BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 May 2013 | Chen JingChen Jing was fined by the Italian Garante in the amount of EUR 2,400 for providing inadequate information about a video surveillance system at Ottimoda S.a.s. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 07 Apr 2016 | Comune di LizzanoComune di Lizzano was fined by the Garante for publishing personal data, including health information about a minor, on its online notice board. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Dec 2022 | Giessegi Industria Mobili S.p.A.Giessegi Industria Mobili S.p.A. was fined by the Garante 50,000 EUR for unlawful processing of personal data. The company installed a device to track the geographical location of a vehicle used by an employee, in breach of GDPR requirements. | IT | Garante | GDPR | €50,000 | ↗ |
| 10 Apr 2025 | Acea EnergiaAcea Energia was fined EUR 3,000,000 by the Garante. The authority found unauthorized telemarketing activities and insufficient protection of databases against access by unauthorized agents. | IT | Garante | GDPR | €3,000,000 | ↗ |
| 22 May 2018 | C.R.M. S.r.l.C.R.M. S.r.l. was fined EUR 28,000 for using a biometric system to record employee attendance without prior notification to the Garante. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €28,000 | ↗ |
| 18 Nov 2015 | 24 Media s.r.l.24 Media s.r.l. was fined EUR 4,000 by the Garante. The authority found that the company required mandatory consent for purposes beyond the original data collection intent, including promotional communications and sharing data with third parties. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Feb 2010 | ADEC Assistenza dentistica e cure odontoiatriche-ortodontiche s.r.l.ADEC Assistenza dentistica e cure odontoiatriche-ortodontiche s.r.l. was fined 6,000 EUR by the Garante. The authority found that personal data were processed through the website contact form without the required information notice, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 21 Mar 2013 | dr. Attilio Vincenzo PignatelliDr. Attilio Vincenzo Pignatelli was fined by the Garante EUR 2,400 for operating a video surveillance system without the required simplified notice and for failing to comply with data retention rules. The case concerned non-compliance with information duties and retention periods for recorded footage. | IT | Garante | GDPR | €2,400 | ↗ |
| 02 Jul 2020 | Istituto Comprensivo di Uggiano La ChiesaIstituto Comprensivo di Uggiano La Chiesa was fined €2,000 by the Garante for posting lists at the school entrance that included minors' names, dates of birth, addresses, phone numbers, and vaccination status. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €2,000 | ↗ |
| 16 Dec 2009 | Casa di cura Villa Russo s.p.a.Casa di cura Villa Russo s.p.a. was fined by the Garante for processing personal data without proper notification. The authority found violations of articles 37 and 38 of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 15 Nov 2012 | Gruppo Ro.Ri. s.r.l.The Garante fined Gruppo Ro.Ri. s.r.l. 24,000 EUR for inadequate data protection measures linked to its video surveillance systems. The company also failed to provide proper information to data subjects as required by the privacy code. | IT | Garante | GDPR | €24,000 | ↗ |
| 13 Jul 2016 | Xu Ja s.n.c.Xu Ja s.n.c. was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned failure to provide simplified information about video surveillance, as required under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 11 Apr 2019 | Vincall s.r.l.sVincall s.r.l.s was fined EUR 2,018,000 by the Garante for failing to provide required information to individuals contacted during telemarketing activities. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €2,018,000 | ↗ |
| 26 Mar 2026 | PSK AD Network S.r.l.PSK AD Network S.r.l. was fined EUR 5,000 by the Garante. The case concerned the failure to respond to a data subject’s deletion request and the failure to provide information requested by the authority, in breach of Article 157 of the Codice. | IT | Garante | GDPR | €5,000 | ↗ |
| 13 Feb 2014 | 2MTech di Renzo De Luca2MTech di Renzo De Luca was fined 2,400 EUR by the Garante. The authority found that the company sent unsolicited promotional emails and provided inadequate information notices on its websites. | IT | Garante | GDPR | €2,400 | ↗ |
| 09 Jul 2020 | Comune di BaronissiComune di Baronissi was fined by the Garante for publishing personal data online without a proper legal basis. The authority found a breach of the data minimization principle. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 Apr 2025 | Cooperativa Sociale QuadrifoglioThe Garante imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio for violations related to data processing. The case concerned non-compliance with personal data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Feb 2015 | Comune di CampotostoComune di Campotosto was fined by the Garante for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy and personal data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Mar 2015 | Istituto Professionale di Stato per i Servizi Commerciali Turistici Alberghieri "Cesare Musatti"The Istituto Professionale di Stato per i Servizi Commerciali Turistici Alberghieri “Cesare Musatti” was fined by the Italian data protection authority, Garante, in the amount of €10,000. The violation involved unlawfully publishing personal data on its website that revealed students’ health status. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2026 | Ristorante pizzeria CN 45The Garante fined Ristorante pizzeria CN 45 2,000 EUR for operating a video surveillance system without proper compliance. The case concerns GDPR breaches related to the lawful operation and implementation of CCTV monitoring. | IT | Garante | GDPR | €2,000 | ↗ |