BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Sept 2007 | Azienda sanitaria locale Avellino 1Azienda sanitaria locale Avellino 1 was fined by the Garante in the amount of 10,000 EUR. The authority found that the entity failed to notify the processing of sensitive personal data, including genetic and biometric data, as required by the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Dec 2010 | Bitmovers s.r.l.Bitmovers s.r.l. was fined by the Garante 6,000 EUR for collecting personal data through its website without the required information notice. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 23 Mar 2023 | Ministero dell’InternoMinistero dell’Interno was fined EUR 4,000 by the Garante for unlawfully communicating personal data, including health information, to the police without proper justification. The case concerned a breach of lawfulness and purpose limitation requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Dec 2021 | Università Telematica Internazionale UninettunoUniversità Telematica Internazionale Uninettuno was fined EUR 1,000 by the Italian supervisory authority Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €1,000 | ↗ |
| 13 Mar 2014 | Paolo ZaniniPaolo Zanini was fined EUR 4,000 by the Garante for sending unsolicited promotional faxes. The conduct breached data protection rules and the requirement for prior consent for marketing communications. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Feb 2020 | Azienda Unità Sanitaria Locale Toscana CentroAzienda Unità Sanitaria Locale Toscana Centro was fined by the Garante 10,000 EUR for violations related to data processing in the health sector. The case concerned the handling of patient data without full compliance with GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Apr 2017 | Hotel Savoia Genova s.r.l.Hotel Savoia Genova s.r.l. was fined €16,800 by the Garante. The authority found that the company failed to provide the required information to individuals about its video surveillance system and kept surveillance footage longer than permitted. | IT | Garante | GDPR | €16,800 | ↗ |
| 10 Jul 2025 | Centro Medico Italiano S.r.l.Centro Medico Italiano S.r.l. was fined by the Garante 30,000 EUR for failing to provide an adequate response to a data subject’s request for access to health data and information about its processing. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €30,000 | ↗ |
| 13 Nov 2024 | Comune di UgentoThe Garante fined Comune di Ugento 2,400 EUR for publishing data on its website that could reveal individuals' health status. The case involved the improper disclosure of sensitive information in a public online setting. | IT | Garante | GDPR | €2,400 | ↗ |
| 03 Jun 2010 | ICTS Italia s.r.l.ICTS Italia s.r.l. was fined by the Garante for using a biometric system for employee access control and attendance without adequate notice, consent, or minimum security measures. The company also failed to notify the Garante. | IT | Garante | GDPR | €18,400 | ↗ |
| 12 May 2022 | Comune di VillabateComune di Villabate was fined 6,000 EUR for failing to update the Data Protection Officer’s contact details on its website and in communications with the Authority. The conduct was found to breach the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €6,000 | ↗ |
| 06 Jun 2024 | Azienda Usl RomagnaThe Garante fined Azienda Usl Romagna EUR 24,000 for data protection violations related to the management of health data. The case concerned irregularities in the processing of sensitive data, which requires heightened safeguards and GDPR compliance. | IT | Garante | GDPR | €24,000 | ↗ |
| 14 May 2026 | Comune di VentassoComune di Ventasso was fined EUR 8,000 by the Garante. The authority found breaches of the principles of lawful, fair and transparent processing of personal data, as well as data minimization. | IT | Garante | GDPR | €8,000 | ↗ |
| 15 Jun 2017 | F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante in the amount of 10,000 EUR for making unsolicited promotional calls to a number listed in the public opposition registry. The conduct breached data protection rules and the right to object to direct marketing. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2025 | Verisure Italy s.r.l.Verisure Italy s.r.l. was fined by the Garante EUR 400,000 for breaches of data retention and information obligations in connection with marketing activities. The case concerned customer and former customer data processed without proper consent and notice. | IT | Garante | GDPR | €400,000 | ↗ |
| 11 Sept 2025 | Comune di NichelinoComune di Nichelino was fined EUR 18,000 by the Garante for failing to provide an adequate response to a data subject's request to exercise their rights. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €18,000 | ↗ |
| 16 Nov 2023 | Provvedimento del 16 novembre 2023 [9960948]The Garante imposed an EUR 18,000 fine on a training company for the unauthorized online publication of personal data relating to health. The case concerned breaches of GDPR Articles 5 and 32 on data processing principles and security. | IT | Garante | GDPR | €18,000 | ↗ |
| 29 Jan 2015 | Azienda Ospedaliera Universitaria Policlinico Sant'Orsola-MalpighiAzienda Ospedaliera Universitaria Policlinico Sant'Orsola-Malpighi was fined EUR 2,400 by the Garante. The authority found that personal data collected through the website’s “contact us” form was processed without the required privacy notice, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale n. 6 di CirièASL Ciriè was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The breach concerned obligations under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Feb 2017 | Lucini & Lucini Communication LtdLucini & Lucini Communication Ltd was fined EUR 72,000 by the Garante. The authority found that the company collected personal data through its websites and sent promotional emails without proper consent. | IT | Garante | GDPR | €72,000 | ↗ |