BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Sept 2025 | ISV Group SrlsISV Group Srls was fined €15,000 by the Garante for sending unsolicited promotional emails without consent. The authority also found that the company failed to properly control its partner Ismax, which carried out unlawful data processing activities. | IT | Garante | GDPR | €15,000 | ↗ |
| 26 Feb 2026 | Istituto Tecnico Statale L. 80014050357Istituto Tecnico Statale was fined by the Garante for breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization. The school improperly published personal data on its website. | IT | Garante | GDPR | €2,000 | ↗ |
| 15 Mar 2018 | Istituto Tecnico Statale Commerciale e per Geometri Masullo ThetiIstituto Tecnico Statale Commerciale e per Geometri Masullo Theti was fined by the Garante €12,000 for operating a video surveillance system without the required authorization. The case concerns a breach of privacy and personal data protection rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 29 Jan 2026 | Istituto tecnico industriale statale “Stanislao Cannizzaro” di CataniaIstituto tecnico industriale statale “Stanislao Cannizzaro” di Catania was fined by the Garante €10,000 for breaches of data protection principles. The authority found that personal data were processed in a manner that was not lawful, fair, or transparent. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Feb 2016 | Istituto Tecnico Industriale Ettore MajoranaIstituto Tecnico Industriale Ettore Majorana was fined for processing biometric data for attendance tracking without the required notification to the Garante. This breached the Italian Privacy Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 11 Feb 2021 | Istituto Superiore Statale "Pitagora"Istituto Superiore Statale "Pitagora" was fined by the Garante 5,000 EUR for unlawful processing of personal data. The authority found failures to ensure data minimization and transparency toward data subjects. | IT | Garante | GDPR | €5,000 | ↗ |
| 31 Jan 2019 | Istituto Statale di Istruzione Superiore “Guglielmo Marconi”Istituto Statale di Istruzione Superiore “Guglielmo Marconi” was fined by the Garante €4,000 for unlawfully processing personal data. The school published teacher rankings on its website that disclosed health information, breaching privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Jan 2019 | Istituto Scolastico Superiore “Andrea Mantegna”Istituto Scolastico Superiore “Andrea Mantegna” was fined by the Garante €4,000 for unlawfully publishing personal data on its institutional website. The disclosure included health information about teaching staff, which is sensitive personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Jul 2016 | Istituto Scolastico Masterform s.r.l.Istituto Scolastico Masterform s.r.l. was fined EUR 2,400 by the Italian Garante. The company collected personal data through its website without providing users with the required privacy information, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 26 Jul 2017 | Istituto scolastico "A. Mantegna"Istituto scolastico "A. Mantegna" was fined by the Garante for unlawfully publishing students’ personal data, including sensitive information, on its website without a legal basis. The case concerned a breach of lawfulness and data minimization requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 May 2016 | Istituto Robert Kennedy s.r.l.Istituto Robert Kennedy s.r.l. was fined EUR 2,400 by the Italian Garante for providing clients with inadequate information about data processing. The authority found a breach of the information duties under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 24 Jun 2021 | Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” di NovaraThe Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” in Novara was fined by the Garante EUR 2,000. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |
| 05 Mar 2015 | Istituto Professionale di Stato per i Servizi Commerciali Turistici Alberghieri "Cesare Musatti"The Istituto Professionale di Stato per i Servizi Commerciali Turistici Alberghieri “Cesare Musatti” was fined by the Italian data protection authority, Garante, in the amount of €10,000. The violation involved unlawfully publishing personal data on its website that revealed students’ health status. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Jun 2014 | Istituto Poligrafico e Zecca dello Stato S.p.AIstituto Poligrafico e Zecca dello Stato S.p.A was fined EUR 60,000 by the Garante. The authority found that the company did not fully implement required security measures, in particular the logging of system administrator access to electronic archives. | IT | Garante | GDPR | €60,000 | ↗ |
| 16 Sept 2021 | Istituto per Ciechi Ardizzone GioeniIstituto per Ciechi Ardizzone Gioeni was fined by the Garante EUR 5,000 for failing to provide adequate data protection information about the activation of a video surveillance system. The case involved vulnerable guests, including blind and visually impaired persons, who were not properly informed about the processing of their personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 09 Feb 2011 | Istituto Ninetta Rosano s.r.lIstituto Ninetta Rosano s.r.l was fined EUR 30,000 by the Garante for violating data protection rules. The authority found non-compliance with the requirements of Article 37 of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 29 Nov 2018 | Istituto Nazionale Previdenza Sociale (INPS)INPS was fined for processing the personal data of 12.6 million private workers using automated software without prior verification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 11 Apr 2024 | Istituto Nazionale Previdenza Sociale - INPSThe Italian Data Protection Authority fined INPS EUR 20,000 for violating data protection principles. The case concerned the improper handling of candidates’ personal data in a public competition. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Jan 2015 | Istituto Nazionale Previdenza SocialeIstituto Nazionale Previdenza Sociale was fined EUR 44,000 by the Garante. The authority found that the required privacy notice was not provided to users, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €44,000 | ↗ |
| 10 Feb 2022 | Istituto Nazionale di StatisticaIstituto Nazionale di Statistica was fined €6,000 by the Garante for breaches of data protection rules. The case concerned inadequate security measures and data processing practices that did not meet compliance requirements. | IT | Garante | GDPR | €6,000 | ↗ |