BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Jun 2021 | Aeroporto Guglielmo Marconi di Bologna S.p.a.Aeroporto Guglielmo Marconi di Bologna S.p.a. was fined by the Garante EUR 40,000 for violations related to the protection of whistleblower identities. The case indicates insufficient personal data safeguards in the handling of reports. | IT | Garante | GDPR | €40,000 | ↗ |
| 05 Jul 2018 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 800,000 by the Garante for making unsolicited promotional phone calls and sending SMS messages without proper consent. The authority found that these practices breached data protection rules. | IT | Garante | GDPR | €800,000 | ↗ |
| 08 Feb 2007 | Asl OristanoAsl Oristano was fined EUR 10,000 by the Garante for failing to notify the processing of personal data concerning health and sexual life. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Dec 2022 | Eurosanità S.P.A.Eurosanità S.P.A. was fined by the Garante in the amount of 30,000 EUR for violations related to the processing of health data. The authority cited inadequate personal data protection measures. | IT | Garante | GDPR | €30,000 | ↗ |
| 30 Oct 2013 | Ye BiYe Bi was fined by the Garante EUR 2,400 for operating a video surveillance system at Bar Millennium without the required signage. The authority found a breach of privacy regulations. | IT | Garante | GDPR | €2,400 | ↗ |
| 05 Feb 2015 | Comune di MontagnarealeThe Garante fined Comune di Montagnareale 10,000 EUR for unlawfully publishing personal data revealing health status on its institutional website. The breach involved disclosure of sensitive data without an adequate legal basis or safeguards. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Jul 2015 | Ordinanza ingiunzione - 2 luglio 2015 [4337649]The condominium administrator did not respond to requests for information related to a data protection complaint. Garante imposed a fine of EUR 4,000 for violating data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 11 Jul 2013 | Slots R Us srlSlots R Us srl was fined EUR 6,000 by the Garante for failing to provide the required information notice for its video surveillance system. The case concerned non-compliance with data protection rules on informing individuals subject to CCTV monitoring. | IT | Garante | GDPR | €6,000 | ↗ |
| 21 Jul 2016 | Personal club s.r.l.Personal club s.r.l. was fined by the Garante in the amount of EUR 2,400 for failing to provide simplified information about the use of a video surveillance system. The breach concerned the data protection information duties applicable to such processing. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Nov 2015 | Capodarco Società Cooperativa Sociale IntegrataCapodarco Società Cooperativa Sociale Integrata was fined EUR 12,000 by the Garante for recording and listening to calls between call center operators and users. The authority found that the required information notice was not provided to worker members, in breach of data protection rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 29 Apr 2026 | Istituto Comprensivo Statale MontelibrettiIstituto Comprensivo Statale Montelibretti was fined EUR 4,000 by the Garante for breaches of data protection rules in the processing of personal data on its institutional website. The authority cited failures to comply with lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Feb 2017 | Sisal S.p.A.Sisal S.p.A. was fined by the Garante in the amount of EUR 20,000 for installing a geolocation system on smartphones provided to employees without proper compliance with data protection rules. The case concerned the processing of location data in an employment context and insufficient legal safeguards. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Apr 2016 | Comune di OttavianoComune di Ottaviano was fined for publishing individuals’ personal data on its website without a legal basis. The authority found this breached Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Sept 2021 | Prefettura - Ufficio Territoriale del Governo di GenovaPrefettura - Ufficio Territoriale del Governo di Genova was fined by the Garante for publishing personal data on its institutional website. The conduct breached GDPR requirements on lawful processing and protection of personal data. | IT | Garante | GDPR | €11,000 | ↗ |
| 01 Jun 2023 | NH Italia S.p.A.NH Italia S.p.A. was fined EUR 200,000 by the Garante for failing to appoint specific data processors responsible for the installation and maintenance of video surveillance systems. The authority found this breached the GDPR principles of lawful, fair, and transparent processing of personal data. | IT | Garante | GDPR | €200,000 | ↗ |
| 14 Sept 2023 | Nimbus s.r.l.Nimbus s.r.l. was fined by the Garante 5,000 EUR for using a fingerprint-based attendance system. The authority found that employees were not properly informed and that the required consent was not obtained. | IT | Garante | GDPR | €5,000 | ↗ |
| 12 Feb 2026 | Anconambiente S.P.A.Anconambiente S.P.A. was fined by the Garante for failing to ensure that personal data processing was lawful, fair, and transparent. The authority also found that the company did not have a proper contract with a data processor, as required by Article 28 GDPR. | IT | Garante | GDPR | €2,500 | ↗ |
| 16 Dec 2021 | 1000 Luci Round a BarThe establishment 1000 Luci Round a Bar was fined EUR 1,000 by the Italian authority Garante. The sanction concerned a video surveillance system that did not meet the information requirements of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |
| 29 Sept 2021 | Comune di FormiaComune di Formia was fined for processing personal data linked to parking subscription services without providing adequate information to data subjects. The authority also found excessive data collection and a failure to clearly define the role of the external data processor. | IT | Garante | GDPR | €30,000 | ↗ |
| 18 May 2016 | Accademia Dante Alighieri s.r.l.Accademia Dante Alighieri s.r.l. was fined by the Garante 2,400 EUR for collecting personal data from users through its websites without providing the required information or obtaining consent. The conduct breached Articles 13 and 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |