BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Apr 2021 | Ordine degli Avvocati di RomaOrdine degli Avvocati di Roma was fined €2,000 by the Garante for a significant delay in responding to a data subject access request. The case highlights a failure to meet the required timelines for handling access requests under data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 25 Sept 2025 | La Prima SrlLa Prima Srl was fined EUR 10,000 by the Garante for sending unsolicited emails. The authority also found that the company failed to respond to a data deletion request, in breach of the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 02 Apr 2015 | Regione CalabriaRegione Calabria was fined EUR 80,000 by the Garante for failing to designate data processing officers and for only partially implementing IT security measures. The authority also noted a failure to respond to information requests, which required further investigation. | IT | Garante | GDPR | €80,000 | ↗ |
| 09 Mar 2023 | Consorzio Concessioni Reti Gas S.c.a.r.l.The Garante fined Consorzio Concessioni Reti Gas S.c.a.r.l. EUR 2,000 for GDPR breaches linked to the improper handling of email accounts and the failure to provide data processing information after an internship ended. The case highlights deficiencies in information duties and access control over personal data. | IT | Garante | GDPR | €2,000 | ↗ |
| 13 Apr 2023 | Azienda Ospedaliero Universitaria SeneseThe Garante fined Azienda Ospedaliero Universitaria Senese EUR 13,000 for violations related to the processing of personal data in the health sector. The case concerned data minimization and security measures. | IT | Garante | GDPR | €13,000 | ↗ |
| 14 Mar 2013 | Vinci s.r.l.Vinci s.r.l. was fined €6,000 by the Italian data protection authority, Garante. The case concerned the failure to provide the required privacy notice on the website contact form, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 29 Jan 2026 | Provincia della Congregazione dei Fratelli delle Suore CristianeThe entity was fined for failing to ensure sufficient transparency in data processing and for not carrying out a data protection impact assessment for workplace surveillance systems. The authority found breaches of the GDPR and the national privacy code. | IT | Garante | GDPR | €12,000 | ↗ |
| 22 May 2018 | Adolfo AllegriniAdolfo Allegrini, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 May 2021 | Agenzia di Tutela della Salute della Città metropolitana di MilanoAgenzia di Tutela della Salute della Città metropolitana di Milano was fined by the Garante 80,000 EUR for violations linked to data processing during an emergency. The authority found inadequate data protection measures and a failure to provide required information to data subjects. | IT | Garante | GDPR | €80,000 | ↗ |
| 27 Jun 2013 | New Company di Scattolin LorisNew Company di Scattolin Loris was fined EUR 6,400 by the Garante for making unsolicited promotional phone calls without proper consent. The conduct breached Articles 13 and 130 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,400 | ↗ |
| 23 Oct 2014 | Simply Gold s.r.l.Simply Gold s.r.l. was fined by the Garante for collecting personal data through a website form without providing the required information notice to data subjects. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 13 Apr 2023 | Azienda Ospedaliera Universitaria di CagliariAzienda Ospedaliera Universitaria di Cagliari was fined EUR 8,000 by the Garante for unlawfully publishing personal data related to a disciplinary procedure online. The authority found breaches of data minimization and transparency principles. | IT | Garante | GDPR | €8,000 | ↗ |
| 09 Oct 2014 | Comune di Lamezia TermeThe Municipality of Lamezia Terme was fined 4,000 EUR by the Garante. The authority found that personal data, including names, tax codes, and IBANs, had been published on its website without a legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Dec 2024 | Istituto Comprensivo Statale CalenzanoIstituto Comprensivo Statale Calenzano was fined EUR 1,000 by the Garante for breaching data protection principles. The case concerned the processing of personal data without meeting the requirements of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 21 Feb 2013 | Elettrodomestici Parise sncElettrodomestici Parise snc was fined 222,000 EUR by the Italian Garante. The company improperly registered numerous phone cards to unaware third parties and then sold them to phone centers, breaching data protection rules. | IT | Garante | GDPR | €222,000 | ↗ |
| 14 Sept 2023 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined 42,000 EUR by the Garante for failing to provide timely access to personal data requested by a parent under GDPR Article 15. The authority said the delay resulted from an operational error that prevented timely handling of the request. | IT | Garante | GDPR | €42,000 | ↗ |
| 20 Nov 2014 | Andrea Romualdo CerriAndrea Romualdo Cerri was fined €2,400 by the Garante. The violation concerned failing to provide the required information to data subjects when collecting personal data through a web form on the company website. | IT | Garante | GDPR | €2,400 | ↗ |
| 13 Sept 2017 | Serval s.r.l.Serval s.r.l. was fined by the Garante in the amount of €10,000 for failing to adopt minimum security measures. The authority also found that employees were not appointed as data processors, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Oct 2015 | Macellerie Rinaldo Giampaolo e figli sncMacellerie Rinaldo Giampaolo e figli snc was fined EUR 2,400 by the Garante. The authority found that the company failed to inform data subjects about the processing of personal data through a video surveillance system, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 17 Apr 2026 | Istituto “Ancelle della Compagnia della Regina dei Gigli”The Garante fined the school EUR 4,000 for processing students’ personal data without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |