BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Feb 2020 | Comune di Urago d'OglioComune di Urago d'Oglio was fined EUR 4,000 by the Garante for improper processing and online publication of special-category personal data, including health data. The authority found insufficient legal basis and inadequate transparency toward the data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Nov 2023 | Provvedimento del 16 novembre 2023 [9973749]An attorney was fined for unlawfully processing personal data by sending sensitive judicial documents via certified email. The authority found that the method of transmission breached data protection rules. | IT | Garante | GDPR | €500 | ↗ |
| 16 Apr 2015 | Media Lab Italia s.r.l.Media Lab Italia s.r.l. was fined by the Garante EUR 10,000 for processing personal data through a website form without obtaining separate consent for different purposes. The purposes included promotional communications and market research. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Apr 2025 | Tirrenia Hospital S.r.l.Tirrenia Hospital S.r.l. was fined by the Garante EUR 2,000 for breaching the data processing principles set out in GDPR Article 5. The case concerned processing in the healthcare sector, where a particularly high level of compliance is required. | IT | Garante | GDPR | €2,000 | ↗ |
| 14 Jan 2021 | Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined by the Garante €30,000 for unlawfully processing employees’ biometric data to monitor attendance. The conduct breached GDPR requirements on lawful processing and data minimisation. | IT | Garante | GDPR | €30,000 | ↗ |
| 06 Jul 2006 | Ced di Demartis CarloThe sole proprietorship Ced di Demartis Carlo was fined by the Garante for failing to notify the processing of personal data. This constituted a breach of Article 7 of Law 675/1996. | IT | Garante | GDPR | €5,164 | ↗ |
| 26 May 2011 | Eredi Trossello dei Fratelli Trossello C.A.R. s.n.c.The company was fined EUR 10,000 by the Garante for operating a video surveillance system without the required privacy notice. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 May 2015 | Comune di BagnoregioComune di Bagnoregio was fined by the Garante for unlawfully publishing personal data on its website. The conduct breached the conditions set out in the Italian data protection code. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Jun 2021 | Soluzione Tasse S.p.A.Soluzione Tasse S.p.A. was fined by the Garante 30,000 EUR for sending unsolicited emails without proper consent. The case concerned GDPR principles on data processing and transparency. | IT | Garante | GDPR | €30,000 | ↗ |
| 12 Dec 2024 | Comune di Corte FrancaComune di Corte Franca was fined EUR 6,000 for publishing personal data online without a proper legal basis. The authority found breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 27 Nov 2024 | Molise dati S.p.A.Molise dati S.p.A. was fined EUR 10,000 by the Garante for a data breach involving the regional health portal. A system vulnerability allowed unauthorized access to personal data of citizens in the Molise Regional Registry. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Oct 2017 | Roma Gestioni s.r.l.Roma Gestioni s.r.l. was fined EUR 30,000 by the Garante. The authority found that the company retained surveillance footage longer than permitted under privacy rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 20 Nov 2008 | G.F.A. marketing di Cavezzali PatriziaG.F.A. marketing di Cavezzali Patrizia was fined EUR 3,000 by the Italian Garante for failing to provide the required data protection notice to recipients of promotional faxes. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 11 Dec 2014 | Comune di NapoliComune di Napoli was fined 10,000 EUR by the Garante for publishing substitute teachers’ personal information, including health-related data, on its institutional website. The authority found that this disclosure breached privacy rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Feb 2017 | Marc 1 s.r.l.Marc 1 s.r.l. was fined €850,000 by the Garante for transferring money to China using techniques designed to avoid anti-money laundering rules. The authority also found that the actual senders had not given consent for the processing of their personal data. | IT | Garante | GDPR | €850,000 | ↗ |
| 26 Jul 2017 | Cloud Europa s.r.l.Cloud Europa s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unsolicited promotional phone calls, in breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 27 Oct 2016 | Coledan EmanuelaColedan Emanuela was fined EUR 2,400 by the Garante for failing to inform data subjects about the processing of personal data through a video surveillance system at a private club. The case concerns a breach of transparency and information obligations toward individuals under surveillance. | IT | Garante | GDPR | €2,400 | ↗ |
| 01 Feb 2018 | Iqbal QuasimIqbal Quasim was fined EUR 30,000 by the Garante. The case concerned registering phone SIM cards to third parties without their consent, which breached data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 17 Apr 2026 | Associazione Movimento Cinque Stelle SiciliaThe Garante fined Associazione Movimento Cinque Stelle Sicilia 5,000 EUR for failing to adopt adequate technical and organizational measures to facilitate the exercise of data protection rights. The authority also found that requests were not addressed without undue delay. | IT | Garante | GDPR | €5,000 | ↗ |
| 04 Jun 2025 | Noi Compriamo Auto.it S.r.l.The Italian Supervisory Authority fined Noi Compriamo Auto.it S.r.l. 45,000 EUR for sending unsolicited promotional emails without proper consent documentation. The case indicates a breach of GDPR requirements for lawful direct marketing. | IT | Garante | GDPR | €45,000 | ↗ |