BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Sept 2006 | Asl FerraraAsl Ferrara was fined by the Garante for processing genetic, health, and sexual life data without the required notification. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Asl 21 di Casale MonferratoThe Garante fined Asl 21 di Casale Monferrato 10,000 EUR for processing genetic and health data without the required notification. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Asl VercelliAsl Vercelli was fined by the Garante for processing special-category personal data, including genetic and health data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | De.Mo. s.r.l.De.Mo. s.r.l. was fined 3,000 EUR by the Garante for failing to provide the required information to data subjects under Article 13 of the Italian Data Protection Code. The breach occurred in connection with the company’s marketing activities. | IT | Garante | GDPR | €3,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale di PiacenzaAzienda sanitaria locale di Piacenza was fined for failing to notify the Garante about processing data relating to health and sexual life. The authority treated this as a breach of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Centro diagnostico Helios s.n.c.Centro diagnostico Helios s.n.c. was fined for failing to notify the processing of sensitive health data, including HIV status and other medical conditions. The authority treated this as a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Pasquadibisceglie PaoloPasquadibisceglie Paolo was fined by the Garante 3,000 EUR for failing to provide adequate information to individuals recorded by a video surveillance system in a commercial establishment. The authority found a breach of privacy rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale n. 6 di CirièASL Ciriè was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The breach concerned obligations under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Nov 2006 | Anonymised (HDPA 61/2006)A hospital was fined for failing to properly inform the complainant about the transmission of sensitive health data. The case concerns a breach of the duty to provide clear information to the data subject. | GR | HDPA | GDPR | €3,000 | ↗ |
| 20 Nov 2006 | Anonymised (HDPA 61/2006)An insurance company was fined for unlawfully transmitting the complainant’s sensitive health data. The case concerned a breach of the rules governing the lawful processing of special-category personal data. | GR | HDPA | GDPR | €15,000 | ↗ |
| 08 Feb 2007 | RFI S.p.A.RFI S.p.A. was fined EUR 54,000 by the Garante for failing to provide the required data protection information to individuals covered by video surveillance at several train stations. The authority found a breach of data protection rules. | IT | Garante | GDPR | €54,000 | ↗ |
| 08 Feb 2007 | Asl Vibo ValentiaThe health authority Asl Vibo Valentia was fined by Garante for improperly handling sensitive personal data, including genetic and biometric data, without proper authorization. The case concerns a breach of data protection rules and the legal basis required for processing such data. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 Feb 2007 | Comune di FirenzeGarante imposed a EUR 3,000 fine on Comune di Firenze for failing to provide adequate information to individuals about the processing of personal data through a video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 08 Feb 2007 | Asl OristanoAsl Oristano was fined EUR 10,000 by the Garante for failing to notify the processing of personal data concerning health and sexual life. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl Alto MoliseAsl Alto Molise was fined 10,000 EUR by the Garante for failing to notify data processing activities related to health diagnosis, treatment, and prevention within the required timeframe. The breach violated the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl Centro MoliseAsl Centro Molise was fined by the Garante for processing personal data, including genetic and biometric data, without the required notification. The breach concerned obligations under the Italian data protection code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl Basso MoliseAsl Basso Molise was fined by the Garante for failing to notify its data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl n. 5 CrotoneAsl n. 5 Crotone was fined by the Garante for failing to notify the processing of sensitive personal data, including genetic and health data. The notification requirement was set out in the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2007 | Asl di Maglie (Lecce)Asl di Maglie (Lecce) was fined by the Garante for failing to notify personal data processing activities within the required timeframe. This constituted a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Apr 2007 | Asl Brindisi 1The Garante fined Asl Brindisi 1 for failing to notify the processing of personal data under the Italian Data Protection Code. Article 37 was violated, and the fine amounted to EUR 20,000. | IT | Garante | GDPR | €20,000 | ↗ |