BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Nov 2024 | Comune di Torre AnnunziataThe Garante imposed a EUR 2,000 fine on Comune di Torre Annunziata for failing to communicate the contact details of its Data Protection Officer. This obligation arises under Article 37(7) GDPR and is intended to ensure the supervisory authority can reach the DPO. | IT | Garante | GDPR | €2,000 | ↗ |
| 06 Feb 2020 | Liceo Artistico Statale di NapoliLiceo Artistico Statale di Napoli was fined EUR 4,000 by the Garante for publishing an outdated teacher ranking on its institutional website. The authority found this breached GDPR principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Nov 2022 | Areti S.p.A.Areti S.p.A. was fined EUR 1,000,000 by the Garante for incorrectly labeling a customer as a “defaulting client” based on inaccurate and outdated data. The issue may have affected up to 16,743 other individuals, indicating a broader data processing failure. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 24 Jul 2014 | Easy Call srlEasy Call srl was fined EUR 112,000 by the Garante for making unsolicited promotional calls. The company contacted individuals listed in the opposition register, breaching data protection rules. | IT | Garante | GDPR | €112,000 | ↗ |
| 20 Mar 2014 | SIGE S.p.a.SIGE S.p.a. was fined by the Italian data protection authority, Garante, in the amount of €14,400. The case concerned a video surveillance system that retained images longer than permitted under the Garante's guidelines. | IT | Garante | GDPR | €14,400 | ↗ |
| 29 May 2008 | Target informatica di Rebosio GiancarloThe sole proprietorship Target informatica di Rebosio Giancarlo was fined EUR 1,549 by the Garante. The sanction concerned sending unsolicited promotional emails without providing the required information notice to the data subjects, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €1,549 | ↗ |
| 02 Oct 2019 | Tgroup s.r.l.Tgroup s.r.l. was fined 6,400 EUR by the Italian data protection authority, Garante. The case concerned the activation of a SIM card without the user's knowledge, which breached data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 01 Mar 2018 | Ministero dell’Istruzione, dell’Università e della RicercaThe Ministry of Education, University and Research was fined €16,000 by the Garante for violations related to the handling of personal data in the implementation of the “Carta docente” application. The case concerned deficiencies in the way user data was processed within the service. | IT | Garante | GDPR | €16,000 | ↗ |
| 23 Oct 2025 | Franco SpellecchiaFranco Spellecchia was fined by the Garante for installing a video surveillance system around his residence without the required legal basis. The authority found that the setup breached GDPR rules, including the absence of a legitimate interest or authorization. | IT | Garante | GDPR | €500 | ↗ |
| 16 Dec 2021 | Centro di Medicina preventiva s.r.l.Centro di Medicina preventiva s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate measures to prevent unauthorized access to personal data. The deficiency resulted in a data breach. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Mar 2013 | Unitelma SapienzaUnitelma Sapienza was fined EUR 8,000 by the Garante for failing to provide information to data subjects and for not obtaining consent to process sensitive data. The violations occurred during online registration for university courses. | IT | Garante | GDPR | €8,000 | ↗ |
| 21 Jul 2022 | Stay Over s.r.l.Stay Over s.r.l. was fined by the Garante EUR 10,000 for a delayed and inadequate response to a data access request. The authority also found unlawful processing of a former employee's email account after employment ended. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 Feb 2007 | RFI S.p.A.RFI S.p.A. was fined EUR 54,000 by the Garante for failing to provide the required data protection information to individuals covered by video surveillance at several train stations. The authority found a breach of data protection rules. | IT | Garante | GDPR | €54,000 | ↗ |
| 11 Apr 2013 | Teknoelettronica s.r.l.Teknoelettronica s.r.l. was fined EUR 6,000 by the Italian data protection authority, Garante. The company failed to provide the required privacy notice on its website, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 05 Mar 2020 | Azienda Sanitaria Locale di Ciriè, Chivasso e Ivrea (ASL TO4)ASL TO4 was fined by the Garante EUR 8,000 for unlawful data processing through video surveillance. The authority found that the required agreements with unions were not in place. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Mar 2025 | Comune di RoccarasoThe Garante fined Comune di Roccaraso EUR 2,000 for publishing personal data on a public notice board. The authority found breaches of GDPR Articles 5, 6 and 12, as well as Article 2-ter of the Italian Privacy Code. | IT | Garante | GDPR | €2,000 | ↗ |
| 02 Jul 2020 | GTL s.r.l.GTL s.r.l. was fined EUR 3,000 by the Garante for failing to respond to an individual's data access request. The authority treated this as a breach of GDPR obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 13 Apr 2023 | Ordine degli Avvocati di AnconaThe Garante fined the Ordine degli Avvocati di Ancona 20,000 EUR for violations related to data processing transparency and security. The authority found incorrect privacy notices and non-compliance with GDPR principles. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Oct 2017 | Antea Service soc. coop.Antea Service soc. coop. was fined by the Garante 10,000 EUR for unlawfully processing biometric data of employees. The data were used to monitor workplace attendance. The case concerns a breach of personal data protection rules in an employment context. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Oct 2024 | AziendaThe company was fined for failing to implement adequate security measures, which led to a data breach affecting a large number of individuals. The case indicates insufficient protection of personal data and elevated risk to data subjects. | IT | Garante | GDPR | €25,000 | ↗ |