BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Oct 2010 | Giomi s.p.a. - Gestione Istituti Ortopedici nel mezzogiorno d'ItaliaGiomi s.p.a. was fined €30,000 by the Italian data protection authority, Garante. The case concerned data processing activities carried out without the required notification under the Italian data protection code. | IT | Garante | GDPR | €30,000 | ↗ |
| 24 Jun 2021 | Ospedale Pediatrico Bambino GesùOspedale Pediatrico Bambino Gesù was fined by the Garante 15,000 EUR for breaches involving a data incident and improper handling of patient health data. The authority cited violations of GDPR Articles 5 and 32 on lawful processing and security of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 23 Jun 2025 | Società Autocooperative Trasporti Italiani S.p.A.The company was fined by the Garante for unlawfully disclosing sensitive personal data about employee absences, including the reasons for absence. The information was posted on company notice boards and sent by email to employees. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Mar 2014 | Danilo DiscolpaDanilo Discolpa was fined by the Garante 4,800 EUR for processing personal data through video surveillance and recording customer identification documents without providing the required notice. The authority found this to be a breach of the Italian Privacy Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 21 Apr 2021 | Azienda provinciale per i servizi sanitari di TrentoAzienda provinciale per i servizi sanitari di Trento was fined by the Garante EUR 40,000 for violations related to the processing of health data. The authority found omissions in implementing technical and organizational measures for access to the health dossier. | IT | Garante | GDPR | €40,000 | ↗ |
| 08 Jun 2023 | Marcozzi Brand s.r.l.Marcozzi Brand s.r.l. was fined €8,400 by the Garante. The case concerned the failure to provide the complainant with the name of the occupational physician and the specific reasons for a negative fitness-for-work assessment, breaching GDPR transparency and access rights. | IT | Garante | GDPR | €8,400 | ↗ |
| 02 Apr 2015 | Midolo MichelaMidolo Michela was fined EUR 15,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €15,000 | ↗ |
| 09 Oct 2025 | FT Solutions S.r.l.FT Solutions S.r.l. was fined by the Garante 5,000 EUR for processing personal data for marketing purposes without proper consent. The case involved more than 2 million records and resulted in unauthorized telemarketing activities. | IT | Garante | GDPR | €5,000 | ↗ |
| 21 Dec 2023 | Impresa individuale Macelleria Salumeria HalalThe Garante fined the owner of Impresa individuale Macelleria Salumeria Halal EUR 2,000 for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency and data processing requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 Feb 2026 | Bressanelli Galli Gelpi Porta & C. S.r.l.The company was fined EUR 15,000 by the Garante for sending promotional emails without prior consent from recipients. The authority found this to be a breach of GDPR principles, including Article 5. | IT | Garante | GDPR | €15,000 | ↗ |
| 09 Oct 2014 | Zhao ShujuanZhao Shujuan was fined by the Garante for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system. This constituted a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 16 Sept 2021 | Accademia di Belle Arti di RomaAccademia di Belle Arti di Roma was fined EUR 5,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data in a disciplinary procedure and the dissemination of sensitive information. | IT | Garante | GDPR | €5,000 | ↗ |
| 09 Oct 2025 | Sicuritalia S.p.A.Sicuritalia S.p.A. was fined EUR 500,000 by the Italian supervisory authority Garante. The case concerned unauthorized access to a former employee's email account after employment ended, in breach of GDPR requirements. | IT | Garante | GDPR | €500,000 | ↗ |
| 21 Mar 2024 | LAZIOcrea S.p.a.LAZIOcrea S.p.a. was fined by the Garante for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies led to unauthorized access attempts and temporary unavailability of regional services. | IT | Garante | GDPR | €271,000 | ↗ |
| 21 Jan 2016 | Malta Games di Belgiorno Chiara & C. s.a.s.Malta Games di Belgiorno Chiara & C. s.a.s. was fined EUR 2,400 by the Garante. The authority found that the company failed to provide the required information to data subjects about personal data processing through a video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 18 Feb 2010 | Fibrille s.r.l.Fibrille s.r.l. was fined EUR 6,000 by the Garante for processing personal data from job applicants' CVs without providing the required information. The authority found a breach of the notice obligation under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 06 Jun 2018 | Dalmesse Italia s.r.l.Dalmesse Italia s.r.l. was fined €22,000 by the Italian supervisory authority, Garante. The case concerned the processing of personal data, including sensitive health data, without proper compliance with data protection rules. | IT | Garante | GDPR | €22,000 | ↗ |
| 31 Jan 2019 | CT BARCT BAR was fined by the Garante for unlawful processing of personal data through its video surveillance system. The recordings were retained for 15 days without proper compliance with applicable rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 01 Jun 2023 | AUSL Toscana Sud EstThe Garante fined AUSL Toscana Sud Est 20,000 EUR for the unlawful dissemination of a patient's health data. The authority found a breach of data protection principles. | IT | Garante | GDPR | €20,000 | ↗ |
| 09 Jun 2016 | Comune di LevantoThe Municipality of Levanto was fined EUR 4,000 by the Garante for publishing on its website a list of candidates for regional contributions. The disclosure of personal data lacked sufficient legal basis and breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |