BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Nov 2025 | Verisure Italy s.r.l.Verisure Italy s.r.l. was fined by the Garante EUR 400,000 for breaches of data retention and information obligations in connection with marketing activities. The case concerned customer and former customer data processed without proper consent and notice. | IT | Garante | GDPR | €400,000 | ↗ |
| 11 Sept 2025 | Comune di NichelinoComune di Nichelino was fined EUR 18,000 by the Garante for failing to provide an adequate response to a data subject's request to exercise their rights. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €18,000 | ↗ |
| 16 Nov 2023 | Provvedimento del 16 novembre 2023 [9960948]The Garante imposed an EUR 18,000 fine on a training company for the unauthorized online publication of personal data relating to health. The case concerned breaches of GDPR Articles 5 and 32 on data processing principles and security. | IT | Garante | GDPR | €18,000 | ↗ |
| 29 Jan 2015 | Azienda Ospedaliera Universitaria Policlinico Sant'Orsola-MalpighiAzienda Ospedaliera Universitaria Policlinico Sant'Orsola-Malpighi was fined EUR 2,400 by the Garante. The authority found that personal data collected through the website’s “contact us” form was processed without the required privacy notice, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale n. 6 di CirièASL Ciriè was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The breach concerned obligations under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Feb 2017 | Lucini & Lucini Communication LtdLucini & Lucini Communication Ltd was fined EUR 72,000 by the Garante. The authority found that the company collected personal data through its websites and sent promotional emails without proper consent. | IT | Garante | GDPR | €72,000 | ↗ |
| 19 Dec 2012 | Il Tetto srlIl Tetto srl was fined EUR 6,400 by the Garante for sending unsolicited promotional faxes. The authority found that prior, specific, and informed consent from recipients had not been obtained, in breach of data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 09 May 2024 | Caffetteria 77 di Dughetti BarbaraThe Garante fined Caffetteria 77 di Dughetti Barbara EUR 3,000 for operating a video surveillance system without meeting the legal requirements. The system captured both customers and employees, creating a data protection compliance breach. | IT | Garante | GDPR | €3,000 | ↗ |
| 09 Oct 2025 | Ordine Interprovinciale dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche della Riabilitazione e della Prevenzione di AQ - CH - PE - TEThe Garante fined Ordine Interprovinciale dei Tecnici Sanitari 6,000 EUR for keeping an online disciplinary suspension record available despite the suspension being contested. The authority found breaches of lawfulness, fairness, transparency, data minimization, and accuracy. | IT | Garante | GDPR | €6,000 | ↗ |
| 30 Oct 2014 | Planetcall s.r.l.Planetcall s.r.l. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned promotional phone calls made without the individuals’ prior consent, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Jun 2013 | Hotel Villa Las Tronas s.r.l.Hotel Villa Las Tronas s.r.l. was fined EUR 2,400 by the Garante for failing to provide simplified information about video surveillance. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 25 Nov 2021 | Società H San Raffaele Resnati s.r.l.The Garante imposed a fine of EUR 6,000 on Società H San Raffaele Resnati s.r.l. for violations of data protection rules in the health sector. The case involved a data breach incident, which triggered supervisory action. | IT | Garante | GDPR | €6,000 | ↗ |
| 02 Feb 2017 | Sirama s.r.lSirama s.r.l was fined EUR 1,430,000 by the Garante for transferring money to China using techniques intended to evade anti-money laundering rules. The authority also found that personal data were processed without consent from the actual senders. | IT | Garante | GDPR | €1,430,000 | ↗ |
| 28 Jun 2018 | Luigi Di CesareLuigi Di Cesare was fined EUR 10,000 by the Garante for failing to implement minimum security measures. The breach led to the unauthorized disclosure of medical reports to a third party. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jul 2022 | Acqua Novara.VCO S.p.a.Acqua Novara.VCO S.p.a. was fined EUR 20,000 by the Garante for breaches related to the processing of personal data. The case concerned confidentiality and the risks arising from handling sensitive data in a workplace context. | IT | Garante | GDPR | €20,000 | ↗ |
| 18 Oct 2012 | Verzeri MaurizioVerzeri Maurizio was fined EUR 32,000 by the Italian data protection authority, Garante. The case concerned the sending of unsolicited promotional faxes without prior recipient consent and without providing the information required under the data protection code. | IT | Garante | GDPR | €32,000 | ↗ |
| 29 Apr 2009 | Altea Servizi s.r.l.Altea Servizi s.r.l. was fined by the Garante 2,580 EUR for sending promotional faxes without obtaining specific and informed consent from consumers. The conduct breached the consumer code and data protection rules. | IT | Garante | GDPR | €2,580 | ↗ |
| 29 Sept 2011 | XX s.a.s.XX s.a.s. was fined for sending unsolicited promotional emails without the recipients' explicit consent. The authority also found that the required privacy notice was not provided, constituting a data protection breach. | IT | Garante | GDPR | €10,400 | ↗ |
| 04 Oct 2011 | Villa Azzurra Hospital s.r.l.Villa Azzurra Hospital s.r.l. was fined by the Garante in the amount of 30,000 EUR for failing to comply with data processing notification requirements. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 13 Feb 2025 | ADVFAST s.r.l.s.ADVFAST s.r.l.s. was fined by the Garante for failing to respond to information requests concerning repeated unsolicited telemarketing calls. The case indicates a failure to cooperate with the supervisory authority. | IT | Garante | GDPR | €2,000 | ↗ |