BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jun 2023 | Thin SrlThin Srl was fined EUR 15,000 by the Garante for breaching the GDPR principles of lawfulness, fairness, and transparency in data processing. The case concerned processing activities linked to a medical project. | IT | Garante | GDPR | €15,000 | ↗ |
| 22 Oct 2015 | Comune di ZagariseComune di Zagarise was fined for processing employees’ biometric data without notifying the Garante and without requesting prior verification. The authority found violations of Articles 17 and 37 of the Codice. | IT | Garante | GDPR | €12,000 | ↗ |
| 24 Sept 2015 | Acquapark di Milillo Rosa & C. s.a.s.Acquapark di Milillo Rosa & C. s.a.s. was fined EUR 6,400 by the Garante for collecting personal data without providing the required information notice and for publishing user photos without consent. The case concerns failures to meet transparency obligations and lawful processing requirements. | IT | Garante | GDPR | €6,400 | ↗ |
| 03 Apr 2014 | Robianton s.r.l.Robianton s.r.l. was fined by the Garante in the amount of 2,400 EUR. The authority found that the company failed to provide the simplified information required by the data protection code and the rules on video surveillance. | IT | Garante | GDPR | €2,400 | ↗ |
| 06 Jul 2016 | Sorec s.r.l.Sorec s.r.l. was fined EUR 4,000 by the Garante for inadequate password security in its data processing systems. The case concerned non-compliance with data protection requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 15 Jan 2020 | TIM S.p.A.TIM S.p.A. was fined by the Garante for making unauthorized promotional calls. The authority found that the company failed to ensure adequate consent and accountability measures under data protection rules. | IT | Garante | GDPR | €27,802,000 | ↗ |
| 06 Oct 2022 | Alpha Exploration Co. Inc.Alpha Exploration Co. Inc. was fined by the Garante EUR 2,000,000 for violations related to data processing practices on its social media platform, Clubhouse. The case concerned irregularities in the way user data was processed. | IT | Garante | GDPR | €2,000,000 | ↗ |
| 21 Feb 2013 | American Express Services Europe LimitedAmerican Express Services Europe Limited was fined EUR 60,000 by the Garante. The authority found that the security program document was not updated in line with the technical rules on minimum security measures. | IT | Garante | GDPR | €60,000 | ↗ |
| 06 Feb 2014 | Genesis Consulting s.r.l.Genesis Consulting s.r.l. was fined EUR 4,000 by the Garante. The authority found that personal data collected through a website form were used for marketing purposes without adequate notice and without specific consent. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Jul 2014 | Onbrand Call s.r.lOnbrand Call s.r.l was fined by the Garante for processing personal data through a web form without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 18 Sept 2008 | Universitalia s.r.l.Universitalia s.r.l. was fined €6,000 by the Italian data protection authority, Garante. The authority found that the company failed to provide adequate privacy information to data subjects as required by the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 29 Apr 2021 | Azienda socio sanitaria territoriale Melegnano e della MartesanaAzienda socio sanitaria territoriale Melegnano e della Martesana was fined by the Garante €6,000 for a data breach involving the loss of health data. The case concerned special-category personal data and indicates insufficient organizational or technical safeguards. | IT | Garante | GDPR | €6,000 | ↗ |
| 03 Feb 2011 | Able Tech s.r.l.Able Tech s.r.l. was fined EUR 9,000 by the Garante for failing to provide timely information to the data subject. The breach concerned the obligation under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 24 Oct 2013 | ASL n.1 – Avezzano/Sulmona/L'AquilaASL n.1 – Avezzano/Sulmona/L'Aquila was fined EUR 8,000 by the Garante. The authority found a breach consisting of failure to make the notification required under the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 24 May 2017 | LAM Centro Biomedico s.r.l.LAM Centro Biomedico s.r.l. was fined by the Garante for failing to notify the corporate name change following a merger. The case involved processing sensitive personal data, which required informing the supervisory authority. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Feb 2025 | Claudio BattagliaDr. Claudio Battaglia, an oncologist, was fined for using patient data for electoral propaganda without consent. The case indicates a breach of GDPR principles on lawfulness and purpose limitation. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Jul 2025 | Comune di Tocco da CasauriaComune di Tocco da Casauria was fined EUR 2,000 by the Garante for publishing personal data on its institutional website. The authority found that the processing did not comply with the principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |
| 02 Mar 2023 | Flowers R di Malalan MitjaMalalan Mitja was fined by the Garante in the amount of 5,000 EUR for sending unsolicited promotional emails. The messages were sent to randomly generated email addresses, which constituted a breach of GDPR requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 01 Aug 2012 | S.I.G.A.T. s.r.l.S.I.G.A.T. s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 13,400. The case concerned the sending of unsolicited promotional faxes without prior consent from recipients. | IT | Garante | GDPR | €13,400 | ↗ |
| 17 May 2023 | La Gazzetta di Parma S.r.l.La Gazzetta di Parma S.r.l. was fined by the Garante EUR 10,000 for publishing an image of a presumed murderer in breach of privacy rules. The person was shown in a state of physical restraint without proper anonymization. | IT | Garante | GDPR | €10,000 | ↗ |