BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Oct 2015 | Semplice viaggi s.r.l.Semplice viaggi s.r.l. was fined EUR 6,400 by the Garante for providing insufficient information to users on its website and for pre-setting consent to the processing of personal data for promotional purposes. The authority found these practices to be in breach of data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 06 Nov 2014 | Fengfeng WuFengfeng Wu was fined by the Garante in the amount of EUR 2,400 for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system at Bar Wu Fengfeng in Milan. The case concerns a breach of transparency and information obligations linked to CCTV processing. | IT | Garante | GDPR | €2,400 | ↗ |
| 09 May 2024 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante for violations related to telemarketing and teleselling. The authority found that individuals listed in the opposition register were contacted without proper consent. | IT | Garante | GDPR | €500,000 | ↗ |
| 17 Oct 2013 | Ideal Service srlIdeal Service srl was fined by the Garante EUR 2,400 for sending promotional emails without the required privacy information. The authority found this to be a breach of Article 161 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Apr 2011 | Trentino Trasporti Esercizio S.p.A.Trentino Trasporti Esercizio S.p.A. was fined by the Garante 25,000 EUR for collecting personal data through web forms without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €25,000 | ↗ |
| 11 Apr 2024 | Comune di MadignanoThe Garante fined Comune di Madignano EUR 3,000 for unlawfully using surveillance data in a disciplinary proceeding against an employee. The authority found breaches of data protection and transparency principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 10 Jun 2020 | Istituto autonomo per le case popolari della provincia di IserniaIstituto autonomo per le case popolari della provincia di Isernia was fined EUR 2,000 by the Garante. The authority found that personal data, including health information, had been published on the institutional website without a proper legal basis. | IT | Garante | GDPR | €2,000 | ↗ |
| 26 Feb 2026 | Dedalus Italia S.p.A.Dedalus Italia S.p.A. was fined EUR 32,000 by the Garante for inadequate security measures that led to a data breach. The company implemented corrective actions promptly, but prior violations were taken into account when setting the penalty. | IT | Garante | GDPR | €32,000 | ↗ |
| 19 Sept 2013 | dott. Luigi Ventronedott. Luigi Ventrone was fined for failing to respond to requests for information concerning the processing of personal data in connection with a complaint by Ms. Ilaria Corsale. The authority found a breach of Article 157 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Dec 2022 | Amazon Italia Logistica s.r.l.Amazon Italia Logistica s.r.l. was fined by the Garante for delaying its response to a data subject’s request to access professional certificates. The authority found a breach of Article 15 GDPR. | IT | Garante | GDPR | €20,000 | ↗ |
| 24 Feb 2011 | Federconsorzi Dolomiti SuperskiFederconsorzi Dolomiti Superski was fined EUR 12,000 by the Italian Garante. The authority found that the company failed to provide the required data protection information to individuals, in breach of Articles 13 and 161 of the Italian Data Protection Code. | IT | Garante | GDPR | €12,000 | ↗ |
| 28 Jul 2016 | Jurica PavicJurica Pavic was fined by the Garante for failing to provide adequate information to data subjects about video surveillance. The authority found this to be a breach of privacy regulations. | IT | Garante | GDPR | €2,400 | ↗ |
| 11 Sept 2025 | Casa di Cura Città di RomaCasa di Cura Città di Roma was fined EUR 12,000 by the Garante for allowing unauthorized access to patient medical records. The case concerns a breach of data protection rules and indicates a need for stronger access controls. | IT | Garante | GDPR | €12,000 | ↗ |
| 06 Jul 2006 | Comune di AugustaThe Municipality of Augusta was fined by the Garante for failing to make a required notification under data protection law. The breach concerned Article 163 of the Codice Privacy. | IT | Garante | GDPR | €5,164 | ↗ |
| 18 Dec 2013 | Comune di MonticianoThe Municipality of Monticiano was fined 8,000 EUR by the Garante. The authority found a privacy violation after the municipality failed to provide requested information about the publication of personal data on its institutional website. | IT | Garante | GDPR | €8,000 | ↗ |
| 23 Oct 2025 | Provvedimento del 23 ottobre 2025 [10210718]The Garante imposed a EUR 10,000 fine on an individual tobacco shop owner for suspicious financial transactions involving the misuse of a third party’s identification data with a prepaid card. The case concerns unauthorized use of personal data in the context of payment operations. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Apr 2023 | Retimedia S.r.l.Retimedia S.r.l. was fined 2,500 EUR by the Garante for publishing detailed health data of an individual without consent. The conduct breached GDPR Article 9 on special categories of personal data. | IT | Garante | GDPR | €2,500 | ↗ |
| 03 May 2018 | Omis s.p.a.Omis s.p.a. was fined by the Garante 8,000 EUR for failing to notify the processing of geolocation data from vehicles. This notification was required under privacy regulations. | IT | Garante | GDPR | €8,000 | ↗ |
| 18 Nov 2015 | Zsa Zsa srlZsa Zsa srl was fined EUR 2,400 by the Italian Garante. The violation concerned the failure to provide the required privacy notice on the website’s data collection form, in breach of the Italian data protection code. | IT | Garante | GDPR | €2,400 | ↗ |
| 15 Jun 2011 | Azienda Multiservizi e Igiene Urbana S.p.A.Azienda Multiservizi e Igiene Urbana S.p.A. was fined for collecting personal data through a web form without providing users with the required privacy notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |