BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Mar 2025 | Provvedimento del 27 marzo 2025 [10140216]The Garante fined Powerfit, Soleo, and Zero Due Villa for sending promotional SMS messages without the recipients’ consent. The messages also did not provide an opt-out mechanism, which breached GDPR requirements. | IT | Garante | GDPR | €6,000 | ↗ |
| 26 Feb 2020 | Comune di Fogliano RedipugliaThe Municipality of Comune di Fogliano Redipuglia was fined by the Garante for unlawfully publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €6,000 | ↗ |
| 10 Jul 2014 | Onbrand Call s.r.lOnbrand Call s.r.l was fined by the Garante for processing personal data through a web form without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 18 Sept 2008 | Universitalia s.r.l.Universitalia s.r.l. was fined €6,000 by the Italian data protection authority, Garante. The authority found that the company failed to provide adequate privacy information to data subjects as required by the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 29 Apr 2021 | Azienda socio sanitaria territoriale Melegnano e della MartesanaAzienda socio sanitaria territoriale Melegnano e della Martesana was fined by the Garante €6,000 for a data breach involving the loss of health data. The case concerned special-category personal data and indicates insufficient organizational or technical safeguards. | IT | Garante | GDPR | €6,000 | ↗ |
| 27 Mar 2025 | Corriere del Giorno 1947 Media Group Soc. Coop. ArlThe Garante imposed a fine of 6,000 EUR on Corriere del Giorno 1947 Media Group Soc. Coop. Arl for violations related to the right to be forgotten. The authority found that certain articles were no longer relevant and were not in the public interest. | IT | Garante | GDPR | €6,000 | ↗ |
| 18 Jul 2013 | Yang YijieYang Yijie was fined EUR 6,000 by the Garante for failing to provide the required privacy notice in connection with a video surveillance system at his business. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 01 Jan 2019 | AMADOR RECREATIVOS, S.L.AMADOR RECREATIVOS, S.L. was fined by the AEPD 6,000 EUR for installing a video surveillance system aimed at public space without justified cause. The case concerned an unjustified scope of monitoring and a breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 24 Feb 2010 | Alampi Carmela & C. s.n.c. di Sapone GiovannaThe company was fined for processing personal data through a video surveillance system without providing the required simplified and detailed information to data subjects. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 13 Jan 2022 | A.S.L. Napoli 1 CentroA.S.L. Napoli 1 Centro was fined EUR 6,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data in violation of lawfulness, fairness, transparency, and data minimization requirements. | IT | Garante | GDPR | €6,000 | ↗ |
| 24 Mar 2022 | Azienda sanitaria provinciale di CaltanissettaAzienda sanitaria provinciale di Caltanissetta was fined for failing to update the Data Protection Officer’s contact details on its website and in communications with the Authority. The conduct breached GDPR Article 37. | IT | Garante | GDPR | €6,000 | ↗ |
| 01 Dec 2022 | A.R.N.A.S. CivicoA.R.N.A.S. Civico was fined EUR 6,000 by the Italian authority Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €6,000 | ↗ |
| 01 Jan 2012 | IBEREXPERT GRUPO CONSULTOR INFORMATICO, S.L.IBEREXPERT GRUPO CONSULTOR INFORMATICO, S.L. was fined by the AEPD in the amount of 6,000 EUR for sending unsolicited commercial communications after a request to stop. The conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 20 Feb 2014 | Giuseppe IlacquaGiuseppe Ilacqua was fined for inadequate data protection measures related to a video surveillance system. The authority found insufficient employee notification and improper image retention practices. | IT | Garante | GDPR | €6,000 | ↗ |
| 31 Jan 2019 | Comune di CataniaThe Municipality of Catania was fined EUR 6,000 by the Garante for unlawfully publishing personal data on its institutional website in connection with housing and rental assistance programs. The disclosed information included names, dates of birth, tax codes, and addresses. | IT | Garante | GDPR | €6,000 | ↗ |
| 15 May 2013 | HU YonghuHU Yonghu was fined EUR 6,000 by the Garante for failing to provide the required privacy notice for the restaurant surveillance system. The case concerned non-compliance with the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 13 Nov 2025 | Comune di OrteComune di Orte was fined EUR 6,000 by the Garante for installing surveillance cameras without ensuring the required transparency in data processing. The authority found breaches of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €6,000 | ↗ |
| 08 Apr 2022 | B.B.B.The entity was fined by the AEPD for recording audio through a video surveillance system without informing the employee. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 23 Sept 2014 | XD SOFTWARE, S.L.XD SOFTWARE, S.L. was fined by the AEPD in the amount of 6,000 EUR for sending unsolicited commercial emails and messages without recipient consent. The conduct breached Article 21 of the LSSI and involved marketing communications sent without prior authorization. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 11 Apr 2024 | Libero Consorzio comunale di EnnaThe Garante fined Libero Consorzio comunale di Enna €6,000 for improperly assigning tasks to the Data Protection Officer. Those tasks should have been performed by the data controller or processor, not the DPO. | IT | Garante | GDPR | €6,000 | ↗ |