BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Feb 2007 | Asl Vibo ValentiaThe health authority Asl Vibo Valentia was fined by Garante for improperly handling sensitive personal data, including genetic and biometric data, without proper authorization. The case concerns a breach of data protection rules and the legal basis required for processing such data. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Sept 2023 | Axpo Italia S.p.A.Axpo Italia S.p.A. was fined by the Garante 10,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the conclusion of unsolicited contracts for electricity and gas supply. | IT | Garante | GDPR | €10,000,000 | ↗ |
| 13 Jan 2022 | A.S.L. Napoli 1 CentroA.S.L. Napoli 1 Centro was fined EUR 6,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data in violation of lawfulness, fairness, transparency, and data minimization requirements. | IT | Garante | GDPR | €6,000 | ↗ |
| 16 Apr 2015 | avv. Pasquale GiordanoAvv. Pasquale Giordano was fined EUR 4,000 by the Italian data protection authority, Garante. The sanction concerned the disclosure of a client's personal data to the opposing party's lawyer in a divorce proceeding without the client's consent, in breach of Article 23 of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 26 Jul 2018 | MEVALUATE ITALIA S.R.L.MEVALUATE ITALIA S.R.L. was fined by the Garante 26,000 EUR for sending promotional emails without obtaining specific consent. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |
| 05 Sept 2013 | Leon d'oro Shi e Shi di Shi Deshao e C. S.n.cThe company was fined by the Garante 2,400 EUR for operating a video surveillance system without the required privacy notice. This breached the Italian Privacy Code because individuals under surveillance were not properly informed. | IT | Garante | GDPR | €2,400 | ↗ |
| 06 Jul 2023 | Ristorante Francesco s.r.l.Ristorante Francesco s.r.l. was fined by the Garante in the amount of 5,000 EUR for operating surveillance cameras without the required notices to affected individuals. The authority treated this as a breach of privacy rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 17 Jan 2008 | Aesculapius s.r.l.Aesculapius s.r.l. was fined by the Garante for missing the deadline to notify personal data processing activities. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Oct 2017 | Italprest di Luca Bosimini & C. s.a.s.Italprest di Luca Bosimini & C. s.a.s. was fined €10,000 by the Garante. The authority found that the company failed to implement minimum security measures, including the use of passwords shorter than eight characters, in breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Dec 2023 | MediafondMediafond was fined EUR 10,000 by the Garante for continuing to use a former employee’s email account after the employment ended. The company also forwarded emails without proper notice, which breached GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Jun 2018 | SECCHI Elettroservice S.r.l.SECCHI Elettroservice S.r.l. was fined by the Garante 8,000 EUR for failing to properly notify employees about the use of a geolocation system on company vehicles. The authority found a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 22 Jun 2017 | Adsalsa Italia Publicidad SucursalAdsalsa Italia Publicidad Sucursal was fined EUR 20,000 by the Garante. The authority found that personal data were processed without obtaining separate consent for each purpose, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Dec 2017 | SEMS – Servizi per la mobilità sostenibile S.r.l.SEMS – Servizi per la mobilità sostenibile S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to meet notification obligations linked to the installation of satellite tracking devices in its vehicle fleet, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Mar 2013 | Giant s.r.l.Giant s.r.l. was fined 114,000 EUR by the Garante for the unauthorized registration of numerous phone cards to third parties without their knowledge. The authority found this conduct to be in breach of data protection rules. | IT | Garante | GDPR | €114,000 | ↗ |
| 23 Jan 2014 | Valter Mancinelli BottoniValter Mancinelli Bottoni was fined 2,400 EUR by the Garante. The case concerned failure to provide the simplified information required by the data protection code when operating a video surveillance system at a non-profit association. | IT | Garante | GDPR | €2,400 | ↗ |
| 01 Dec 2022 | Regione LazioThe Garante fined Regione Lazio EUR 100,000 for unlawfully collecting metadata from employees' emails without a proper legal basis. The authority found that the processing did not meet the legal requirements for monitoring employee communications. | IT | Garante | GDPR | €100,000 | ↗ |
| 24 Mar 2022 | Azienda sanitaria provinciale di CaltanissettaAzienda sanitaria provinciale di Caltanissetta was fined for failing to update the Data Protection Officer’s contact details on its website and in communications with the Authority. The conduct breached GDPR Article 37. | IT | Garante | GDPR | €6,000 | ↗ |
| 25 Sept 2025 | Comune di PazzanoThe Garante imposed a fine of 3,960 EUR on Comune di Pazzano for failing to meet data protection obligations. The case concerned, among other issues, the improper provision of the Data Protection Officer’s contact details and other GDPR requirements. | IT | Garante | GDPR | €3,960 | ↗ |
| 27 Jan 2022 | T.S.M. s.r.l.T.S.M. s.r.l. was fined EUR 40,000 by the Italian supervisory authority, the Garante. The sanction concerned the failure to respond to information requests, which breached GDPR obligations related to data subject rights. | IT | Garante | GDPR | €40,000 | ↗ |
| 13 Feb 2007 | Asl n. 5 CrotoneAsl n. 5 Crotone was fined by the Garante for failing to notify the processing of sensitive personal data, including genetic and health data. The notification requirement was set out in the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |