BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Jun 2011 | Azienda ospedaliera San Giuseppe Moscati (AOSGM)Azienda ospedaliera San Giuseppe Moscati was fined EUR 20,000 by the Garante. The authority found that the security program document was not updated and that minimum security measures were not adopted for the processing of health data. | IT | Garante | GDPR | €20,000 | ↗ |
| 08 May 2013 | Agro Informatica di Buracchi GinoAgro Informatica di Buracchi Gino was fined 32,000 EUR by the Garante for sending unsolicited promotional emails without prior explicit consent. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €32,000 | ↗ |
| 18 Oct 2012 | Umbra Acque S.p.a.Umbra Acque S.p.a. was fined by the Garante 10,000 EUR for breaches of data protection rules. The authority found that the company failed to designate data processing officers and did not adopt minimum security measures for its video surveillance system. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 May 2025 | Agenzia di Tutela della Salute, della Città Metropolitana di Milano, Servizio Prevenzione e Sicurezza Ambienti di Lavoro Milano Città NordAgenzia di Tutela della Salute was fined EUR 7,000 by the Garante for improperly sending medical reports and certificates. The authority found a breach of data protection rules. | IT | Garante | GDPR | €7,000 | ↗ |
| 11 Sept 2025 | Provvedimento dell'11 settembre 2025 [10184654]The decision imposes a fine on a healthcare company for cybersecurity-related breaches following a security incident involving patient data. The authority found non-compliance with Articles 25 and 32 GDPR. | IT | Garante | GDPR | €8,000 | ↗ |
| 25 Mar 2021 | GEDI News Network S.p.a.GEDI News Network S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The case concerned failure to comply with a request to delete personal data from an article about a 1998 legal case, which remained prejudicial because the outcome was not updated. | IT | Garante | GDPR | €20,000 | ↗ |
| 24 Jun 2021 | Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” di NovaraThe Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” in Novara was fined by the Garante EUR 2,000. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |
| 11 Mar 2021 | Planet Group spaPlanet Group spa was fined EUR 80,000 by the Garante. The authority found that the company made unsolicited promotional calls without a proper legal basis, breaching GDPR rules on data processing and privacy by design. | IT | Garante | GDPR | €80,000 | ↗ |
| 28 Apr 2022 | Educationest s.r.l.Educationest s.r.l. was fined EUR 1,000 by the Italian data protection authority, Garante. The case concerned the unlawful disclosure of an employee’s pregnancy status to third parties via email, in breach of data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 06 Jun 2018 | MP Tuscolana s.r.l.MP Tuscolana s.r.l. was fined EUR 20,000 by the Garante for the unauthorized activation of two phone cards without the consent of the individuals concerned. The case indicates a failure to obtain valid consent before activating the services. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 May 2018 | Luigi PagnanelliLuigi Pagnanelli, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Jul 2024 | Postel S.p.A.Postel S.p.A. was fined by the Garante EUR 900,000 for a data breach following a ransomware attack. The attack exploited vulnerabilities in the Microsoft Exchange platform, resulting in unauthorized access to data and publication on the dark web. | IT | Garante | GDPR | €900,000 | ↗ |
| 07 Mar 2024 | Hotel Milano di Foschi Eros e Righini Rina & C. SncThe Garante fined Hotel Milano EUR 3,000 for improper installation of surveillance cameras. The cameras captured public streets and third-party properties, and the informational signage was inadequate. | IT | Garante | GDPR | €3,000 | ↗ |
| 13 May 2015 | Ottodue s.r.l.Ottodue s.r.l. was fined EUR 12,000 by the Garante for retaining surveillance footage for 98 days. This exceeded the 7-day retention limit set out in the video surveillance guidelines. | IT | Garante | GDPR | €12,000 | ↗ |
| 27 Mar 2025 | Provvedimento del 27 marzo 2025 [10140216]The Garante fined Powerfit, Soleo, and Zero Due Villa for sending promotional SMS messages without the recipients’ consent. The messages also did not provide an opt-out mechanism, which breached GDPR requirements. | IT | Garante | GDPR | €6,000 | ↗ |
| 26 Feb 2020 | Comune di Fogliano RedipugliaThe Municipality of Comune di Fogliano Redipuglia was fined by the Garante for unlawfully publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €6,000 | ↗ |
| 05 Feb 2015 | Comune di BellizziComune di Bellizzi was fined for unlawfully publishing sensitive personal data revealing health information on its institutional website. The conduct breached privacy rules governing the processing and disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Comune di Motta Sant'AnastasiaThe Garante imposed a EUR 10,000 fine on Comune di Motta Sant'Anastasia for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Feb 2016 | Anteprima Group srlAnteprima Group srl was fined EUR 6,400 by the Garante. The case concerned an unsolicited promotional call made without prior information to the recipient and without obtaining consent. | IT | Garante | GDPR | €6,400 | ↗ |
| 01 Apr 2009 | Casa di cura Sant'Antonio s.p.a.Casa di cura Sant'Antonio s.p.a. was fined by the Italian data protection authority, Garante. The case concerned processing personal data without the required notification under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |