BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Feb 2011 | Federconsorzi Dolomiti SuperskiFederconsorzi Dolomiti Superski was fined EUR 12,000 by the Italian Garante. The authority found that the company failed to provide the required data protection information to individuals, in breach of Articles 13 and 161 of the Italian Data Protection Code. | IT | Garante | GDPR | €12,000 | ↗ |
| 28 Jul 2016 | Jurica PavicJurica Pavic was fined by the Garante for failing to provide adequate information to data subjects about video surveillance. The authority found this to be a breach of privacy regulations. | IT | Garante | GDPR | €2,400 | ↗ |
| 11 Sept 2025 | Casa di Cura Città di RomaCasa di Cura Città di Roma was fined EUR 12,000 by the Garante for allowing unauthorized access to patient medical records. The case concerns a breach of data protection rules and indicates a need for stronger access controls. | IT | Garante | GDPR | €12,000 | ↗ |
| 06 Jul 2006 | Comune di AugustaThe Municipality of Augusta was fined by the Garante for failing to make a required notification under data protection law. The breach concerned Article 163 of the Codice Privacy. | IT | Garante | GDPR | €5,164 | ↗ |
| 18 Dec 2013 | Comune di MonticianoThe Municipality of Monticiano was fined 8,000 EUR by the Garante. The authority found a privacy violation after the municipality failed to provide requested information about the publication of personal data on its institutional website. | IT | Garante | GDPR | €8,000 | ↗ |
| 23 Oct 2025 | Provvedimento del 23 ottobre 2025 [10210718]The Garante imposed a EUR 10,000 fine on an individual tobacco shop owner for suspicious financial transactions involving the misuse of a third party’s identification data with a prepaid card. The case concerns unauthorized use of personal data in the context of payment operations. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Apr 2023 | Retimedia S.r.l.Retimedia S.r.l. was fined 2,500 EUR by the Garante for publishing detailed health data of an individual without consent. The conduct breached GDPR Article 9 on special categories of personal data. | IT | Garante | GDPR | €2,500 | ↗ |
| 03 May 2018 | Omis s.p.a.Omis s.p.a. was fined by the Garante 8,000 EUR for failing to notify the processing of geolocation data from vehicles. This notification was required under privacy regulations. | IT | Garante | GDPR | €8,000 | ↗ |
| 18 Nov 2015 | Zsa Zsa srlZsa Zsa srl was fined EUR 2,400 by the Italian Garante. The violation concerned the failure to provide the required privacy notice on the website’s data collection form, in breach of the Italian data protection code. | IT | Garante | GDPR | €2,400 | ↗ |
| 15 Jun 2011 | Azienda Multiservizi e Igiene Urbana S.p.A.Azienda Multiservizi e Igiene Urbana S.p.A. was fined for collecting personal data through a web form without providing users with the required privacy notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 30 Oct 2013 | Compagnia Assicuratrice Linear s.p.a.Compagnia Assicuratrice Linear s.p.a. was fined by the Garante 80,000 EUR for collecting personal data without specific consent for purposes beyond registration services. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €80,000 | ↗ |
| 27 Jan 2022 | Azienda socio sanitaria territoriale Nord di MilanoAzienda socio sanitaria territoriale Nord di Milano was fined by the Garante 20,000 EUR for failing to implement adequate security measures to protect personal data. The authority found a breach of GDPR provisions on data protection and security. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Dec 2024 | BDM Banca S.p.A.BDM Banca S.p.A. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The sanction concerned the failure to provide a timely response to a data subject’s access request, which constitutes a breach of GDPR Article 15. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 May 2018 | Wind Tre s.p.a.Wind Tre s.p.a. was fined by the Garante EUR 600,000 for conducting marketing campaigns without obtaining the required user consent. The conduct breached data protection rules. | IT | Garante | GDPR | €600,000 | ↗ |
| 13 Jun 2013 | Vito GiacoiaVito Giacoia was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned the failure to provide the required privacy notice for a video surveillance system at the “Fratelli Venaria” club, in breach of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 13 May 2015 | Barbirato Danilo s.a.s. di Barbirato Marco e c.Barbirato Danilo s.a.s. was fined by the Garante 16,800 EUR for failing to provide the required privacy notice on its data collection form. The authority also found breaches of CCTV rules, including inadequate signage and excessive retention of recorded images. | IT | Garante | GDPR | €16,800 | ↗ |
| 05 Feb 2015 | Comune di San Giuseppe JatoComune di San Giuseppe Jato was fined by the Garante for unlawfully publishing sensitive personal data revealing health status on its website. The conduct breached privacy rules governing the processing and disclosure of sensitive data. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Sept 2013 | Maria Vita PezzellaMaria Vita Pezzella was fined EUR 6,000 by Garante for failing to provide the required privacy notice in a video surveillance system. The case concerned a breach of the Italian Privacy Code and the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €6,000 | ↗ |
| 12 Sept 2013 | Azienda USL ViterboAzienda USL Viterbo was fined for failing to implement minimum security measures and for not appointing data processing officers. The authority also noted that the security program document was not updated between 2006 and 2010. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jul 2022 | Azienda Socio Sanitaria Territoriale RhodenseAzienda Socio Sanitaria Territoriale Rhodense was fined by the Garante EUR 3,000 for violations of data protection rules. The case concerned data breaches and inadequate security measures. | IT | Garante | GDPR | €3,000 | ↗ |