BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 May 2019 | Comune di FerraraComune di Ferrara was fined 2,400 EUR by the Garante for violations linked to its online registry service. The system allowed citizens to obtain personal and civil status certificates at municipal pharmacies without adequate data protection measures. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Jan 2021 | Comune di Falconara MarittimaComune di Falconara Marittima was fined EUR 10,000 by the Garante for violating data protection principles. The authority found improper processing of personal data in a disciplinary context, including breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Apr 2018 | Comune di DerutaThe Municipality of Deruta was fined 10,000 EUR for unlawfully providing lists of personal data of residents born in 1994–1996 to a private educational institution. The recipient was not entitled to receive the data under public utility exceptions. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Oct 2025 | Comune di CurtaroloComune di Curtarolo was fined EUR 15,000 by the Garante for using surveillance footage for disciplinary purposes without proper legal justification. The authority also found that adequate privacy information was not provided to the individuals concerned. | IT | Garante | GDPR | €15,000 | ↗ |
| 12 Dec 2024 | Comune di Corte FrancaComune di Corte Franca was fined EUR 6,000 for publishing personal data online without a proper legal basis. The authority found breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 16 Jan 2025 | Comune di CoriThe Garante fined Comune di Cori EUR 2,000 for violations related to the processing of personal data in connection with the issuance of the “Dedicata a te” card. The case involved electronic payment cards provided by Poste Italiane. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Mar 2014 | Comune di ConversanoComune di Conversano was fined 4,000 EUR by the Garante for failing to update the annual Security Policy Document. The breach concerned compliance with data protection obligations. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Jul 2025 | Comune di ConversanoComune di Conversano was fined €3,000 by the Garante for failing to communicate the contact details of its Data Protection Officer. The breach concerned the obligation under Article 37 GDPR to notify the supervisory authority. | IT | Garante | GDPR | €3,000 | ↗ |
| 15 Oct 2020 | Comune di CollegnoComune di Collegno was fined by the Garante for failing to respond in time to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €2,000 | ↗ |
| 30 Jan 2020 | Comune di ColledaraComune di Colledara was fined EUR 4,000 by the Garante for publishing personal data in the provisional ranking of a competition on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Jun 2021 | Comune di Cogollo del CengioThe Municipality of Comune di Cogollo del Cengio was fined by the Garante 1,000 EUR for unlawfully publishing personal data related to a disciplinary procedure. The authority found no legal basis for the disclosure and held that it breached the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 13 Apr 2023 | Comune di Cogollo del CengioThe Garante fined Comune di Cogollo del Cengio EUR 3,000 for breaches of GDPR Articles 5, 6 and 9, as well as Articles 2-ter and 2-septies of the Italian Privacy Code. The case concerned the processing of an employee’s personal data without an adequate legal basis and in breach of data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 17 Apr 2026 | Comune di CogoletoComune di Cogoleto was fined EUR 4,000 by the Garante for failing to ensure transparency in data processing. The authority also found that no data protection impact assessment had been carried out, breaching the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Feb 2026 | Comune di CoccaglioComune di Coccaglio was fined EUR 6,000 for using surveillance footage for disciplinary purposes without informing employees. The authority also found that no data protection impact assessment had been carried out, in breach of data protection rules. | IT | Garante | GDPR | €6,000 | ↗ |
| 05 Oct 2017 | Comune di CivitavecchiaComune di Civitavecchia was fined by the Garante for unlawfully transmitting sensitive data revealing the health status of disabled students to service providers without a proper legal basis. The authority found that the processing breached data protection and confidentiality requirements. | IT | Garante | GDPR | €30,000 | ↗ |
| 22 Feb 2024 | Comune di Civita CastellanaComune di Civita Castellana was fined EUR 3,000 by the Garante for improper handling of personal data during COVID-19 data transmission. The authority found that GDPR formalities were not properly complied with. | IT | Garante | GDPR | €3,000 | ↗ |
| 10 Nov 2022 | Comune di Cisterna di LatinaComune di Cisterna di Latina was fined 5,000 EUR by the Garante for violating data protection principles, including data minimization. Improper handling of personal data led to unauthorized access by third parties. | IT | Garante | GDPR | €5,000 | ↗ |
| 04 Jul 2013 | Comune di CiampinoThe Municipality of Ciampino was fined EUR 4,000 by the Garante for publishing on its website a list containing personal data of individuals eligible to serve as polling station scrutineers. The publication was made without an appropriate legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Jan 2021 | Comune di Cesano BosconeThe Municipality of Cesano Boscone was fined EUR 2,000 by the Garante for publishing personal data related to a disciplinary sanction on its website. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €2,000 | ↗ |
| 17 Apr 2014 | Comune di CavedineThe Municipality of Cavedine was fined by the Garante 4,000 EUR for publishing personal data online longer than legally permitted. The case concerned a breach of data protection rules and limits on online retention. | IT | Garante | GDPR | €4,000 | ↗ |