BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Jul 2024 | Comune di TrevisoThe Garante fined Comune di Treviso EUR 7,000 for failing to adopt internal measures governing data processing in connection with the TrevisoSicura application. The authority also found that the municipality incorrectly assumed the role of data processor instead of properly defining its data protection responsibilities. | IT | Garante | GDPR | €7,000 | ↗ |
| 04 Apr 2007 | Azienda sanitaria locale di PescaraAzienda sanitaria locale di Pescara was fined €10,000 by the Garante for breaching data protection rules. The case involved improper handling of sensitive personal data, including genetic and health information, without the required notification to the authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 May 2020 | Azienda Teatro del GiglioAzienda Teatro del Giglio was fined 6,000 EUR by the Garante for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €6,000 | ↗ |
| 26 Sept 2024 | CI & DI Food s.r.l.CI & DI Food s.r.l. was fined by the Garante 4,000 EUR for failing to respond to an employee’s request to access personal data related to employment. The request included work attendance records. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Apr 2021 | Isinc S.r.l.s.Isinc S.r.l.s. was fined 20,000 EUR by the Garante for sending promotional emails using personal data taken from public databases without proper consent. The authority found this conduct to be in breach of GDPR Article 5. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Jul 2017 | InvalsiInvalsi was fined EUR 40,000 by the Italian Garante for unlawful processing of personal data. The case concerned the online publication of files containing disaggregated student personal data, including sensitive information. | IT | Garante | GDPR | €40,000 | ↗ |
| 06 Jun 2024 | Drivalia Leasys Rent S.p.A.Drivalia Leasys Rent S.p.A. was fined by Garante 250,000 EUR for denying a car rental voucher to a customer listed on a blacklist. The authority found insufficient transparency in data processing and a lack of proper legal basis and consent under GDPR. | IT | Garante | GDPR | €250,000 | ↗ |
| 09 Jul 2020 | Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 800,000 by the Garante for irregularities in the processing of customer data. The violations concerned SIM card activation, promotional use of data, inadequate security measures, and improper data retention. | IT | Garante | GDPR | €800,000 | ↗ |
| 25 Jan 2018 | Trivenet s.r.l.Trivenet s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company retained call data longer than permitted under data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 17 Jul 2024 | Azienda ULSS n. 14The Garante fined Azienda ULSS n. 14 EUR 22,000 for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies resulted in a data breach involving sensitive health data. | IT | Garante | GDPR | €22,000 | ↗ |
| 17 Dec 2020 | Azienda Unità Sanitaria Locale Toscana Sud EstAzienda Unità Sanitaria Locale Toscana Sud Est was fined for processing personal data without proper safeguards. The authority also found that patient data was shared without anonymization, in breach of GDPR requirements. | IT | Garante | GDPR | €100,000 | ↗ |
| 21 Apr 2011 | Azienda USL della Valle D'AostaAzienda USL della Valle D'Aosta was fined for processing personal data during phone bookings without providing the required information notice and for failing to update the security program document. The authority found these actions breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 09 May 2018 | Amiu S.p.a.Amiu S.p.a. was fined by the Garante 20,000 EUR for improper processing of personal data through its video surveillance systems. The authority found that the company failed to properly designate data processing personnel and to implement adequate data protection measures. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 May 2015 | Zampino Giuseppe GiovanniZampino Viaggi, operated by Zampino Giuseppe Giovanni, was fined 2,400 EUR by the Garante. The authority found that personal data were collected through the website without the required privacy notice, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 27 Apr 2011 | Comune di AdroThe Municipality of Adro was fined 15,000 EUR by the Italian supervisory authority Garante. The case concerned the publication of employees’ personal data, including health information, in a periodical. | IT | Garante | GDPR | €15,000 | ↗ |
| 10 Dec 2015 | Aruba s.p.a.Aruba s.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 40,000. The case concerned the sending of promotional emails without obtaining the required consent, in breach of articles 23 and 130 of the Italian data protection code. | IT | Garante | GDPR | €40,000 | ↗ |
| 19 Mar 2015 | Liceo Statale "Farnesina"Liceo Statale Farnesina was fined EUR 4,000 by the Garante for unlawfully publishing lists of student names on its institutional website without a legal basis. The conduct breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 Jan 2014 | Goldenbridge s.r.l.Goldenbridge s.r.l. was fined EUR 2,400 by the Garante for failing to provide the required privacy notice when collecting personal data through a website contact form. The authority found this to be a breach of the Italian data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 17 Jan 2008 | Assioma selezione e sviluppo s.r.l.Assioma selezione e sviluppo s.r.l. was fined by the Garante in the amount of 10,000 EUR for failing to comply with data protection notification requirements. The breach concerned Article 163 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2014 | Zheng SuigenZheng Suigen was fined by the Italian data protection authority, Garante, in the amount of EUR 2,400. The case concerned inadequate information about the use of a video surveillance system, which breached privacy rules. | IT | Garante | GDPR | €2,400 | ↗ |