BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Oct 2024 | la SocietàThe company was fined EUR 7,000 by the Garante for violations related to security measures in handling online medical reports and data. The case concerned insufficient safeguards for processed medical information. | IT | Garante | GDPR | €7,000 | ↗ |
| 09 Nov 2017 | GSG Enterprise società cooperativa edileGSG Enterprise was fined EUR 96,000 by the Garante for using the personal data of car owners to demand payment for services that were neither performed nor requested. The case concerns unlawful processing of personal data for debt-collection style demands. | IT | Garante | GDPR | €96,000 | ↗ |
| 23 Oct 2025 | Geturhotels SrlGeturhotels Srl was fined EUR 6,000 by the Garante for sending unsolicited SMS messages to a complainant despite their objection. The authority found that the company’s conduct breached GDPR rules on processing personal data for promotional purposes. | IT | Garante | GDPR | €6,000 | ↗ |
| 11 Feb 2021 | Liceo Pepe CalamoLiceo Pepe Calamo was fined EUR 5,000 by the Garante for publishing teachers' personal data in public rankings on its institutional website. The authority found a breach of data minimization and transparency principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 26 Mar 2010 | Lenzi automobili s.p.a.Lenzi automobili s.p.a. was fined by the Garante for using a biometric system to verify employee attendance without the required authorization. This constituted a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2014 | Eismann s.r.l.Eismann s.r.l. was fined by the Garante 40,000 EUR for making promotional phone calls without prior express consent from recipients. The company also concealed the caller's identity, which breached Italian data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Nov 2015 | Pasticceria Gelateria Bar D.D. & D. di Davide Busato & C. s.n.c.The company was fined by the Garante 2,400 EUR for operating a video surveillance system without providing the simplified information notice required under data protection law. The breach concerned the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Apr 2011 | Mansutti S.p.A.Mansutti S.p.A. was fined EUR 12,000 by the Garante for failing to provide the required data protection notice on its website forms. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €12,000 | ↗ |
| 17 Apr 2014 | Comune di CavedineThe Municipality of Cavedine was fined by the Garante 4,000 EUR for publishing personal data online longer than legally permitted. The case concerned a breach of data protection rules and limits on online retention. | IT | Garante | GDPR | €4,000 | ↗ |
| 20 Oct 2022 | Associazione Covid-Healer ODVThe Garante fined Associazione Covid-Healer ODV 500 EUR for breaches linked to the processing of health data through its app, which was active for a short period. The authority cited inadequate transparency and deficiencies in the data protection impact assessment. | IT | Garante | GDPR | €500 | ↗ |
| 28 Mar 2023 | Sky Italia S.r.l.The Italian Data Protection Authority fined Sky Italia S.r.l. EUR 842,062 for violations related to telemarketing and commercial communications. The company failed to properly verify consent, relied on outdated consents, and did not check the Public Register of Oppositions before campaigns. | IT | Garante per la protezione dei dati personali | GDPR | €842,000 | ↗ |
| 10 Apr 2025 | Comune di Ponte nelle AlpiThe Garante fined Comune di Ponte nelle Alpi 4,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Codice. The case concerned improper personal data processing activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 Mar 2023 | Deca s.r.l.Deca s.r.l. was fined EUR 1,600 by the Garante. The authority found that the company failed to respond to requests for access to personal data relating to work attendance and unlawfully processed data through an incomplete video surveillance system. | IT | Garante | GDPR | €1,600 | ↗ |
| 18 Oct 2012 | Fastweb S.p.A.Fastweb S.p.A. was fined by the Garante in the amount of EUR 300,000 for violations related to unsolicited telemarketing calls and improper data processing. The case indicates deficiencies in marketing compliance and personal data protection controls. | IT | Garante | GDPR | €300,000 | ↗ |
| 15 Feb 2018 | Genova Car Sharing SrlGenova Car Sharing Srl was fined EUR 46,000 by the Garante. The authority found that customers were not fully informed about vehicle geolocation and that separate consent was not obtained for newsletter communications. | IT | Garante | GDPR | €46,000 | ↗ |
| 27 Apr 2016 | Luziotti Auto s.r.l.Luziotti Auto s.r.l. was fined by the Garante 2,400 EUR for collecting personal data through its website without providing users with the required information notice. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 13 Sept 2017 | Jump 3000 s.r.l.Jump 3000 s.r.l. was fined by the Garante 14,800 EUR for providing clients with inadequate data protection information. The authority found that the privacy notices did not properly identify the data controller. | IT | Garante | GDPR | €14,800 | ↗ |
| 14 May 2026 | Azienda ospedaliera dei colli Monaldi-Cotugno-CTO di NapoliAzienda ospedaliera dei colli Monaldi-Cotugno-CTO di Napoli was fined EUR 15,000 by the Garante. The authority found that the entity provided false statements and interrupted the performance of its tasks. The case concerns breaches of data protection rules. | IT | Garante | GDPR | €15,000 | ↗ |
| 17 Dec 2020 | Ordine degli Assistenti Sociali della Regione LazioOrdine degli Assistenti Sociali della Regione Lazio was fined EUR 2,000 by the Garante. The authority found that the entity failed to respond to a request for access to personal data, which is a breach of GDPR Article 15. | IT | Garante | GDPR | €2,000 | ↗ |
| 26 May 2022 | Azienda sanitaria universitaria Friuli OccidentaleAzienda sanitaria universitaria Friuli Occidentale was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the electronic health dossier. The authority found non-compliance with GDPR requirements. | IT | Garante | GDPR | €5,000 | ↗ |