and access control requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Feb 2024 | Ordine dei Medici Veterinari della Provincia di LatinaOrdine dei Medici Veterinari della Provincia di Latina was fined by the Garante 5,000 EUR for breaches of data protection principles. The case involved the unlawful communication of personal data to its members. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 Jan 2024 | Società David S.r.l.The Garante imposed an €8,000 fine on Società David S.r.l. for posting on Instagram a video of a patient undergoing a cosmetic procedure without a lawful basis. The authority found breaches of the GDPR principles of lawfulness, fairness, transparency, and purpose limitation. | IT | Garante | GDPR | €8,000 | ↗ |
| 05 Dec 2013 | Langella AlessandroLangella Alessandro was fined EUR 2,400 by the Garante. The case concerned the failure to provide the required privacy notice on www.orofirst.it, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 30 Nov 2017 | CAR SHARING TRENTINO Società CooperativaCAR SHARING TRENTINO Società Cooperativa was fined by the Garante 20,000 EUR. The authority found failures to comply with notification obligations related to vehicle geolocation, constituting a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 30 Jun 2022 | Federazione Italiana Sommelier, Albergatori e RistoratoriFederazione Italiana Sommelier, Albergatori e Ristoratori was fined by the Garante 5,000 EUR for unlawful processing of personal data. The breach involved the improper communication of one member’s data to all associates. | IT | Garante | GDPR | €5,000 | ↗ |
| 17 Mar 2016 | Apcoa Parking Italia spaApcoa Parking Italia spa was fined EUR 4,800 by the Garante for improper use of surveillance images to enforce parking rules and recover debts. The authority also found inadequate data protection information on the company’s website and in its communications with data subjects. | IT | Garante | GDPR | €4,800 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di PordenoneOrdine delle Professioni Infermieristiche di Pordenone was fined 6,000 EUR by the Garante for breaching data protection rules. The authority found that the organization mishandled a data subject request and failed to respect privacy rights. | IT | Garante | GDPR | €6,000 | ↗ |
| 29 Jan 2026 | Istituto tecnico industriale statale “Stanislao Cannizzaro” di CataniaIstituto tecnico industriale statale “Stanislao Cannizzaro” di Catania was fined by the Garante €10,000 for breaches of data protection principles. The authority found that personal data were processed in a manner that was not lawful, fair, or transparent. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Feb 2019 | Ordinanza ingiunzione - 14 febbraio 2019 [9106367]A doctor used the email addresses of former patients to send electoral propaganda without first informing them or obtaining consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 17 Dec 2015 | Zero srlZero srl was fined EUR 2,400 by the Garante for failing to provide the required privacy notice on its website. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 17 Oct 2024 | la SocietàThe company was fined EUR 7,000 by the Garante for violations related to security measures in handling online medical reports and data. The case concerned insufficient safeguards for processed medical information. | IT | Garante | GDPR | €7,000 | ↗ |
| 09 Nov 2017 | GSG Enterprise società cooperativa edileGSG Enterprise was fined EUR 96,000 by the Garante for using the personal data of car owners to demand payment for services that were neither performed nor requested. The case concerns unlawful processing of personal data for debt-collection style demands. | IT | Garante | GDPR | €96,000 | ↗ |
| 23 Oct 2025 | Geturhotels SrlGeturhotels Srl was fined EUR 6,000 by the Garante for sending unsolicited SMS messages to a complainant despite their objection. The authority found that the company’s conduct breached GDPR rules on processing personal data for promotional purposes. | IT | Garante | GDPR | €6,000 | ↗ |
| 11 Feb 2021 | Liceo Pepe CalamoLiceo Pepe Calamo was fined EUR 5,000 by the Garante for publishing teachers' personal data in public rankings on its institutional website. The authority found a breach of data minimization and transparency principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 26 Mar 2010 | Lenzi automobili s.p.a.Lenzi automobili s.p.a. was fined by the Garante for using a biometric system to verify employee attendance without the required authorization. This constituted a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2014 | Eismann s.r.l.Eismann s.r.l. was fined by the Garante 40,000 EUR for making promotional phone calls without prior express consent from recipients. The company also concealed the caller's identity, which breached Italian data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Nov 2015 | Pasticceria Gelateria Bar D.D. & D. di Davide Busato & C. s.n.c.The company was fined by the Garante 2,400 EUR for operating a video surveillance system without providing the simplified information notice required under data protection law. The breach concerned the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Apr 2011 | Mansutti S.p.A.Mansutti S.p.A. was fined EUR 12,000 by the Garante for failing to provide the required data protection notice on its website forms. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €12,000 | ↗ |
| 17 Apr 2014 | Comune di CavedineThe Municipality of Cavedine was fined by the Garante 4,000 EUR for publishing personal data online longer than legally permitted. The case concerned a breach of data protection rules and limits on online retention. | IT | Garante | GDPR | €4,000 | ↗ |