BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Dec 2021 | ASL LatinaASL Latina was fined for violations of data protection rules. The authority found inadequate measures to prevent data breaches involving health data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2025 | Logika Group s.r.l.Logika Group s.r.l. was fined EUR 5,000 by the Italian supervisory authority, Garante. The authority found that the company sent unsolicited commercial communications and failed to respond to a data access request, in breach of GDPR requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 10 Jul 2025 | Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the Italian authority Garante in the amount of €100,000. The case concerned an inadequate response to a data access request linked to a fraud incident, which breached Article 15 of the GDPR. | IT | Garante | GDPR | €100,000 | ↗ |
| 12 Dec 2024 | Provvedimento del 12 dicembre 2024 [10095836]A doctor was fined EUR 20,000 for breaching core data protection principles. The authority cited failures relating to lawfulness, fairness, transparency, purpose limitation, data minimization, and integrity and confidentiality. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Oct 2025 | Emera SrlEmera Srl was fined by the Garante EUR 6,000 for sending unsolicited promotional SMS messages despite the recipient's repeated requests for data deletion. The authority also found inadequate data retention and organizational procedures to ensure respect for data subject rights. | IT | Garante | GDPR | €6,000 | ↗ |
| 26 May 2011 | DVDR.it s.r.l.DVDR.it s.r.l. was fined EUR 7,000 by the Garante. The authority found that the company sent unsolicited commercial emails without consent, in breach of data protection rules. | IT | Garante | GDPR | €7,000 | ↗ |
| 17 Oct 2024 | Ente di Supporto Tecnico Amministrativo Regionale DirezionaleEnte di Supporto Tecnico Amministrativo Regionale Direzionale was fined 5,000 EUR by the Garante for improper handling of personal data during a public selection process. The issue concerned the transmission of files with incorrect names, even though the content was correct. | IT | Garante | GDPR | €5,000 | ↗ |
| 27 Nov 2024 | Maximum International Corp. S.r.l.Maximum International Corp. S.r.l. was fined by the Garante 10,000 EUR for persistent promotional calls despite objections and for failing to respond to data subject requests. The authority found breaches of GDPR rules on consent and information obligations. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Dec 2016 | Wu KuanzhaoWu Kuanzhao was fined EUR 2,400 by the Garante. The authority found that data subjects were not informed about the processing of personal data through a video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 24 Apr 2024 | Gestore Dei Servizi Energetici - Gse S.p.A.The Garante fined Gestore Dei Servizi Energetici - Gse S.p.A. 30,000 EUR for failing to respond to a data subject access request. The request concerned the individual's personal performance evaluation records for 2019 and 2020. | IT | Garante | GDPR | €30,000 | ↗ |
| 15 Apr 2021 | Ordine degli Avvocati di RomaOrdine degli Avvocati di Roma was fined €2,000 by the Garante for a significant delay in responding to a data subject access request. The case highlights a failure to meet the required timelines for handling access requests under data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 25 Sept 2025 | La Prima SrlLa Prima Srl was fined EUR 10,000 by the Garante for sending unsolicited emails. The authority also found that the company failed to respond to a data deletion request, in breach of the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Apr 2015 | Regione CalabriaRegione Calabria was fined EUR 80,000 by the Garante for failing to designate data processing officers and for only partially implementing IT security measures. The authority also noted a failure to respond to information requests, which required further investigation. | IT | Garante | GDPR | €80,000 | ↗ |
| 09 Mar 2023 | Consorzio Concessioni Reti Gas S.c.a.r.l.The Garante fined Consorzio Concessioni Reti Gas S.c.a.r.l. EUR 2,000 for GDPR breaches linked to the improper handling of email accounts and the failure to provide data processing information after an internship ended. The case highlights deficiencies in information duties and access control over personal data. | IT | Garante | GDPR | €2,000 | ↗ |
| 13 Apr 2023 | Azienda Ospedaliero Universitaria SeneseThe Garante fined Azienda Ospedaliero Universitaria Senese EUR 13,000 for violations related to the processing of personal data in the health sector. The case concerned data minimization and security measures. | IT | Garante | GDPR | €13,000 | ↗ |
| 14 Mar 2013 | Vinci s.r.l.Vinci s.r.l. was fined €6,000 by the Italian data protection authority, Garante. The case concerned the failure to provide the required privacy notice on the website contact form, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 29 Jan 2026 | Provincia della Congregazione dei Fratelli delle Suore CristianeThe entity was fined for failing to ensure sufficient transparency in data processing and for not carrying out a data protection impact assessment for workplace surveillance systems. The authority found breaches of the GDPR and the national privacy code. | IT | Garante | GDPR | €12,000 | ↗ |
| 22 May 2018 | Adolfo AllegriniAdolfo Allegrini, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 May 2021 | Agenzia di Tutela della Salute della Città metropolitana di MilanoAgenzia di Tutela della Salute della Città metropolitana di Milano was fined by the Garante 80,000 EUR for violations linked to data processing during an emergency. The authority found inadequate data protection measures and a failure to provide required information to data subjects. | IT | Garante | GDPR | €80,000 | ↗ |
| 27 Jun 2013 | New Company di Scattolin LorisNew Company di Scattolin Loris was fined EUR 6,400 by the Garante for making unsolicited promotional phone calls without proper consent. The conduct breached Articles 13 and 130 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,400 | ↗ |