BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Feb 2018 | Technical Hunter s.r.l.Technical Hunter s.r.l. was fined by the Garante 20,000 EUR for processing job applicants’ personal data without proper compliance with data protection rules. The data was collected and used through the company website, job portals, and social networks. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Oct 2014 | S.A.B. Alberghi di Baveno s.p.a.S.A.B. Alberghi di Baveno s.p.a. was fined by the Garante in the amount of €2,400 for processing personal data connected with job applications without providing the required information notice. The case concerned the information duty under Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 27 Apr 2023 | Checcoro di Nigro FrancescoThe company was fined EUR 2,000 by the Italian data protection authority, Garante. The sanction concerned the use of surveillance cameras without appropriate informational signage, in breach of GDPR requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 07 Jul 2011 | F.B. Aurum di Ferrero Wilma e Barathier Sergio s.n.c.F.B. Aurum di Ferrero Wilma e Barathier Sergio s.n.c. was fined by the Garante 10,000 EUR for operating a video surveillance system without providing the required notice to data subjects. This constituted a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Oct 2017 | Comune di CivitavecchiaComune di Civitavecchia was fined by the Garante for unlawfully transmitting sensitive data revealing the health status of disabled students to service providers without a proper legal basis. The authority found that the processing breached data protection and confidentiality requirements. | IT | Garante | GDPR | €30,000 | ↗ |
| 11 Apr 2013 | Casa di cura La Quiete srlCasa di cura La Quiete srl was fined by the Garante for failing to notify data processing activities related to patients’ laboratory tests. The data could reveal infectious diseases, which required notification under the Italian data protection code. | IT | Garante | GDPR | €40,000 | ↗ |
| 13 Apr 2023 | GMC s.a.p.a.GMC s.a.p.a. was fined EUR 15,000 by the Italian supervisory authority, Garante. The case concerned the publication of detailed health data of an individual without consent, in breach of GDPR Article 9 on special categories of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 11 Apr 2024 | Olimpia S.r.l.Olimpia S.r.l. was fined for making unsolicited promotional calls without prior consent and for using numbers listed in the Public Opposition Register. The conduct breached GDPR requirements on data protection and security measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 12 Oct 2017 | Hu GuangyuHu Guangyu was fined EUR 14,400 by the Garante. The authority found inadequate simplified information on video surveillance and retention of recorded images beyond the permitted period. | IT | Garante | GDPR | €14,400 | ↗ |
| 18 Jan 2018 | Italia Consulenza e Formazione s.r.l.Italia Consulenza e Formazione s.r.l. was fined EUR 32,000 by the Garante for sending promotional emails without proper consent. The case concerns a breach of data protection rules governing direct marketing. | IT | Garante | GDPR | €32,000 | ↗ |
| 17 Jul 2024 | Provvedimento del 17 luglio 2024 [10070330]The Garante imposed a fine of EUR 4,000 for violations related to the processing of health data. The case highlights the need to comply with data protection principles when handling special category data. | IT | Garante | GDPR | €4,000 | ↗ |
| 26 Apr 2018 | Raffaele FrancescoRaffaele Francesco was fined by the Garante for processing the personal data of five patients without the required consent during dental services. The conduct breached the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 30 Oct 2014 | Wangjun JiWangjun Ji was fined EUR 2,400 by the Italian supervisory authority, Garante. The case concerned a failure to provide the required information to data subjects about the processing of personal data through a video surveillance system at a massage and beauty center. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Feb 2016 | Istituto Tecnico Industriale Ettore MajoranaIstituto Tecnico Industriale Ettore Majorana was fined for processing biometric data for attendance tracking without the required notification to the Garante. This breached the Italian Privacy Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 15 Oct 2010 | Clinica Luccioni S.p.a.Clinica Luccioni S.p.a. was fined by the Garante for failing to timely notify the authority of personal data processing activities required under the Italian Data Protection Code. The case concerned a breach of the notification obligation to the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Oct 2017 | Pittaluga servizio containers S.p.A.Pittaluga servizio containers S.p.A. was fined by the Garante €8,000 for using a geolocation system on its vehicles without full compliance with data protection rules. The case concerned improper processing of location data linked to vehicles or employees. | IT | Garante | GDPR | €8,000 | ↗ |
| 26 Feb 2026 | Ciemme S.r.l.sThe Italian Data Protection Authority fined Ciemme S.r.l.s EUR 1,000 for failing to respond to a data subject request to exercise rights of access, erasure, and objection. The case arose after unsolicited marketing calls. | IT | Garante | GDPR | €1,000 | ↗ |
| 27 Mar 2014 | Tarulli Francesca e Comune di ConversanoThe Garante imposed a EUR 4,000 fine on Tarulli Francesca and the Comune di Conversano for failing to designate data processors under the Italian Data Protection Code. The conduct breached Articles 30 and 33 and reflected a deficiency in data processing governance. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Mar 2021 | Comune di CastellanzaComune di Castellanza was fined by the Garante EUR 4,000 for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. Personal data remained accessible online for an extended period. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 May 2024 | Provvedimento del 9 maggio 2024 [10027595]The authority imposed a fine on an anonymized healthcare entity for unauthorized access to patient health records by personnel without proper authorization. The case concerned GDPR requirements on data protection and processing security. | IT | Garante | GDPR | €25,000 | ↗ |