BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Apr 2026 | Azienda USL ModenaAzienda USL Modena was fined by the Garante in the amount of 10,000 EUR for a data breach caused by a ransomware attack. The authority found a breach of GDPR data security obligations. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Dec 2014 | Enrico TecchioThe Garante fined Enrico Tecchio EUR 2,400 for failing to provide data subjects with information about the processing of personal data through a video surveillance system at a dental practice. The case concerned the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €2,400 | ↗ |
| 06 Jul 2023 | Regione SicilianaThe Garante fined Regione Siciliana EUR 7,000 for publishing personal data of numerous individuals, including sensitive employment-related information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €7,000 | ↗ |
| 23 Jun 2025 | Ordine delle Professioni Infermieristiche di ViterboThe Garante imposed a fine of EUR 10,000 on the Ordine delle Professioni Infermieristiche di Viterbo for breaches of data protection rules. The case concerned non-compliance with requirements governing the processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 03 Mar 2016 | Comune di Ischia di CastroThe Municipality of Comune di Ischia di Castro was fined 4,000 EUR by the Garante for unlawfully publishing personal data of jury members on its online notice board for longer than the legally permitted period. The case concerned a breach of data protection rules and retention limits. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jun 2017 | Bookingshow s.p.a.Bookingshow s.p.a. was fined EUR 62,000 by the Garante for unlawfully processing personal data. The company required mandatory consent for promotional purposes during online ticket purchases, which breached data processing rules. | IT | Garante | GDPR | €62,000 | ↗ |
| 08 Feb 2024 | Medtronic Italia S.p.a.Medtronic Italia S.p.a. was fined by the Garante in the amount of €300,000 for a data protection breach. The authority found inadequate technical and organizational measures that led to unauthorized disclosure of data. | IT | Garante | GDPR | €300,000 | ↗ |
| 10 Apr 2025 | Stefanelli FedericaThe Garante imposed a 45,000 EUR fine on Stefanelli Federica for processing personal data without proper consent in unauthorized call-center operations. The case also involved sensitive data, including payment method information, which could have led to unauthorized contract activations. | IT | Garante | GDPR | €45,000 | ↗ |
| 16 Jan 2026 | Associazione Turistica Pro Loco di CittarealeThe association unlawfully disclosed the personal data of 23 members by publishing it in a public notice and online. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €600 | ↗ |
| 06 Feb 2014 | Oreiade s.r.l.Oreiade s.r.l. was fined by the Garante for installing a video surveillance system at Hotel Blu Inn without adequate safeguards. The authority found a breach of data protection rules. | IT | Garante | GDPR | €24,400 | ↗ |
| 09 Jan 2014 | Giallooro s.r.lGiallooro s.r.l was fined EUR 2,400 by the Garante for collecting personal data through a website contact form without providing the required privacy notice. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 03 May 2018 | Pace MarinaPace Marina, a general practitioner, was fined by the Garante for failing to implement minimum security measures to protect patients’ personal and sensitive data. This failure allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Apr 2025 | Regione Emilia RomagnaThe Garante fined Regione Emilia Romagna EUR 15,000 for violations related to the processing of personal data for official statistical purposes. The authority found incorrect application of data protection principles and measures. | IT | Garante | GDPR | €15,000 | ↗ |
| 17 Apr 2026 | Provvedimento del 17 aprile 2026 [10254325]The supervisory authority found that a video surveillance system with 25 cameras operated without the required informational signage. The breach concerned GDPR information obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 31 Jan 2019 | Azienda Sanitaria Locale di AlessandriaAzienda Sanitaria Locale di Alessandria was fined by the Garante 16,000 EUR for processing personal data through the health dossier without full compliance with data protection rules. The case concerned improper handling of sensitive data in a medical system. | IT | Garante | GDPR | €16,000 | ↗ |
| 09 Mar 2023 | Aesse S.r.l.s.Aesse S.r.l.s. was fined by the Italian Garante in the amount of €3,000. The case concerned unsolicited telemarketing calls made without consent and insufficient information provided about the source of personal data. | IT | Garante | GDPR | €3,000 | ↗ |
| 16 Sept 2021 | Istituto Comprensivo - IC Cosenza III “V. Negroni”Istituto Comprensivo - IC Cosenza III “V. Negroni” was fined by the Garante 2,000 EUR for unlawful processing of personal data and inadequate data protection. The authority also noted that personal data were made accessible online, increasing the risk to affected individuals. | IT | Garante | GDPR | €2,000 | ↗ |
| 18 Apr 2018 | Marigliano GianpaoloMarigliano Gianpaolo was fined by the Garante 50,000 EUR for unlawfully using personal data to activate 15 phone cards without the consent of the individuals concerned. The case indicates a breach of lawful processing requirements and consent rules. | IT | Garante | GDPR | €50,000 | ↗ |
| 16 Feb 2017 | Momax s.r.l.Momax s.r.l. was fined by the Garante for improper handling of telephone traffic data. The authority found failures to implement appropriate safeguards, including strong authentication and biometric recognition measures, and retention of data beyond the permitted period for billing and crime prevention purposes. | IT | Garante | GDPR | €60,000 | ↗ |
| 17 Jul 2025 | Associazione Il Cavallo Rosa/ChangeTheGame ODVThe Garante fined Associazione Il Cavallo Rosa/ChangeTheGame ODV 10,000 EUR for publishing a minor’s personal data on its Facebook page without anonymization. The authority found a breach of the data subject’s rights under the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |