BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Sept 2006 | Centro diagnostico Helios s.n.c.Centro diagnostico Helios s.n.c. was fined for failing to notify the processing of sensitive health data, including HIV status and other medical conditions. The authority treated this as a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Apr 2018 | Azienda Ospedaliera Sant’Andrea di RomaAzienda Ospedaliera Sant’Andrea di Roma was fined 32,000 EUR by the Garante for violations related to the processing of personal data in healthcare services. The case concerned deficiencies in consent handling and patient information forms. | IT | Garante | GDPR | €32,000 | ↗ |
| 07 May 2015 | V.V.S. s.r.l. Viaggi Vacanze Soggiorni StudioV.V.S. s.r.l. was fined by the Italian data protection authority, Garante, in the amount of €2,400. The case concerned the collection of personal data through website forms without providing the required privacy notice, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 10 Jun 2021 | Foodinho s.r.l.Foodinho s.r.l. was fined by the Garante EUR 2,600,000 for violations in the processing of riders’ personal data. The authority cited insufficient data minimization, inadequate privacy by design measures, and automated decision-making without proper human intervention. | IT | Garante | GDPR | €2,600,000 | ↗ |
| 26 Jul 2017 | Istituto scolastico "A. Mantegna"Istituto scolastico "A. Mantegna" was fined by the Garante for unlawfully publishing students’ personal data, including sensitive information, on its website without a legal basis. The case concerned a breach of lawfulness and data minimization requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 08 May 2013 | Business Services s.r.lBusiness Services s.r.l was fined EUR 6,400 by the Garante. The case concerned the sending of promotional faxes without the required information and without obtaining explicit consent from recipients. | IT | Garante | GDPR | €6,400 | ↗ |
| 14 Jan 2021 | Azienda Usl di BolognaAzienda Usl di Bologna was fined by the Garante 18,000 EUR for violations related to personal data protection in the healthcare sector. The case concerned irregularities in the processing of patient data, which breached data protection requirements. | IT | Garante | GDPR | €18,000 | ↗ |
| 23 Oct 2025 | Zephiromedia S.r.l.Zephiromedia S.r.l. was fined EUR 30,000 by the Garante for sending unsolicited promotional emails. The authority also found that recipients were not given an effective way to unsubscribe or exercise their rights. | IT | Garante | GDPR | €30,000 | ↗ |
| 01 Oct 2015 | Comune di Loiri Porto San PaoloThe Municipality of Comune di Loiri Porto San Paolo was fined by the Garante 10,000 EUR for publishing personal data on its website that revealed health status. The case involved unlawful disclosure of sensitive data in breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Jun 2018 | Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined by the Garante €20,000 for sharing access credentials among employees. The authority found this to be a breach of data protection rules and access control requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Feb 2024 | Ordine dei Medici Veterinari della Provincia di LatinaOrdine dei Medici Veterinari della Provincia di Latina was fined by the Garante 5,000 EUR for breaches of data protection principles. The case involved the unlawful communication of personal data to its members. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 Jan 2024 | Società David S.r.l.The Garante imposed an €8,000 fine on Società David S.r.l. for posting on Instagram a video of a patient undergoing a cosmetic procedure without a lawful basis. The authority found breaches of the GDPR principles of lawfulness, fairness, transparency, and purpose limitation. | IT | Garante | GDPR | €8,000 | ↗ |
| 05 Dec 2013 | Langella AlessandroLangella Alessandro was fined EUR 2,400 by the Garante. The case concerned the failure to provide the required privacy notice on www.orofirst.it, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 30 Nov 2017 | CAR SHARING TRENTINO Società CooperativaCAR SHARING TRENTINO Società Cooperativa was fined by the Garante 20,000 EUR. The authority found failures to comply with notification obligations related to vehicle geolocation, constituting a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 30 Jun 2022 | Federazione Italiana Sommelier, Albergatori e RistoratoriFederazione Italiana Sommelier, Albergatori e Ristoratori was fined by the Garante 5,000 EUR for unlawful processing of personal data. The breach involved the improper communication of one member’s data to all associates. | IT | Garante | GDPR | €5,000 | ↗ |
| 17 Mar 2016 | Apcoa Parking Italia spaApcoa Parking Italia spa was fined EUR 4,800 by the Garante for improper use of surveillance images to enforce parking rules and recover debts. The authority also found inadequate data protection information on the company’s website and in its communications with data subjects. | IT | Garante | GDPR | €4,800 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di PordenoneOrdine delle Professioni Infermieristiche di Pordenone was fined 6,000 EUR by the Garante for breaching data protection rules. The authority found that the organization mishandled a data subject request and failed to respect privacy rights. | IT | Garante | GDPR | €6,000 | ↗ |
| 29 Jan 2026 | Istituto tecnico industriale statale “Stanislao Cannizzaro” di CataniaIstituto tecnico industriale statale “Stanislao Cannizzaro” di Catania was fined by the Garante €10,000 for breaches of data protection principles. The authority found that personal data were processed in a manner that was not lawful, fair, or transparent. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Feb 2019 | Ordinanza ingiunzione - 14 febbraio 2019 [9106367]A doctor used the email addresses of former patients to send electoral propaganda without first informing them or obtaining consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 17 Dec 2015 | Zero srlZero srl was fined EUR 2,400 by the Garante for failing to provide the required privacy notice on its website. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |