BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Apr 2015 | Comune di FolloComune di Follo was fined for unlawfully communicating personal data of children under three years old to a private company. The authority found this breached Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Apr 2021 | Ordine degli Avvocati di LagonegroOrdine degli Avvocati di Lagonegro was fined EUR 3,000 by the Garante for publishing the content of a PEC email on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €3,000 | ↗ |
| 23 May 2019 | Ordinanza ingiunzione - 23 maggio 2019 [9124593]The Garante imposed a fine of EUR 1,250 for the loss of medical documentation related to a patient's health assessment. The records were not found in either paper or electronic form, which constituted a breach of data protection rules. | IT | Garante | GDPR | €1,250 | ↗ |
| 06 Oct 2022 | Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante in the amount of 10,000 EUR for failing to respond to a data access request. The authority found a breach of Article 15 of the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Mar 2015 | Provincia di PisaProvincia di Pisa was fined €10,000 by the Garante. The authority found that employees at the employment center were not designated as data processing officers, resulting in insufficient security measures for handling personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Dec 2020 | Comune di Santo Stefano BelboComune di Santo Stefano Belbo was fined for unlawfully disclosing personal data, including names and legal information, on its website without a proper legal basis. The case concerned the publication of data that should not have been made publicly available. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Dec 2022 | Comune di Reggio EmiliaThe Municipality of Reggio Emilia was fined 8,000 EUR by the Garante for unlawfully publishing personal data, including health information, of a former employee on its website. The case concerned an unauthorized disclosure of sensitive information in breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 27 May 2021 | Intesa Sanpaolo s.p.a.Intesa Sanpaolo s.p.a. was fined by the Garante in the amount of 200,000 EUR for unlawfully communicating banking data to an unauthorized third party. The case concerned breaches of data protection principles, including lawfulness and restricted access to information. | IT | Garante | GDPR | €200,000 | ↗ |
| 20 Jun 2024 | Max & Mix Ferrara s.r.l.Max & Mix Ferrara s.r.l. was fined €5,000 by the Garante for operating a video surveillance system with 32 cameras without the required informational signage. The authority found this to be a breach of GDPR information obligations. | IT | Garante | GDPR | €5,000 | ↗ |
| 04 Jun 2025 | INTS Italia S.r.l.INTS Italia S.r.l. was fined 15,000 EUR by the Garante for failing to provide employees with adequate information on data protection and for not responding to data access requests. The authority found that the company breached core GDPR principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 09 Jul 2020 | Wind Tre S.p.A.Wind Tre S.p.A. was fined by the Garante 16,729,600 EUR for carrying out promotional activities without ensuring that contacts respected the wishes of individuals who did not want to receive marketing communications. The case concerns GDPR requirements on consent and the right to object to direct marketing. | IT | Garante | GDPR | €16,729,000 | ↗ |
| 12 Feb 2015 | Enescu Georgiana OfeliaEnescu Georgiana Ofelia was fined 2,400 EUR by the Italian supervisory authority Garante. The case concerned failure to provide data subjects with the required information about video surveillance at the business premises, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 11 May 2017 | Laboratorio Villafranca sncLaboratorio Villafranca snc was fined EUR 20,000 by the Italian data protection authority, Garante. The case concerned a failure to properly notify data processing activities under the Italian data protection code. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Nov 2023 | Autostrade per l’Italia S.p.A.Autostrade per l’Italia S.p.A. was fined by the Garante 100,000 EUR for failing to respond to employees' requests for access and rectification of personal data linked to annual severance pay calculations. The case concerns a failure to meet obligations for handling data subject rights requests. | IT | Garante | GDPR | €100,000 | ↗ |
| 20 Oct 2022 | Istituto di Istruzione Superiore “G. Renda” di Polistena, Reggio CalabriaIstituto di Istruzione Superiore “G. Renda” was fined EUR 900 by the Garante for unlawfully processing personal data. The school published sensitive information about an employee’s contract termination without a legal basis, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €900 | ↗ |
| 29 Apr 2021 | Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante in the amount of 4,000 EUR for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization because personal data remained accessible online for an extended period. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jan 2015 | Francesco Saverio ManesFrancesco Saverio Manes was fined by the Garante EUR 2,400 for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system at the cultural club “K2”. The case concerned the absence of mandatory notices for individuals captured by the CCTV system. | IT | Garante | GDPR | €2,400 | ↗ |
| 16 Jan 2014 | Bios Marx s.r.l.Bios Marx s.r.l. was fined by the Italian Garante in the amount of EUR 16,000 for providing an inadequate privacy notice during a medical initiative. The authority also found that personal data were shared with third parties without obtaining specific consent. | IT | Garante | GDPR | €16,000 | ↗ |
| 05 May 2011 | Mondolibri s.p.a.Mondolibri s.p.a. was fined EUR 8,000 by the Garante for collecting personal email addresses through its website without providing adequate information to the data subjects. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 07 Mar 2024 | Ministero della saluteThe Italian Ministry of Health was fined EUR 100,000 by the Garante for inadequate data protection and communication measures in the National Health Information System. The authority found breaches of GDPR requirements on data security and breach notification. | IT | Garante | GDPR | €100,000 | ↗ |