BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Jun 2014 | Istituto Poligrafico e Zecca dello Stato S.p.AIstituto Poligrafico e Zecca dello Stato S.p.A was fined EUR 60,000 by the Garante. The authority found that the company did not fully implement required security measures, in particular the logging of system administrator access to electronic archives. | IT | Garante | GDPR | €60,000 | ↗ |
| 28 May 2026 | Azienda Tutela della Salute per la LiguriaAzienda Tutela della Salute per la Liguria was fined by the Garante 6,000 EUR for violations related to the processing of personal data using a satellite localization system in a disciplinary procedure against an employee. The case concerned the use of data in a manner that did not comply with data protection requirements. | IT | Garante | GDPR | €6,000 | ↗ |
| 04 Jul 2024 | Comune di VillasimiusComune di Villasimius was fined for failing to respond to a request to remove personal data from its website and for unlawfully publishing personal data. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Mar 2016 | Pia GiordanoPia Giordano was fined by the Garante for collecting personal data through her website without providing users with the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 08 Mar 2012 | Comune di Marano PrincipatoThe Municipality of Marano Principato was fined by the Garante for processing personal data without appointing data processors and for failing to adopt minimum security measures. The authority found a breach of Article 33 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 May 2026 | The European House – Ambrosetti spaThe Italian data protection authority fined The European House – Ambrosetti spa EUR 85,000 for security shortcomings following a data breach affecting 61,670 people. The company notified affected individuals too late, only after intervention by the authority. | IT | Garante per la protezione dei dati personali | GDPR | €85,000 | ↗ |
| 26 Feb 2026 | Istituto Tecnico Statale L. 80014050357Istituto Tecnico Statale was fined by the Garante for breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization. The school improperly published personal data on its website. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 Apr 2026 | Lepida S.c.p.A.Lepida S.c.p.A. was fined by the Italian supervisory authority Garante €100,000 for unauthorized access and data handling violations linked to SPID digital identity management. The authority found breaches of GDPR Articles 25 and 32, covering data protection by design and security of processing. | IT | Garante | GDPR | €100,000 | ↗ |
| 04 Dec 2014 | Itala s.p.aItala s.p.a was fined EUR 4,000 by the Garante for processing personal data related to job applications without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Aug 2022 | Colosseo S.r.l.Colosseo S.r.l. was fined EUR 1,000 by the Garante for sending unsolicited promotional emails without prior recipient consent. The authority found this breached GDPR rules on lawful processing and consent. | IT | Garante | GDPR | €1,000 | ↗ |
| 22 May 2018 | Ordinanza ingiunzione - 22 maggio 2018 [9027240]A general practitioner was fined for failing to adopt minimum security measures in a health information system. The deficiencies allowed unauthorized access to the data. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Apr 2022 | Ministero della DifesaMinistero della Difesa was fined EUR 10,000 by the Garante for improperly disclosing personal data, including health-related information, to unauthorized personnel. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Nov 2011 | C.O.E.STRA. S.p.A.C.O.E.STRA. S.p.A. was fined EUR 30,000 by the Italian data protection authority, Garante. The sanction concerned the failure to appoint data processing officers, which breached the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 21 Mar 2018 | Ditta individuale Smile di Remmert OriettaThe company was fined for processing the personal data of 36 individuals without consent in connection with training enrollments. It also submitted false documents to the Province of Turin to account for courses that were never conducted. | IT | Garante | GDPR | €40,000 | ↗ |
| 17 Mar 2016 | Università degli studi di FoggiaUniversità degli studi di Foggia was fined 4,000 EUR by the Garante for unlawfully disclosing health-related data to third parties. The authority found that the disclosure lacked an appropriate legal basis and breached privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Jul 2025 | Comune di ConversanoComune di Conversano was fined €3,000 by the Garante for failing to communicate the contact details of its Data Protection Officer. The breach concerned the obligation under Article 37 GDPR to notify the supervisory authority. | IT | Garante | GDPR | €3,000 | ↗ |
| 11 Feb 2016 | Circolo ricreativo D.D. PeckerCircolo ricreativo D.D. Pecker was fined by the Garante for providing inadequate information to data subjects about the processing of their personal data. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 May 2011 | Centrale Palace HotelCentrale Palace Hotel was fined EUR 6,000 by the Garante. The violation concerned the failure to provide the required privacy notice for its video surveillance system, in breach of the Italian data protection code. | IT | Garante | GDPR | €6,000 | ↗ |
| 01 Mar 2018 | Priolo Servizi S.c.p.A.Priolo Servizi S.c.p.A. was fined EUR 52,000 for the unlawful processing of biometric data of about 6,700 workers. The authority found that the company failed to properly notify the Garante and provided inadequate information to the data subjects. | IT | Garante | GDPR | €52,000 | ↗ |
| 15 Jan 2020 | Comune di Francavilla FontanaThe Municipality of Francavilla Fontana was fined 10,000 EUR by the Garante for publishing personal data on its institutional website. The conduct breached data protection rules and triggered supervisory action. | IT | Garante | GDPR | €10,000 | ↗ |