BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Oct 2014 | Simply Gold s.r.l.Simply Gold s.r.l. was fined by the Garante for collecting personal data through a website form without providing the required information notice to data subjects. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 13 Apr 2023 | Azienda Ospedaliera Universitaria di CagliariAzienda Ospedaliera Universitaria di Cagliari was fined EUR 8,000 by the Garante for unlawfully publishing personal data related to a disciplinary procedure online. The authority found breaches of data minimization and transparency principles. | IT | Garante | GDPR | €8,000 | ↗ |
| 09 Oct 2014 | Comune di Lamezia TermeThe Municipality of Lamezia Terme was fined 4,000 EUR by the Garante. The authority found that personal data, including names, tax codes, and IBANs, had been published on its website without a legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Dec 2024 | Istituto Comprensivo Statale CalenzanoIstituto Comprensivo Statale Calenzano was fined EUR 1,000 by the Garante for breaching data protection principles. The case concerned the processing of personal data without meeting the requirements of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 21 Feb 2013 | Elettrodomestici Parise sncElettrodomestici Parise snc was fined 222,000 EUR by the Italian Garante. The company improperly registered numerous phone cards to unaware third parties and then sold them to phone centers, breaching data protection rules. | IT | Garante | GDPR | €222,000 | ↗ |
| 14 Sept 2023 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined 42,000 EUR by the Garante for failing to provide timely access to personal data requested by a parent under GDPR Article 15. The authority said the delay resulted from an operational error that prevented timely handling of the request. | IT | Garante | GDPR | €42,000 | ↗ |
| 20 Nov 2014 | Andrea Romualdo CerriAndrea Romualdo Cerri was fined €2,400 by the Garante. The violation concerned failing to provide the required information to data subjects when collecting personal data through a web form on the company website. | IT | Garante | GDPR | €2,400 | ↗ |
| 13 Sept 2017 | Serval s.r.l.Serval s.r.l. was fined by the Garante in the amount of €10,000 for failing to adopt minimum security measures. The authority also found that employees were not appointed as data processors, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Oct 2015 | Macellerie Rinaldo Giampaolo e figli sncMacellerie Rinaldo Giampaolo e figli snc was fined EUR 2,400 by the Garante. The authority found that the company failed to inform data subjects about the processing of personal data through a video surveillance system, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 17 Apr 2026 | Istituto “Ancelle della Compagnia della Regina dei Gigli”The Garante fined the school EUR 4,000 for processing students’ personal data without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Aug 2022 | Mister Brick S.a.s.Mister Brick S.a.s. was fined EUR 1,000 by the Garante for sending an unsolicited promotional email without obtaining prior consent from the recipient. The authority found this to be a breach of GDPR requirements on lawful processing and consent. | IT | Garante | GDPR | €1,000 | ↗ |
| 22 Jul 2021 | Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5)Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5) was fined EUR 4,000 by the Garante for violations related to the processing of personal data, including health data, during the COVID-19 pandemic. The case concerned improper handling of sensitive data in the context of pandemic-related activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 20 Oct 2022 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined by the Garante €40,000 for failing to provide a data subject with access to personal data relating to derivative transactions. The authority found a breach of the principles of lawful, fair, and transparent processing. | IT | Garante | GDPR | €40,000 | ↗ |
| 11 Feb 2016 | E-Via s.p.a.E-Via s.p.a. was fined 10,000 EUR by the Garante for failing to implement minimum security measures in the processing of telematic traffic data. The authority found a breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 May 2026 | Action Fit di MilanoThe Garante fined Action Fit di Milano EUR 3,930 for sending unsolicited commercial emails to a customer without consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €3,930 | ↗ |
| 31 Aug 2023 | RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined by the Garante EUR 10,000 for publishing an article on the Corriere della Sera website. The article included a photograph of a holographic will that disclosed a witness’s personal data without consent. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Feb 2016 | Vito Roma s.r.l.Vito Roma s.r.l. was fined by the Garante for operating a video surveillance system without providing the required data protection notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 18 Apr 2013 | Itel s.r.l. UnipersonaleItel s.r.l. Unipersonale was fined EUR 102,000 by the Garante for improper processing of personal data. The case involved registering phone cards to third parties without their knowledge, in breach of privacy rules. | IT | Garante | GDPR | €102,000 | ↗ |
| 13 Feb 2025 | MDE – Movimento Diritti Europei s.r.l.s.MDE – Movimento Diritti Europei s.r.l.s. was fined 15,000 EUR by the Garante. The authority found that the company failed to provide shareholders with the information required under GDPR Article 14 and instead referred them to a website that did not contain sufficient details. | IT | Garante | GDPR | €15,000 | ↗ |
| 17 Jul 2024 | Mark s.r.l.s.Mark s.r.l.s. was fined by the Garante for operating a video surveillance system without the required signage. The case concerned a breach of GDPR information obligations. | IT | Garante | GDPR | €5,000 | ↗ |