BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Dec 2023 | Azienda OspedalieraAzienda Ospedaliera was fined EUR 8,000 by the Garante for breaches of data protection rules. The case concerned data processing principles and insufficient security measures. | IT | Garante | GDPR | €8,000 | ↗ |
| 30 Jan 2014 | Orovicenza di Picaro CristinaOrovicenza di Picaro Cristina was fined EUR 4,800 by the Garante. The authority found that the website’s contact and registration forms did not provide the required data protection information, in breach of the Italian data protection code. | IT | Garante | GDPR | €4,800 | ↗ |
| 11 Jan 2023 | Reweb s.r.l.Reweb s.r.l. was fined 5,000 EUR by the Garante. The company kept a former employee’s email account active and accessed it after the employment relationship ended, in breach of GDPR requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 03 May 2018 | Ordinanza ingiunzione - 3 maggio 2018 [9023941]A fine of EUR 20,000 was imposed for failing to notify the Garante about the processing of geolocation data collected through GPS devices. The case concerns a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Oct 2023 | Scionti Selezioni Superiori S.r.l.Scionti Selezioni Superiori S.r.l. was fined EUR 70,000 by the Garante for failing to implement adequate measures to prevent unauthorized access to customer data. The data was then used for promotional purposes without the individuals' consent. | IT | Garante | GDPR | €70,000 | ↗ |
| 12 Feb 2015 | Visini FabioVisini Fabio was fined EUR 12,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection requirements. | IT | Garante | GDPR | €12,000 | ↗ |
| 16 May 2018 | Conafi Prestitò s.p.a.Conafi Prestitò s.p.a. was fined by the Garante for failing to notify certain data processing activities related to loan management. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Jan 2015 | Barta s.r.l.Barta s.r.l. was fined by the Garante EUR 12,000 for operating a video surveillance system without prior authorization. Footage was retained for 15 days, exceeding the permitted one-week period. | IT | Garante | GDPR | €12,000 | ↗ |
| 28 Mar 2019 | Comune di GenovaComune di Genova was fined for unlawfully communicating personal data to third-party companies without a proper legal basis. The authority found a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Jan 2022 | Azienda sanitaria unica regionale MarcheAzienda sanitaria unica regionale Marche was fined EUR 14,000 by the Garante for inadequate data protection measures. The breach involved health data and was linked to QR code generation; improved security measures were later implemented. | IT | Garante | GDPR | €14,000 | ↗ |
| 17 Jul 2025 | Poliambulatorio San Liberale S.r.l.The Garante imposed a EUR 12,500 fine on Poliambulatorio San Liberale S.r.l. for failing to meet information and transparency obligations in the processing of personal data, including health data. The company also did not respond to a data access request, adding a further breach of data subject rights. | IT | Garante | GDPR | €12,500 | ↗ |
| 19 Feb 2015 | Andrea AngeloniAndrea Angeloni was fined by the Garante for sending unsolicited promotional letters. The entity also failed to respond to information requests from the supervisory authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2025 | Azienda ULSS n. 02573090236The public health company was fined for making a disciplinary proceeding document visible to unauthorized employees. The authority found breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 May 2017 | Starweb s.r.l.Starweb s.r.l. was fined €16,000 by the Garante for making unsolicited promotional calls. The authority found that the company failed to provide the required information notice and did not obtain consent from the contacted individuals. | IT | Garante | GDPR | €16,000 | ↗ |
| 14 Jun 2018 | Faiella Nicola s.r.l.Faiella Nicola s.r.l. was fined EUR 112,000 by the Garante for improper processing of personal data using geolocation and video surveillance systems. The authority found that the company did not comply with data protection requirements when deploying these tools. | IT | Garante | GDPR | €112,000 | ↗ |
| 02 Jul 2015 | Lycamobile s.r.l.Lycamobile s.r.l. was fined EUR 102,000 by the Garante for failing to provide requested information on the retention of telephone and telematic traffic data. The case concerned a breach of data protection rules. | IT | Garante | GDPR | €102,000 | ↗ |
| 25 Sept 2025 | Azienda Ospedaliero Universitaria di FerraraAzienda Ospedaliero Universitaria di Ferrara was fined EUR 20,000 by the Garante for irregularities in the handling of personal data in its health dossier system. The authority found that the organization failed to implement adequate measures to protect data privacy. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Nov 2025 | Maviglia Assicurazioni snc di Gherardo Maviglia & c.Maviglia Assicurazioni was fined by the Garante 10,000 EUR for unlawful processing of personal data. The case involved automatic email redirection and indefinite retention of email logs and content, which breached GDPR principles. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Feb 2025 | Ministero dell’Interno-Dipartimento per gli affari interni e territorialiThe Ministry of the Interior was fined EUR 3,000 for processing personal data through the CIE-Agenda Online service. The authority found that the processing did not comply with the principles of lawfulness, fairness, transparency, and purpose limitation. | IT | Garante | GDPR | €3,000 | ↗ |
| 23 May 2024 | Provvedimento del 23 maggio 2024 [10043051]The Garante imposed a fine of EUR 400 for the unlawful use of surveillance cameras capturing public areas without a proper legal basis. The conduct breached privacy and data protection requirements. | IT | Garante | GDPR | €400 | ↗ |