BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Jul 2020 | Istituto Nazionale della Previdenza Sociale-Direzione Provinciale di BresciaThe Italian Data Protection Authority fined the INPS Brescia Provincial Directorate for failing to respond to a request for access to personal health data. The authority found a breach of data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 13 Nov 2024 | Istituto Nazionale della Previdenza SocialeThe Italian Data Protection Authority fined Istituto Nazionale della Previdenza Sociale (INPS) EUR 40,000 for violations related to the processing of personal data for official statistics. The authority found that the processing did not comply with core data protection principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 28 Apr 2022 | Istituto Nazionale Assicurazione Infortuni sul LavoroIstituto Nazionale Assicurazione Infortuni sul Lavoro was fined by the Garante EUR 20,000. The authority found that inadequate technical and organizational measures led to a data breach. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Jun 2016 | Istituto Maria Angelica Miliziano s.r.l.Istituto Maria Angelica Miliziano s.r.l. was fined by the Garante 2,400 EUR for collecting users’ personal data through its website without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 23 Oct 2025 | Istituto d'Istruzione Superiore “Statista Aldo Moro” di Fara SabinaThe school published on its website a document containing personal data related to a student's disciplinary proceeding. Garante found that this breached the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Jun 2025 | Istituto d’Istruzione Superiore “Carlo e Nello Rosselli”The Garante imposed a EUR 4,000 fine on Istituto d’Istruzione Superiore “Carlo e Nello Rosselli” for failing to appoint a Data Protection Officer and for delaying notification of the DPO’s contact details to the authority. The authority also found that transparency obligations toward data subjects were not met. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Mar 2025 | Istituto di Istruzione Superiore “P. 96012510796The Garante imposed a fine on an educational institution for breaches of GDPR Articles 5, 6, and 9 in connection with data processing activities. The case concerned deficiencies in the lawful basis and principles of processing, including special-category data. | IT | Garante | GDPR | €4,000 | ↗ |
| 20 Oct 2022 | Istituto di Istruzione Superiore “G. Renda” di Polistena, Reggio CalabriaIstituto di Istruzione Superiore “G. Renda” was fined EUR 900 by the Garante for unlawfully processing personal data. The school published sensitive information about an employee’s contract termination without a legal basis, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €900 | ↗ |
| 31 Jan 2019 | Istituto di Istruzione Superiore C.Istituto di Istruzione Superiore C. was fined EUR 4,000 by the Garante for publishing sensitive personal data, including health information, on its website. The conduct breached data protection requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Jan 2021 | Istituto Comprensivo Villanova D’AstiIstituto Comprensivo Villanova D’Asti was fined EUR 4,000 by the Garante for publishing personal data online. The disclosed information could reveal health status and economic-social conditions, breaching data minimization and transparency principles. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Apr 2026 | Istituto Comprensivo Statale MontelibrettiIstituto Comprensivo Statale Montelibretti was fined EUR 4,000 by the Garante for breaches of data protection rules in the processing of personal data on its institutional website. The authority cited failures to comply with lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 Jul 2020 | Istituto Comprensivo Statale Crucoli TorrettaIstituto Comprensivo Statale Crucoli Torretta was fined EUR 2,000 by the Garante for unlawfully publishing a list of students on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Nov 2024 | Istituto Comprensivo Statale "Corso Matteotti" di AlfonsineIstituto Comprensivo Statale “Corso Matteotti” di Alfonsine was fined by the Garante EUR 1,000 for violations related to the processing of personal data. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 12 Dec 2024 | Istituto Comprensivo Statale CalenzanoIstituto Comprensivo Statale Calenzano was fined EUR 1,000 by the Garante for breaching data protection principles. The case concerned the processing of personal data without meeting the requirements of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 31 Jan 2019 | Istituto Comprensivo Paolo StefanelliIstituto Comprensivo Paolo Stefanelli was fined by the Garante 4,000 EUR for publishing personal data on its website that revealed individuals' health status. The case involved a breach of privacy rules and the protection of sensitive data. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Sept 2021 | Istituto Comprensivo - IC Cosenza III “V. Negroni”Istituto Comprensivo - IC Cosenza III “V. Negroni” was fined by the Garante 2,000 EUR for unlawful processing of personal data and inadequate data protection. The authority also noted that personal data were made accessible online, increasing the risk to affected individuals. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Nov 2025 | Istituto Comprensivo “G. Falcone” Rende-Quattromiglia (CS)The Garante fined Istituto Comprensivo “G. Falcone” EUR 2,000 for breaches of data processing principles, including lawfulness, fairness, and transparency. The authority also found non-compliance with data processing agreements. | IT | Garante | GDPR | €2,000 | ↗ |
| 02 Jul 2020 | Istituto Comprensivo di Uggiano La ChiesaIstituto Comprensivo di Uggiano La Chiesa was fined €2,000 by the Garante for posting lists at the school entrance that included minors' names, dates of birth, addresses, phone numbers, and vaccination status. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €2,000 | ↗ |
| 04 Dec 2025 | Istituto Comprensivo di Roverbella (Mantova)Istituto Comprensivo di Roverbella was fined EUR 1,000 by the Garante for breaches of data protection rules. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency in data processing. | IT | Garante | GDPR | €1,000 | ↗ |
| 04 Dec 2025 | Istituto Comprensivo Centro di Casalecchio di RenoThe Garante fined Istituto Comprensivo Centro di Casalecchio di Reno EUR 2,000 for publishing personal data online without a proper legal basis. The authority found breaches of data minimization and transparency principles. | IT | Garante | GDPR | €2,000 | ↗ |