BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 May 2018 | Autosat S.p.A.Autosat S.p.A. was fined by the Italian Garante in the amount of EUR 30,000 for breaches of data protection rules. The case concerned the handling of personal data and the security measures used in the company’s IT systems. | IT | Garante | GDPR | €30,000 | ↗ |
| 12 Nov 2015 | Giuseppina GhezziGiuseppina Ghezzi was fined by the Garante 26,000 EUR for registering 100 phone cards to an unaware third party. The required data protection information was not provided and consent was not obtained, constituting a breach of data protection law. | IT | Garante | GDPR | €26,000 | ↗ |
| 13 Feb 2007 | Asl Centro MoliseAsl Centro Molise was fined by the Garante for processing personal data, including genetic and biometric data, without the required notification. The breach concerned obligations under the Italian data protection code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Mar 2024 | Imperatori Immobiliari s.r.l.The Garante fined Imperatori Immobiliari s.r.l. 4,000 EUR for operating a surveillance system without the required informational signage. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Jul 2006 | Comune di NapoliThe Municipality of Naples was fined by the Garante in the amount of 2,582 EUR. The sanction resulted from failing to provide requested information and documents, which constituted a breach of data protection rules. | IT | Garante | GDPR | €2,582 | ↗ |
| 05 May 2016 | S.I.S Società Italiana Scommesse s.r.lS.I.S Società Italiana Scommesse s.r.l was fined EUR 2,400 by the Garante. The authority found that the company failed to provide adequate simplified information about its video surveillance system, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 18 Dec 2025 | Provvedimento del 18 dicembre 2025 [10210431]A professional sent a communication containing personal data to an institutional email address, which breached data protection rules. The Garante imposed a fine of EUR 1,000. | IT | Garante | GDPR | €1,000 | ↗ |
| 31 Jan 2019 | Istituto di Istruzione Superiore C.Istituto di Istruzione Superiore C. was fined EUR 4,000 by the Garante for publishing sensitive personal data, including health information, on its website. The conduct breached data protection requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Jun 2018 | Azienda Semplice s.r.l.Azienda Semplice s.r.l. was fined by the Garante 16,000 EUR for unlawful processing of personal data used to place promotional calls to a private residential phone number without consent. The case concerns a lack of a lawful basis for marketing contact and a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 05 Jul 2017 | Klik s.r.l.Klik s.r.l. was fined EUR 30,000 by the Garante for retaining telephone traffic data for more than 24 months. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 12 Feb 2015 | Comune di JesiComune di Jesi was fined for unlawfully publishing personal data related to a public competition on its website without a legislative or regulatory basis. The authority found that this breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 14 Sept 2006 | De.Mo. s.r.l.De.Mo. s.r.l. was fined 3,000 EUR by the Garante for failing to provide the required information to data subjects under Article 13 of the Italian Data Protection Code. The breach occurred in connection with the company’s marketing activities. | IT | Garante | GDPR | €3,000 | ↗ |
| 28 Sept 2023 | Asl Napoli 3 SudThe Garante fined Asl Napoli 3 Sud EUR 30,000 for inadequate security measures that led to a data breach. The incident caused limited service disruption. | IT | Garante | GDPR | €30,000 | ↗ |
| 08 Jul 2015 | Perez s.r.l.Perez s.r.l. was fined by the Garante for failing to provide the required privacy notice to users whose personal data were collected through its website. This constituted a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 05 May 2011 | Idrablu SpaIdrablu Spa was fined by the Garante in the amount of EUR 20,000 for failing to respond to requests for information about the transfer of personal data to another company. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jun 2016 | Azienda per i servizi sanitari n. 2 IsontinaAzienda per i servizi sanitari n. 2 Isontina was fined for unlawfully publishing personal data, including negative performance evaluations, of an individual on its institutional website. The conduct breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 20 Nov 2014 | Aimon s.r.l.Aimon s.r.l. was fined EUR 32,000 by the Garante for sharing customers’ personal data with various companies without proper notice and consent. The authority found that the conduct breached privacy rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 11 Apr 2013 | Travel Factory srl in liquidazioneTravel Factory srl in liquidazione was fined EUR 22,000 by the Garante. The authority found that the company sent promotional faxes and collected data through web forms without providing the required privacy information notice. | IT | Garante | GDPR | €22,000 | ↗ |
| 30 Oct 2014 | sig.ra Wu LiliThe Garante imposed a EUR 2,400 fine on sig.ra Wu Lili for failing to provide adequate information to data subjects about video surveillance at a gaming venue. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 13 Mar 2025 | Interflora Italia S.p.A.Interflora Italia S.p.A. was fined EUR 40,000 by the Garante for sending promotional SMS messages without providing an opt-out option. The case indicates a breach of GDPR requirements for marketing communications and data subject rights. | IT | Garante | GDPR | €40,000 | ↗ |