BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Apr 2015 | Midolo MichelaMidolo Michela was fined EUR 15,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €15,000 | ↗ |
| 09 Oct 2025 | FT Solutions S.r.l.FT Solutions S.r.l. was fined by the Garante 5,000 EUR for processing personal data for marketing purposes without proper consent. The case involved more than 2 million records and resulted in unauthorized telemarketing activities. | IT | Garante | GDPR | €5,000 | ↗ |
| 21 Dec 2023 | Impresa individuale Macelleria Salumeria HalalThe Garante fined the owner of Impresa individuale Macelleria Salumeria Halal EUR 2,000 for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency and data processing requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 Feb 2026 | Bressanelli Galli Gelpi Porta & C. S.r.l.The company was fined EUR 15,000 by the Garante for sending promotional emails without prior consent from recipients. The authority found this to be a breach of GDPR principles, including Article 5. | IT | Garante | GDPR | €15,000 | ↗ |
| 09 Oct 2014 | Zhao ShujuanZhao Shujuan was fined by the Garante for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system. This constituted a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 16 Sept 2021 | Accademia di Belle Arti di RomaAccademia di Belle Arti di Roma was fined EUR 5,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data in a disciplinary procedure and the dissemination of sensitive information. | IT | Garante | GDPR | €5,000 | ↗ |
| 09 Oct 2025 | Sicuritalia S.p.A.Sicuritalia S.p.A. was fined EUR 500,000 by the Italian supervisory authority Garante. The case concerned unauthorized access to a former employee's email account after employment ended, in breach of GDPR requirements. | IT | Garante | GDPR | €500,000 | ↗ |
| 21 Mar 2024 | LAZIOcrea S.p.a.LAZIOcrea S.p.a. was fined by the Garante for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies led to unauthorized access attempts and temporary unavailability of regional services. | IT | Garante | GDPR | €271,000 | ↗ |
| 21 Jan 2016 | Malta Games di Belgiorno Chiara & C. s.a.s.Malta Games di Belgiorno Chiara & C. s.a.s. was fined EUR 2,400 by the Garante. The authority found that the company failed to provide the required information to data subjects about personal data processing through a video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 18 Feb 2010 | Fibrille s.r.l.Fibrille s.r.l. was fined EUR 6,000 by the Garante for processing personal data from job applicants' CVs without providing the required information. The authority found a breach of the notice obligation under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 06 Jun 2018 | Dalmesse Italia s.r.l.Dalmesse Italia s.r.l. was fined €22,000 by the Italian supervisory authority, Garante. The case concerned the processing of personal data, including sensitive health data, without proper compliance with data protection rules. | IT | Garante | GDPR | €22,000 | ↗ |
| 31 Jan 2019 | CT BARCT BAR was fined by the Garante for unlawful processing of personal data through its video surveillance system. The recordings were retained for 15 days without proper compliance with applicable rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 01 Jun 2023 | AUSL Toscana Sud EstThe Garante fined AUSL Toscana Sud Est 20,000 EUR for the unlawful dissemination of a patient's health data. The authority found a breach of data protection principles. | IT | Garante | GDPR | €20,000 | ↗ |
| 09 Jun 2016 | Comune di LevantoThe Municipality of Levanto was fined EUR 4,000 by the Garante for publishing on its website a list of candidates for regional contributions. The disclosure of personal data lacked sufficient legal basis and breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Feb 2024 | Sigma s.r.l.Sigma s.r.l. was fined EUR 150,000 by the Garante for unauthorized activation of paid services and devices using customer data without consent. The authority found that the company’s conduct breached GDPR rules on personal data processing. | IT | Garante | GDPR | €150,000 | ↗ |
| 17 Oct 2024 | ComuneThe Garante fined Comune EUR 8,000 for breaches of GDPR Articles 5, 6 and 9, and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data in the context of public employment and administrative transparency. | IT | Garante | GDPR | €8,000 | ↗ |
| 25 Sept 2025 | E-Power S.r.l.E-Power S.r.l. was fined EUR 35,000 by the Garante for making promotional calls without a valid legal basis. The authority also found that the company failed to respond to data subject rights requests, which breaches GDPR requirements. | IT | Garante | GDPR | €35,000 | ↗ |
| 27 Nov 2024 | Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 20,000 EUR for publishing employees’ personal data without a legal basis. The disclosure included details on additional payments, sickness absences, and union rights, breaching the GDPR and the national privacy code. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Jun 2008 | Contact point s.r.l.Contact point s.r.l. was fined by the Garante 10,000 EUR for breaching data protection rules. The case concerned improper handling of personal data during opinion surveys. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2014 | Roma CapitaleRoma Capitale was fined for unlawfully publishing personal data related to a disciplinary action on its institutional website. The authority found that this conduct violated Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |