BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Dec 2021 | Progetto Udire S.r.l.Progetto Udire S.r.l. was fined by the Garante 30,000 EUR. The authority found that the company sent unsolicited marketing communications without proper consent and failed to provide information on the origin of personal data when requested by the data subject. | IT | Garante | GDPR | €30,000 | ↗ |
| 19 Jul 2018 | BUTALI S.P.A.BUTALI S.P.A. was fined €16,000 by the Garante for activating a SIM card without providing the required privacy information and obtaining the customer’s specific consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 30 Apr 2026 | Intesa SanpaoloItaly’s data protection authority, Garante, fined Intesa Sanpaolo EUR 31.8 million. The sanction concerned serious failures in security and access management for personal data. | IT | Garante per la protezione dei dati personali | GDPR | €31,800,000 | ↗ |
| 12 Feb 2026 | Acea Energia S.p.A.Acea Energia S.p.A. was fined by the Garante 2,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy supply contracts, indicating significant deficiencies in data quality controls. | IT | Garante | GDPR | €2,000,000 | ↗ |
| 12 Nov 2015 | Cantiere 21 s.r.l.Cantiere 21 s.r.l. was fined by the Garante in the amount of 2,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority treated this as a breach of privacy rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 07 Mar 2024 | Giuliana VinziThe Garante fined Giuliana Vinzi, owner of Rocky Bar, 2,000 EUR for operating video surveillance without the required notices to data subjects. The authority also found that authorization from the Labor Inspectorate was missing, resulting in a GDPR breach. | IT | Garante | GDPR | €2,000 | ↗ |
| 24 Sept 2015 | Lo.Gi.Ma. s.r.lLo.Gi.Ma. s.r.l was fined 4,800 EUR by the Italian Garante. The company collected personal data through its website without providing the required privacy notice, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 15 Jan 2015 | Comune di PloagheComune di Ploaghe was fined by the Garante for unlawfully publishing personal data on its website beyond the legally permitted period. The authority found a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Jul 2013 | Global ResearchGlobal Research was fined EUR 12,800 by the Garante for sending unsolicited promotional faxes without the required information and consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €12,800 | ↗ |
| 07 May 2015 | Nappo Nicola JolandaNappo Nicola Jolanda was fined EUR 45,000 by the Garante for activating 37 phone cards in the names of 15 individuals without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €45,000 | ↗ |
| 19 Sept 2013 | Cooperativa di servizi AggregoCooperativa di servizi Aggrego was fined €6,400 by the Garante. The case concerned the sending of unsolicited promotional faxes without prior consent, in breach of data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 05 Mar 2015 | Comune di CapaccioComune di Capaccio was fined for unlawfully publishing sensitive personal data revealing health conditions on its institutional website. The authority found this to be a breach of privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Feb 2013 | Edipro s.a.s.Edipro s.a.s. was fined by the Garante in the amount of EUR 100,000 for violations related to unsolicited telemarketing. The authority also cited the indiscriminate collection and communication of personal data. | IT | Garante | GDPR | €100,000 | ↗ |
| 09 Jun 2022 | Cribis Credit Management s.r.l.Cribis Credit Management s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company unjustifiably communicated debtor information to third parties, in breach of GDPR Article 5. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Mar 2018 | Cristiano PanepintoCristiano Panepinto was fined €26,000 by the Garante for sending promotional emails without obtaining users’ free and specific consent. The conduct breached Article 130 of the Italian Privacy Code. | IT | Garante | GDPR | €26,000 | ↗ |
| 09 Dec 2010 | Bios s.p.a.Bios s.p.a. was fined by the Italian Garante for failing to provide adequate and timely information about the processing of personal data through a video surveillance system. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 25 Jun 2015 | Azienda di Servizi per la persona "Carlo Pezzani" di VogheraThe company published the personal data of five guests on its website without a legal basis. This breached privacy rules and led to a fine imposed by the Garante. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Nov 2012 | Dusty s.r.l.Dusty s.r.l. was fined by the Italian Garante 66,000 EUR for implementing a biometric data collection system for employee attendance without properly appointing data processing officers and without obtaining the required consent. The authority found violations of several provisions of the data protection code. | IT | Garante | GDPR | €66,000 | ↗ |
| 12 Feb 2015 | Aloisio AngeloAloisio Angelo was fined EUR 25,000 by the Italian data protection authority, Garante. The case involved activating 15 phone cards in the names of 5 individuals without their knowledge, which breached data protection rules. | IT | Garante | GDPR | €25,000 | ↗ |
| 17 Dec 2015 | Caaf Cgil Sardegna srlCaaf Cgil Sardegna srl was fined by the Garante 12,000 EUR for failing to provide the required privacy notice on its website. The authority found this to be a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €12,000 | ↗ |