BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 25 Jul 2013 | Axis Strategic Vision srlAxis Strategic Vision srl was fined by the Garante in the amount of 4,800 EUR for providing inadequate privacy notices on its websites. The authority found that the notices did not meet data protection requirements. | IT | Garante | GDPR | €4,800 | ↗ |
| 13 Sept 2007 | Asl Enna 4The Garante fined Asl Enna 4 EUR 10,000 for processing personal data, including genetic and biometric data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Mar 2022 | Agenzia Regionale per la Tutela dell'Ambiente dell'AbruzzoThe Regional Agency for Environmental Protection of Abruzzo was fined by the Garante €8,000 for breaches of data protection principles. The violations concerned lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €8,000 | ↗ |
| 03 Oct 2013 | Telecom Italia s.p.a.Telecom Italia s.p.a. was fined 80,000 EUR by the Garante for making unsolicited promotional calls to a customer. The calls were made after the customer had withdrawn consent for such communications, which breached data protection rules. | IT | Garante | GDPR | €80,000 | ↗ |
| 21 Apr 2021 | Società Eurosanità s.p.a.Società Eurosanità s.p.a. was fined by the Garante in the amount of 5,000 EUR for a breach involving the processing of health data. The authority found violations of GDPR Articles 5 and 9, indicating improper handling of special category personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 09 Dec 2010 | Circolo Privato PirliCircolo Privato Pirli was fined EUR 6,000 by the Garante for failing to provide the required privacy notice to individuals entering the premises. The breach concerned the Italian Data Protection Code and the Garante's video surveillance guidelines. | IT | Garante | GDPR | €6,000 | ↗ |
| 07 Dec 2023 | Azienda OspedalieraAzienda Ospedaliera was fined EUR 8,000 by the Garante for breaches of data protection rules. The case concerned data processing principles and insufficient security measures. | IT | Garante | GDPR | €8,000 | ↗ |
| 30 Jan 2014 | Orovicenza di Picaro CristinaOrovicenza di Picaro Cristina was fined EUR 4,800 by the Garante. The authority found that the website’s contact and registration forms did not provide the required data protection information, in breach of the Italian data protection code. | IT | Garante | GDPR | €4,800 | ↗ |
| 11 Jan 2023 | Reweb s.r.l.Reweb s.r.l. was fined 5,000 EUR by the Garante. The company kept a former employee’s email account active and accessed it after the employment relationship ended, in breach of GDPR requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 03 May 2018 | Ordinanza ingiunzione - 3 maggio 2018 [9023941]A fine of EUR 20,000 was imposed for failing to notify the Garante about the processing of geolocation data collected through GPS devices. The case concerns a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Oct 2023 | Scionti Selezioni Superiori S.r.l.Scionti Selezioni Superiori S.r.l. was fined EUR 70,000 by the Garante for failing to implement adequate measures to prevent unauthorized access to customer data. The data was then used for promotional purposes without the individuals' consent. | IT | Garante | GDPR | €70,000 | ↗ |
| 12 Feb 2015 | Visini FabioVisini Fabio was fined EUR 12,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection requirements. | IT | Garante | GDPR | €12,000 | ↗ |
| 16 May 2018 | Conafi Prestitò s.p.a.Conafi Prestitò s.p.a. was fined by the Garante for failing to notify certain data processing activities related to loan management. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Jan 2015 | Barta s.r.l.Barta s.r.l. was fined by the Garante EUR 12,000 for operating a video surveillance system without prior authorization. Footage was retained for 15 days, exceeding the permitted one-week period. | IT | Garante | GDPR | €12,000 | ↗ |
| 28 Mar 2019 | Comune di GenovaComune di Genova was fined for unlawfully communicating personal data to third-party companies without a proper legal basis. The authority found a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Jan 2022 | Azienda sanitaria unica regionale MarcheAzienda sanitaria unica regionale Marche was fined EUR 14,000 by the Garante for inadequate data protection measures. The breach involved health data and was linked to QR code generation; improved security measures were later implemented. | IT | Garante | GDPR | €14,000 | ↗ |
| 17 Jul 2025 | Poliambulatorio San Liberale S.r.l.The Garante imposed a EUR 12,500 fine on Poliambulatorio San Liberale S.r.l. for failing to meet information and transparency obligations in the processing of personal data, including health data. The company also did not respond to a data access request, adding a further breach of data subject rights. | IT | Garante | GDPR | €12,500 | ↗ |
| 19 Feb 2015 | Andrea AngeloniAndrea Angeloni was fined by the Garante for sending unsolicited promotional letters. The entity also failed to respond to information requests from the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2025 | Azienda ULSS n. 02573090236The public health company was fined for making a disciplinary proceeding document visible to unauthorized employees. The authority found breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 May 2017 | Starweb s.r.l.Starweb s.r.l. was fined €16,000 by the Garante for making unsolicited promotional calls. The authority found that the company failed to provide the required information notice and did not obtain consent from the contacted individuals. | IT | Garante | GDPR | €16,000 | ↗ |