BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Mar 2019 | Enel Energia s.p.a.Enel Energia s.p.a. was fined by the Garante EUR 80,000 for failing to implement adequate security measures. This allowed unauthorized access and massive data downloads by a third-party company using credentials of former employees. | IT | Garante | GDPR | €80,000 | ↗ |
| 30 Oct 2014 | Giacomo Michele Maria GrassoGiacomo Michele Maria Grasso was fined for failing to provide data subjects with the required information about video surveillance at his establishment. The conduct breached Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 22 Jan 2015 | Comune di TroinaComune di Troina was fined 4,000 EUR by the Garante for unlawfully disclosing personal data to the complainant’s sister without a legal basis. The authority found a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 11 Sept 2014 | Liliana ImbrogianoLiliana Imbrogiano was fined by the Italian Garante for failing to provide adequate simplified information about the use of a video surveillance system. The authority found a breach of privacy regulations. | IT | Garante | GDPR | €2,400 | ↗ |
| 11 Apr 2013 | PLD srlPLD srl was fined €100,000 by the Italian Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information. | IT | Garante | GDPR | €100,000 | ↗ |
| 29 Sept 2021 | Solera Italia s.r.l.Solera Italia s.r.l. was fined EUR 10,000 by the Garante for continuing to use an employee's email account after the employment ended. The authority found that the company did not provide proper information about this processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 May 2010 | Roadhouse Grill Italia s.r.l.Roadhouse Grill Italia s.r.l. was fined 6,000 EUR by the Garante for failing to provide proper data protection notices to individuals through signage for its video surveillance system. The authority found a breach of data protection rules. | IT | Garante | GDPR | €6,000 | ↗ |
| 16 May 2018 | Paesano FrancescoPaesano Francesco was fined EUR 60,000 by the Garante for activating six phone cards without the consent of the individuals concerned. The case concerns a breach of data protection rules and the absence of a valid legal basis for processing. | IT | Garante | GDPR | €60,000 | ↗ |
| 08 Mar 2018 | Yahoo! Emea Limited oggi Oath (Emea) LimitedYahoo! Emea Limited, now Oath (Emea) Limited, was fined 160,000 EUR by the Garante. The authority found that the company failed to comply with a request to remove specific URLs containing personal information from Yahoo! Search. | IT | Garante | GDPR | €160,000 | ↗ |
| 09 Nov 2017 | Società Alberghi Circeo s.r.l.Società Alberghi Circeo s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company failed to appoint data processing officers for employees handling personal data, in breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Feb 2011 | Athena Research s.r.l.Athena Research s.r.l. was fined 6,000 EUR by the Garante for sending unsolicited commercial faxes without the recipients' explicit consent. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 23 Mar 2023 | Azienda 1 di SassariThe Garante imposed a fine of 4,000 EUR on Azienda 1 di Sassari for violations related to the processing of personal data, including health data. The authority found that adequate security measures were not in place for this processing. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Apr 2025 | Unione Montana Appennino Parma EstUnione Montana Appennino Parma Est was fined by the Italian supervisory authority, Garante, in the amount of EUR 8,000. The authority found a lack of required transparency in data processing and failure to carry out a data protection impact assessment for workplace video surveillance. | IT | Garante | GDPR | €8,000 | ↗ |
| 05 Mar 2015 | Comune di Acquarica del CapoThe Municipality of Acquarica del Capo was fined 10,000 EUR by the Garante for unlawfully publishing personal data revealing health information on its website. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Apr 2022 | Società Ospedale San Raffaele s.r.l.The Garante fined Società Ospedale San Raffaele s.r.l. EUR 70,000 for making online medical reports accessible to other patients. The case involved a breach of personal data protection and confidentiality of health information. | IT | Garante | GDPR | €70,000 | ↗ |
| 19 Nov 2017 | Superbeton S.p.a.Superbeton S.p.a. was fined 20,000 EUR by the Garante for failing to properly notify the use of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 17 Nov 2010 | Azienda trasporti di MessinaAzienda trasporti di Messina was fined 20,000 EUR by the Garante for processing sensitive personal data without providing the required information notice and without obtaining consent from the data subjects. The case concerns breaches of core transparency and lawful-processing obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 May 2015 | Provincia di FrosinoneProvincia di Frosinone was fined for failing to update the Security Policy Document (DPS) for several years. The authority found this to be a breach of security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Apr 2017 | Regione AbruzzoThe Garante fined Regione Abruzzo EUR 20,000 for unlawfully publishing lists on its website that revealed candidates' health status. The case involved the disclosure of sensitive personal data relating to individuals with disabilities. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Apr 2018 | Comune di DerutaThe Municipality of Deruta was fined 10,000 EUR for unlawfully providing lists of personal data of residents born in 1994–1996 to a private educational institution. The recipient was not entitled to receive the data under public utility exceptions. | IT | Garante | GDPR | €10,000 | ↗ |