BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 Jul 2020 | Merlini s.r.l.Merlini s.r.l. was fined 200,000 EUR by the Garante. The authority found that the collection of potential clients' personal data did not comply with GDPR consent requirements and that call-center activities were carried out outside the telemarketing procedures established by Wind Tre. | IT | Garante | GDPR | €200,000 | ↗ |
| 31 Aug 2023 | Robin S.r.l.The Garante fined Robin S.r.l. 25,000 EUR for publishing a photograph of minors with insufficient anonymization. The case concerns a breach of personal data protection rules applicable to children. | IT | Garante | GDPR | €25,000 | ↗ |
| 12 Feb 2015 | Enel Energia S.p.a.Enel Energia S.p.a. was fined by the Garante 200,000 EUR for failing to provide information and obtain consent for processing personal data for promotional purposes. The breach affected a large database of approximately 43.1 million contacts. | IT | Garante | GDPR | €200,000 | ↗ |
| 02 Dec 2021 | Azienda USL di ParmaAzienda USL di Parma was fined by the Garante for a data breach involving the unauthorized disclosure of health data. The incident affected one individual and did not result in significant harm, but it was still treated as a GDPR violation. | IT | Garante | GDPR | €5,000 | ↗ |
| 15 Dec 2022 | Comune di VicchioComune di Vicchio was fined by the Garante 8,000 EUR for using fingerprints to monitor employee attendance without appropriate legal basis and safeguards. The authority found that the biometric processing breached GDPR requirements. | IT | Garante | GDPR | €8,000 | ↗ |
| 26 Oct 2023 | Azienda Sanitaria Locale TO3Azienda Sanitaria Locale TO3 was fined by the Garante for a health data breach affecting four individuals. The incident lasted nine days and was deemed negligent. | IT | Garante | GDPR | €6,000 | ↗ |
| 12 Dec 2024 | Comune di PorticiThe Garante fined Comune di Portici EUR 6,000 for breaches of data protection principles, including lawfulness, fairness, and transparency. The authority also found that the municipality failed to carry out a data protection impact assessment before processing personal data through video surveillance. | IT | Garante | GDPR | €6,000 | ↗ |
| 23 May 2024 | Associazione Medica Chirone s.c.r.l.The Garante fined Associazione Medica Chirone s.c.r.l. 5,000 EUR for improperly accessing and using an employee's vaccination status data. The authority found that the data were not properly anonymized, resulting in a breach of data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 20 Jun 2024 | TS Food Processing S.r.l.TS Food Processing S.r.l. was fined by the Garante for refusing an employee's request to access personal data related to employment. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Mar 2025 | Casatua S.r.l.Casatua S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited communications via WhatsApp without obtaining proper recipient consent. The company also failed to implement adequate procedures to ensure compliance with data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jun 2013 | Comune di PadovaComune di Padova was fined by the Garante 10,000 EUR for unlawfully publishing personal data online beyond the legally permitted period. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Jun 2025 | Comune di RoccaforzataComune di Roccaforzata was fined EUR 8,000 by the Garante for publishing sensitive health data, including an employee’s disability percentage, in a council resolution. The authority found a breach of the GDPR and national privacy code provisions. | IT | Garante | GDPR | €8,000 | ↗ |
| 22 May 2014 | Colligo s.r.lColligo s.r.l was fined EUR 40,000 by the Garante for making promotional phone calls while disguising or hiding the caller's identity. The authority found this conduct breached the Italian Data Protection Code. | IT | Garante | GDPR | €40,000 | ↗ |
| 13 Apr 2023 | Comune di Cogollo del CengioThe Garante fined Comune di Cogollo del Cengio EUR 3,000 for breaches of GDPR Articles 5, 6 and 9, as well as Articles 2-ter and 2-septies of the Italian Privacy Code. The case concerned the processing of an employee’s personal data without an adequate legal basis and in breach of data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 14 Sept 2006 | Pasquadibisceglie PaoloPasquadibisceglie Paolo was fined by the Garante 3,000 EUR for failing to provide adequate information to individuals recorded by a video surveillance system in a commercial establishment. The authority found a breach of privacy rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 21 Oct 2010 | Palmeto s.r.l.Palmeto s.r.l. was fined EUR 12,000 by the Italian supervisory authority, Garante. The case concerned failure to provide the required data protection information to individuals in connection with video surveillance and personal data collection via the company website. | IT | Garante | GDPR | €12,000 | ↗ |
| 11 Apr 2024 | GS S.p.A.GS S.p.A. was fined by the Garante for failing to respond to an employee's access request. The request concerned disciplinary records and work time stamps, which constitutes a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Dec 2022 | Comune di BorgiaComune di Borgia was fined by the Garante 5,000 EUR for processing employees’ biometric data for attendance tracking without appropriate legislative measures and specific safeguards. The authority found this to be a breach of GDPR rules on special-category data. | IT | Garante | GDPR | €5,000 | ↗ |
| 15 Sept 2022 | Comune di ThieneComune di Thiene was fined EUR 3,000 by the Garante for violating data protection principles. The authority found that personal data related to a disciplinary dismissal case was improperly disclosed online. | IT | Garante | GDPR | €3,000 | ↗ |
| 21 Jul 2016 | Comune di CanicattìComune di Canicattì was fined for publishing personal data, including health information, on its website. The authority found that this breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |