BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Mar 2008 | MO.MA. s.r.l.MO.MA. s.r.l. was fined by the Garante for failing to comply with a request to confirm the conformity of personal data processing. The authority found a breach of Article 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Jan 2013 | Casa di cura Abano TermeCasa di cura Abano Terme was fined EUR 60,000 by the Garante for processing personal data without complying with the legal requirements and limits. The authority found a breach of Article 26 of the Italian Privacy Code. | IT | Garante | GDPR | €60,000 | ↗ |
| 14 Nov 2024 | Provvedimento del 14 novembre 2024 [10104860]Garante imposed a EUR 40,000 fine on a healthcare company for failing to update its security assessments in response to increased cyberattacks. The authority found a breach of GDPR Article 32 because technical and organizational measures were not adjusted to the changed risk level. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 Mar 2018 | ARC Informazioni s.r.l.ARC Informazioni s.r.l. was fined 20,000 EUR by the Garante. The authority found that the company failed to notify data processing activities as required by the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Dec 2010 | Impresa individuale Iba MarinoImpresa individuale Iba Marino was fined by the Garante 6,000 EUR for collecting personal data through its website without providing adequate information to data subjects. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 20 Jun 2013 | Terme di Montecatini s.p.a.Terme di Montecatini s.p.a. was fined by the Garante in the amount of 10,000 EUR. The company processed personal and sensitive data of national health service patients undergoing spa treatments without obtaining consent, in breach of Article 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Feb 2021 | Bonatti S.p.ABonatti S.p.A was fined EUR 40,000 by the Garante for violating data protection rules. The company improperly shared an employee's medical data with a third party. | IT | Garante | GDPR | €40,000 | ↗ |
| 02 Feb 2017 | Sigue Global Service LimitedSigue Global Service Limited was fined by the Garante 5,880,000 EUR for breaches of data protection rules and anti-money laundering requirements. The authority cited money transfers carried out without proper consent, techniques used to obscure the true origin of funds, and non-compliance with AML obligations. | IT | Garante | GDPR | €5,880,000 | ↗ |
| 27 Apr 2023 | Geico S.p.A.Geico S.p.A. was fined 40,000 EUR by the Garante for keeping former employees' email accounts active after the employment relationship ended. The authority found that the company accessed the contents of those accounts in breach of GDPR requirements. | IT | Garante | GDPR | €40,000 | ↗ |
| 17 Apr 2026 | Ausl ModenaAusl Modena was fined by the Garante in the amount of 3,500 EUR for creating duplicate patient records. The case involved processing health data without proper transparency and compliance with data protection rules. | IT | Garante | GDPR | €3,500 | ↗ |
| 27 Oct 2016 | Confezioni Hu LingzhiConfezioni Hu Lingzhi was fined EUR 2,400 by the Garante. The authority found that the company failed to provide data subjects with information about the processing of personal data through a video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 01 Dec 2011 | Soprintendenza per i beni architettonici, paesaggistici, storici, artistici e etnoantropologici per Napoli e provinciaThe Garante fined Soprintendenza 32,000 EUR for violations related to the processing of biometric data. The authority found that the processing did not comply with the required legal requirements. | IT | Garante | GDPR | €32,000 | ↗ |
| 10 Feb 2022 | Comune di GuidizzoloComune di Guidizzolo was fined for publishing a complainant’s personal data, including name and professional qualification, in a public document without proper justification. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €2,000 | ↗ |
| 13 May 2015 | Gelpi Elettrodomestici S.r.l.Gelpi Elettrodomestici S.r.l. was fined 30,000 EUR by the Garante. The case concerned the activation of SIM cards in individuals' names without their knowledge, which breached data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 14 May 2026 | Comune di Mirabella ImbaccariComune di Mirabella Imbaccari was fined for disclosing personal data online without a legal basis and for violating the data minimization principle. The authority also found that the municipality had failed to appoint a Data Protection Officer and to communicate the DPO’s contact details to the supervisory authority. | IT | Garante | GDPR | €1,800 | ↗ |
| 14 Jun 2019 | Facebook Ireland Ltd e Facebook Italy s.r.l.Facebook Ireland Ltd and Facebook Italy s.r.l. were fined EUR 1,000,000 by the Garante for violations involving the unauthorized sharing of user data with the application “Thisisyourdigitallife”. The case affected approximately 214,020 users. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 28 May 2015 | Tex97 s.r.l.Tex97 s.r.l. was fined EUR 20,000 by the Italian data protection authority, Garante. The company retained customers' telephone traffic data for more than 24 months, in breach of Article 132 of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 03 Oct 2013 | Forum Sport Center società sportiva dilettantistica S.r.l.Forum Sport Center società sportiva dilettantistica S.r.l. was fined by the Italian Garante in the amount of €8,400. The sanction concerned inadequate data protection notices for personal data collection and video surveillance systems. | IT | Garante | GDPR | €8,400 | ↗ |
| 04 Oct 2011 | Il Marmo s.r.l.Il Marmo s.r.l. was fined by the Garante in the amount of 10,000 EUR for failing to provide the required privacy notice on its website, specifically in the contact form. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Jul 2021 | Flowbird s.r.l.Flowbird s.r.l. was fined EUR 30,000 by the Garante for processing personal data through parking meters in Rome without a legal basis. The authority also found that the company failed to maintain a record of processing activities. | IT | Garante | GDPR | €30,000 | ↗ |