BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Dec 2019 | Eni Gas e Luce S.p.A.Eni Gas e Luce S.p.A. was fined EUR 8,500,000 by the Garante for making unsolicited telemarketing calls without consent. The conduct also affected individuals who had opted out or were listed in the public opposition register. | IT | Garante | GDPR | €8,500,000 | ↗ |
| 12 Sept 2024 | Sky Italia S.r.l.Sky Italia S.r.l. was fined EUR 842,062 by the Garante for telemarketing violations. The authority found that the company contacted individuals without proper consent and failed to consult the Public Register of Objections before promotional campaigns. | IT | Garante | GDPR | €842,000 | ↗ |
| 02 Nov 2024 | Intesa SanpaoloThe Italian Data Protection Authority fined Intesa Sanpaolo €31.8 million for a data breach involving unauthorized access to banking information of more than 3,500 clients. The authority also found that the bank detected the activity late and filed an incomplete and delayed breach notification. | IT | Garante per la protezione dei dati personali | GDPR | €31,800 | ↗ |
| 15 Dec 2016 | Stireria Rosa di HU XINStireria Rosa di HU XIN was fined 2,400 EUR by the Garante. The authority found that the company failed to inform data subjects about the processing of personal data through a video surveillance system covering public areas. | IT | Garante | GDPR | €2,400 | ↗ |
| 18 Feb 2016 | Europa Investigazioni s.r.lEuropa Investigazioni s.r.l was fined EUR 8,000 by the Garante. The authority found that the company failed to notify the processing of data indicating the geographical position of individuals or objects via an electronic communications network. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Feb 2025 | D.e.c. soc. coop.The Garante imposed a EUR 20,000 fine on D.e.c. soc. coop. for failing to deactivate an ex-employee's email account after the employment ended. The authority found this conduct breached GDPR principles of fair and transparent processing of personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Jun 2016 | Società Territorio Turismo & Sport s.r.l.Società Territorio Turismo & Sport s.r.l. was fined by the Garante 2,400 EUR. The case concerned collecting personal data, including name and email, via its website without providing users with the required information notice. | IT | Garante | GDPR | €2,400 | ↗ |
| 01 Dec 2016 | L'ABBONDANZA s.r.l.L'ABBONDANZA s.r.l. was fined 2,400 EUR by the Garante. The authority found that the company failed to provide data subjects with information about the processing of personal data through a video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 05 Jun 2014 | Ing. Claudio ZiniThe individual enterprise of Ing. Claudio Zini was fined for sending unsolicited promotional emails. The authority also found that the required information notice under Article 13 of the Italian Privacy Code was not provided. | IT | Garante | GDPR | €2,400 | ↗ |
| 21 Apr 2016 | Estracom s.p.a.Estracom s.p.a. was fined EUR 20,000 by the Garante for retaining customers’ call data for more than thirty days. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Oct 2022 | Policlinico Casilino di RomaPoliclinico Casilino di Roma was fined by the Garante for violations related to the handling of personal data in the healthcare sector. The case concerned improper processing of patient data and privacy compliance requirements. | IT | Garante | GDPR | €15,000 | ↗ |
| 02 Dec 2021 | Omnia 24 S.r.l.Omnia 24 S.r.l. was fined EUR 100,000 by the Garante for sending unsolicited promotional SMS messages without proper consent. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €100,000 | ↗ |
| 05 Nov 2015 | Romagna Giochi srlRomagna Giochi srl was fined EUR 4,800 by the Italian Garante. The authority found that the company failed to provide adequate notice about video surveillance at its premises, breaching data protection rules. | IT | Garante | GDPR | €4,800 | ↗ |
| 15 Mar 2018 | S.P. Selezione Personale s.r.l.S.P. Selezione Personale s.r.l. was fined by the Garante in the amount of EUR 20,000 for violations related to the processing of personal data in head hunting and recruitment activities. The case concerned irregularities in the handling of candidate data. | IT | Garante | GDPR | €20,000 | ↗ |
| 10 Jul 2025 | Outly di Veneziani & Co s.r.l.The Garante fined Outly di Veneziani & Co s.r.l. EUR 15,000 for insufficient transparency when obtaining consent and for inadequate information on data retention periods. The issues affected all interested parties and potential customers. | IT | Garante | GDPR | €15,000 | ↗ |
| 22 Feb 2024 | Comune di MonterotondoThe Garante imposed a EUR 3,000 fine on Comune di Monterotondo for breaches involving data processing agreements and security measures. The case also involved improper use of video surveillance. The authority found that the controller did not meet data protection requirements. | IT | Garante | GDPR | €3,000 | ↗ |
| 11 Feb 2021 | Ministero dello Sviluppo EconomicoThe Ministry of Economic Development was fined by the Garante for publishing personal data, including managers' CVs, on its institutional website without a proper legal basis. The authority found this conduct to be in breach of GDPR requirements. | IT | Garante | GDPR | €75,000 | ↗ |
| 01 Mar 2018 | Comune di San Mango PiemonteComune di San Mango Piemonte was fined for unlawfully using a biometric system based on fingerprint processing to record employee attendance. The authority found that this processing breached data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 02 Apr 2015 | Provincia di TriesteProvincia di Trieste was fined for publishing personal data on its institutional website without a legal basis. This breached Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Aug 2023 | Ordine degli Avvocati di XXThe Garante fined the Ordine degli Avvocati di XX EUR 8,000 for unlawfully disclosing personal data without a legal basis. The authority found breaches of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €8,000 | ↗ |