BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Mar 2016 | Comune di Ischia di CastroThe Municipality of Comune di Ischia di Castro was fined 4,000 EUR by the Garante for unlawfully publishing personal data of jury members on its online notice board for longer than the legally permitted period. The case concerned a breach of data protection rules and retention limits. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Feb 2022 | Comune di GuidizzoloComune di Guidizzolo was fined for publishing a complainant’s personal data, including name and professional qualification, in a public document without proper justification. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €2,000 | ↗ |
| 01 Jun 2023 | Comune di GuardiagreleComune di Guardiagrele was fined EUR 5,000 by the Garante for failing to provide an adequate response to a data access request. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing. | IT | Garante | GDPR | €5,000 | ↗ |
| 02 Jul 2020 | Comune di Greve in ChiantiComune di Greve in Chianti was fined by the Garante for unlawfully disclosing personal data relating to criminal convictions and proceedings. The conduct breached the principles of lawfulness, fairness, and transparency in data processing. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Jun 2014 | Comune di GraffignanoComune di Graffignano was fined EUR 4,000 by the Garante. The authority found that personal data remained published on the institutional website for longer than the legally allowed 15 days. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Jul 2022 | Comune di GinosaComune di Ginosa was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the whistleblowing context. The authority found that an adequately high level of confidentiality and protection for the data subjects was not ensured. | IT | Garante | GDPR | €5,000 | ↗ |
| 06 Nov 2014 | Comune di GerenzanoThe Municipality of Gerenzano was fined 4,000 EUR by the Garante for failing to appoint a socially useful worker as a data processor. The authority found this breached the minimum security measures required under the data protection code. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 May 2015 | Comune di GenovaThe Municipality of Genoa was fined by the Garante for unlawfully keeping personal and judicial data on its institutional website beyond the legally permitted period. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 28 Mar 2019 | Comune di GenovaComune di Genova was fined for unlawfully communicating personal data to third-party companies without a proper legal basis. The authority found a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 30 Jul 2015 | Comune di GallipoliThe Municipality of Gallipoli was fined by the Garante for unlawfully publishing personal data revealing health status on its institutional website. The conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Oct 2016 | Comune di FurnariThe Municipality of Furnari was fined 4,000 EUR by the Garante. The authority found that personal data remained published on the institutional website beyond the legally permitted period. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Oct 2016 | Comune di FurnariComune di Furnari was fined for publishing personal data on its institutional website. It also failed to respond to information requests from the Garante. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Jan 2020 | Comune di Francavilla FontanaThe Municipality of Francavilla Fontana was fined 10,000 EUR by the Garante for publishing personal data on its institutional website. The conduct breached data protection rules and triggered supervisory action. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Sept 2021 | Comune di FormiaComune di Formia was fined for processing personal data linked to parking subscription services without providing adequate information to data subjects. The authority also found excessive data collection and a failure to clearly define the role of the external data processor. | IT | Garante | GDPR | €30,000 | ↗ |
| 20 Jun 2024 | Comune di ForlìThe Municipality of Forlì was fined EUR 15,000 by the Garante for failing to embed data protection principles in the design of its video surveillance system. The authority found breaches of transparency and accountability requirements. | IT | Garante | GDPR | €15,000 | ↗ |
| 02 Apr 2015 | Comune di FolloComune di Follo was fined for unlawfully communicating personal data of children under three years old to a private company. The authority found this breached Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 26 Feb 2020 | Comune di Fogliano RedipugliaThe Municipality of Comune di Fogliano Redipuglia was fined by the Garante for unlawfully publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €6,000 | ↗ |
| 22 Feb 2018 | Comune di FiumicinoComune di Fiumicino was fined by the Garante for failing to notify a data breach within the required timeframe. The authority found a violation of the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 24 Jun 2021 | Comune di FiscianoComune di Fisciano was fined EUR 1,000 by the Garante for improper handling of personal data. The data were removed after the complaint, and the case concerned transparency and data protection obligations. | IT | Garante | GDPR | €1,000 | ↗ |
| 08 Feb 2007 | Comune di FirenzeGarante imposed a EUR 3,000 fine on Comune di Firenze for failing to provide adequate information to individuals about the processing of personal data through a video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |