BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Jan 2015 | Zoccatelli MichelaZoccatelli Michela was fined EUR 2,400 by the Garante for failing to provide information to individuals applying for membership in the private Aquila Club. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 01 Dec 2022 | Regione CampaniaRegione Campania was fined by the Garante in the amount of EUR 10,000 for unauthorized access to personal data. The case concerned breaches of GDPR requirements on data protection and security measures. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2015 | Comune di CalatabianoComune di Calatabiano was fined 10,000 EUR by the Garante for unlawfully publishing personal data revealing health conditions on its institutional website. The conduct breached privacy rules governing the processing and disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Sept 2008 | Eurolaurea Caserta s.r.l.Eurolaurea Caserta s.r.l. was fined EUR 3,000 by the Garante. The authority found that the company failed to provide data subjects with the information required under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 06 Nov 2014 | Comune di GerenzanoThe Municipality of Gerenzano was fined 4,000 EUR by the Garante for failing to appoint a socially useful worker as a data processor. The authority found this breached the minimum security measures required under the data protection code. | IT | Garante | GDPR | €4,000 | ↗ |
| 20 Sept 2012 | Casa di cura privata Montevergine s.p.a.The private clinic Montevergine was fined 50,000 EUR by the Garante. The authority found that it processed employees' biometric data for attendance tracking without first notifying the supervisory authority. | IT | Garante | GDPR | €50,000 | ↗ |
| 22 Feb 2024 | Coop Italia Società CooperativaCoop Italia Società Cooperativa was fined by the Garante 90,000 EUR for unlawfully processing personal data for marketing purposes without proper consent. The authority found a breach of GDPR principles, including Article 5. | IT | Garante | GDPR | €90,000 | ↗ |
| 26 Mar 2026 | Comune di XXThe Garante fined Comune di XX EUR 5,000 for breaches of lawfulness, fairness, transparency, and data minimization. It also found failures to implement data protection by design and by default. | IT | Garante | GDPR | €5,000 | ↗ |
| 14 Apr 2023 | Green Network S.p.a.Green Network S.p.a. was fined by the Garante for illegal telemarketing practices in the energy sector. The authority found a breach of data protection principles. | IT | Garante | GDPR | €237,000 | ↗ |
| 14 Jan 2021 | Azienda Ospedaliera San Pio di BeneventoAzienda Ospedaliera San Pio di Benevento was fined by the Garante 10,000 EUR for publishing employees’ personal data on its intranet without a proper legal basis. The case concerned unauthorized disclosure of personal data within the organization’s internal environment. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Dec 2008 | Eutelia S.p.A.Eutelia S.p.A. was fined by the Garante for processing personal data without providing the required privacy notice. The breach occurred during the activation of an unsolicited telephone service and concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €54,000 | ↗ |
| 07 Feb 2013 | Primi sui Motori s.p.a.Primi sui Motori s.p.a. was fined €23,000 by the Garante for sending unsolicited promotional emails. The authority found that the company had not obtained prior, specific, and informed consent from the recipients. | IT | Garante | GDPR | €23,000 | ↗ |
| 15 Apr 2021 | Ordinanza ingiunzione - 15 aprile 2021The case concerned a breach of data protection rules by a healthcare entity. Consent for processing personal data for epidemiological research was obtained improperly. | IT | Garante | GDPR | €5,000 | ↗ |
| 18 Sept 2014 | Meridi s.r.l.Meridi s.r.l. was fined by the Garante 40,000 EUR for failing to provide adequate information about video surveillance and for not appointing data processing officers. The authority found a breach of data security measures. | IT | Garante | GDPR | €40,000 | ↗ |
| 22 Oct 2015 | Ferrara AdrianoFerrara Adriano was fined EUR 2,400 by the Garante. The authority found that the company used a video surveillance system without adequate notices for the individuals being recorded, in breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Nov 2014 | Areacom s.r.l.Areacom s.r.l. was fined by the Garante 16,000 EUR for collecting personal data through its website without providing the required privacy notice. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €16,000 | ↗ |
| 03 May 2018 | Marconi RobertoMarconi Roberto, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum security measures to protect patients' personal and sensitive data were not adopted, allowing unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | Volkswagen Leasing GmbHVolkswagen Leasing GmbH was fined EUR 40,000 by the Garante for failing to adequately respond to a data access request. The authority found a breach of GDPR provisions on data subject rights. | IT | Garante | GDPR | €40,000 | ↗ |
| 13 May 2015 | Provincia di NapoliProvincia di Napoli was fined for unlawfully publishing personal data, including health information, on its institutional website. The authority found a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Alessandro SabatiniAlessandro Sabatini, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum personal data security measures were not implemented, which allowed unauthorized access to a health information system. | IT | Garante | GDPR | €10,000 | ↗ |