BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Apr 2010 | Consiglio dell'ordine degli avvocati di Santa Maria Capua VetereConsiglio dell'ordine degli avvocati di Santa Maria Capua Vetere was fined by the Garante for using a biometric system to verify trainee lawyers' attendance without proper authorization. This constituted a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl di Maglie (Lecce)Asl di Maglie (Lecce) was fined by the Garante for failing to notify personal data processing activities within the required timeframe. This constituted a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Oct 2022 | Douglas Italia S.p.A.Douglas Italia S.p.A. was fined by the Italian Garante in the amount of €1,400,000. The authority found inadequate responses to data subject requests and a lack of clear separation between the privacy policy and cookie policy in the app. The conduct breached multiple GDPR provisions. | IT | Garante | GDPR | €1,400,000 | ↗ |
| 07 Apr 2011 | Enterprise Service s.r.l.Enterprise Service s.r.l. was fined EUR 6,000 by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The authority also found that the required privacy notice was not provided, constituting a breach of privacy rules. | IT | Garante | GDPR | €6,000 | ↗ |
| 10 Nov 2016 | Funworld s.r.l.Funworld s.r.l. was fined €2,400 by the Garante for failing to respond to a request for information concerning the unlawful processing of personal data through a video surveillance system. The case concerned a failure to cooperate with the supervisory authority. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Nov 2014 | Paolo DorelliPaolo Dorelli was fined by the Garante EUR 2,400 for failing to provide the required information to data subjects regarding video surveillance at a public establishment. This constituted a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 22 Feb 2024 | Airone società consortile a r.l.Airone società consortile a r.l. was fined EUR 5,000 by Garante for unlawfully processing biometric data through facial recognition to monitor employee attendance. The authority found that the same purpose could have been achieved by less intrusive means. | IT | Garante | GDPR | €5,000 | ↗ |
| 14 Sept 2023 | Shardana Working Soc. Coop. a r.l.Shardana Working Soc. Coop. a r.l. was fined by the Garante 20,000 EUR for failing to fully comply with data access requests. The authority found a breach of Article 15 GDPR. | IT | Garante | GDPR | €20,000 | ↗ |
| 11 Sept 2025 | Comune di VeronaThe Comune di Verona was fined for improperly sharing personal data of TARI taxpayers with a third party for engagement communications. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €6,000 | ↗ |
| 03 Jul 2014 | Tenacta Group s.p.a.Tenacta Group s.p.a. was fined 10,000 EUR by the Garante for making unsolicited promotional phone calls. The company failed to consult the public opposition register, thereby violating the subscriber's right to object. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Jun 2018 | Azienda Unità Sanitaria Locale di PiacenzaAzienda Unità Sanitaria Locale di Piacenza was fined by the Garante EUR 36,000 for creating electronic health records without informing patients or obtaining their consent. The authority found this to be a breach of privacy rules. | IT | Garante | GDPR | €36,000 | ↗ |
| 02 Jul 2020 | Comune di ManduriaComune di Manduria was fined by the Garante in the amount of 2,000 EUR for breaching data protection principles, including lawfulness, fairness, and transparency. The authority found that personal data had been improperly disseminated through journalistic outlets. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 May 2024 | Azienda USL della RomagnaThe Garante imposed a fine of EUR 8,400 on Azienda USL della Romagna for violations related to data processing operations. The processes were largely manual and dependent on operator diligence, which led to a data breach. | IT | Garante | GDPR | €8,400 | ↗ |
| 16 Jun 2022 | Federazione Italiana NuotoFederazione Italiana Nuoto was fined EUR 2,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 of the GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 14 Nov 2019 | ASL n. 2 SavoneseASL n. 2 Savonese was fined EUR 8,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data, including failures to comply with lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €8,000 | ↗ |
| 02 Jul 2020 | Comune di Greve in ChiantiComune di Greve in Chianti was fined by the Garante for unlawfully disclosing personal data relating to criminal convictions and proceedings. The conduct breached the principles of lawfulness, fairness, and transparency in data processing. | IT | Garante | GDPR | €4,000 | ↗ |
| 30 Oct 2013 | Comune di BolzanoComune di Bolzano was fined 10,000 EUR by the Garante for publishing sensitive health-related information about an employee’s absence on its institutional website. The authority found a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Nov 2017 | A.M.A.CO. s.p.a.A.M.A.CO. s.p.a. was fined by the Garante for installing non-compliant video surveillance and geolocation systems on its vehicles. The authority found that these measures breached data protection rules. | IT | Garante | GDPR | €22,400 | ↗ |
| 24 Nov 2016 | Provincia di VercelliProvincia di Vercelli was fined EUR 10,000 by the Garante for unlawfully publishing personal data on its institutional website. The disclosed information included photocopies of identity cards and bank account numbers, without an appropriate legal basis. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Mar 2008 | Frareg s.r.l.Frareg s.r.l. was fined by the Garante for sending advertising material by fax without providing prior and adequate information to recipients. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |