BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Sept 2012 | Casa di cura privata Montevergine s.p.a.The private clinic Montevergine was fined 50,000 EUR by the Garante. The authority found that it processed employees' biometric data for attendance tracking without first notifying the supervisory authority. | IT | Garante | GDPR | €50,000 | ↗ |
| 21 Jan 2010 | Casa di cura privata Di Lorenzo s.p.a.The private clinic Casa di cura privata Di Lorenzo s.p.a. was fined by the Garante for breaching data protection rules. The authority found that it failed to comply with notification obligations under the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Mar 2013 | Casa di cura Parco dei Tigli S.a.s. di Alessandro Borgherini & Co.The Garante fined Casa di cura Parco dei Tigli S.a.s. 2,400 EUR for providing inadequate data protection information on its website. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 11 Apr 2013 | Casa di cura La Quiete srlCasa di cura La Quiete srl was fined by the Garante for failing to notify data processing activities related to patients’ laboratory tests. The data could reveal infectious diseases, which required notification under the Italian data protection code. | IT | Garante | GDPR | €40,000 | ↗ |
| 02 Dec 2021 | Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.The Garante imposed a EUR 30,000 fine on Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting patient health data. | IT | Garante | GDPR | €30,000 | ↗ |
| 11 Oct 2012 | Casa di cura Eretenia S.p.a.The Garante fined Casa di cura Eretenia S.p.a. €30,000 for failing to provide proper data protection notices in its video surveillance system. The authority found a breach of privacy rules and the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €30,000 | ↗ |
| 11 Sept 2025 | Casa di Cura Città di RomaCasa di Cura Città di Roma was fined EUR 12,000 by the Garante for allowing unauthorized access to patient medical records. The case concerns a breach of data protection rules and indicates a need for stronger access controls. | IT | Garante | GDPR | €12,000 | ↗ |
| 24 Jan 2013 | Casa di cura Abano TermeCasa di cura Abano Terme was fined EUR 60,000 by the Garante for processing personal data without complying with the legal requirements and limits. The authority found a breach of Article 26 of the Italian Privacy Code. | IT | Garante | GDPR | €60,000 | ↗ |
| 15 Feb 2018 | Casa della legalità e della cultura onlusCasa della legalità e della cultura onlus was fined EUR 20,000 by the Garante. The authority found a data protection breach because the organization failed to respond to requests for information about the publication of personal data on its websites. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Apr 2023 | CARTONAJES BAÑERES, S.A.CARTONAJES BAÑERES, S.A. was fined by the AEPD 220,000 EUR for processing biometric data without the required data protection impact assessment. The authority also found a failure to comply with data subjects’ access rights. | ES | AEPD | GDPR | €220,000 | ↗ |
| 08 Apr 2022 | CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined EUR 1,000 by the AEPD for sending a commercial SMS to an individual who had already exercised the right to erasure. The authority found this conduct to be a breach of data protection rules. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 05 Jan 2022 | CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined by the AEPD in the amount of EUR 5,000 for sending commercial SMS messages without the recipient’s consent. The conduct breached Article 21 of the LSSI, which governs unsolicited electronic marketing. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 15 Oct 2024 | CARSO TRADING, S.L.CARSO TRADING, S.L. was fined by the AEPD in the amount of EUR 6,000 for failing to respond to a data access request. The authority found a breach of Article 15 of the GDPR and Article 58.2 of the GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 01 Jan 2023 | CARSO TRADING, S.L.CARSO TRADING, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails. The company also failed to respond to a data access request, which constitutes a breach of Article 15 GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 04 Dec 2023 | CARSO TRADING, S.L.CARSO TRADING, S.L. was fined by the AEPD for sending unsolicited commercial emails without prior consent from recipients. The company also failed to respond to a request to stop such communications, which constitutes a breach of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 30 Nov 2017 | CAR SHARING TRENTINO Società CooperativaCAR SHARING TRENTINO Società Cooperativa was fined by the Garante 20,000 EUR. The authority found failures to comply with notification obligations related to vehicle geolocation, constituting a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 24 Nov 2022 | CARROZADOS TECAI, S.L.CARROZADOS TECAI, S.L. was fined by the AEPD EUR 300 for installing a surveillance camera that could capture public areas without proper authorization. The authority also found inadequate informational signage for affected individuals, in breach of Article 13 GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 08 Mar 2018 | Carriere Italia s.r.l.Carriere Italia s.r.l. was fined for processing personal data revealing health status without notifying the Garante. The authority also found that required information was not provided to data subjects in job advertisements. | IT | Garante | GDPR | €10,400 | ↗ |
| 20 Jun 2023 | CARRETERAS Y ASFALTOS, S.L.The company installed surveillance cameras that recorded both image and audio without proper signage or informing employees. This breached data protection requirements. | ES | AEPD | GDPR | €3,000 | ↗ |
| 17 Apr 2026 | Carlo Maria Antonio ParisiThe Garante fined Carlo Maria Antonio Parisi, owner of the online newspaper “giornalistitalia.it”, EUR 2,500. The authority found inadequate technical and organizational measures to support data subject rights and delays in handling requests without undue delay. | IT | Garante | GDPR | €2,500 | ↗ |