BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Feb 2024 | Airone società consortile a r.l.Airone società consortile a r.l. was fined EUR 5,000 by Garante for unlawfully processing biometric data through facial recognition to monitor employee attendance. The authority found that the same purpose could have been achieved by less intrusive means. | IT | Garante | GDPR | €5,000 | ↗ |
| 14 Sept 2023 | Shardana Working Soc. Coop. a r.l.Shardana Working Soc. Coop. a r.l. was fined by the Garante 20,000 EUR for failing to fully comply with data access requests. The authority found a breach of Article 15 GDPR. | IT | Garante | GDPR | €20,000 | ↗ |
| 11 Sept 2025 | Comune di VeronaThe Comune di Verona was fined for improperly sharing personal data of TARI taxpayers with a third party for engagement communications. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €6,000 | ↗ |
| 03 Jul 2014 | Tenacta Group s.p.a.Tenacta Group s.p.a. was fined 10,000 EUR by the Garante for making unsolicited promotional phone calls. The company failed to consult the public opposition register, thereby violating the subscriber's right to object. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Jun 2018 | Azienda Unità Sanitaria Locale di PiacenzaAzienda Unità Sanitaria Locale di Piacenza was fined by the Garante EUR 36,000 for creating electronic health records without informing patients or obtaining their consent. The authority found this to be a breach of privacy rules. | IT | Garante | GDPR | €36,000 | ↗ |
| 02 Jul 2020 | Comune di ManduriaComune di Manduria was fined by the Garante in the amount of 2,000 EUR for breaching data protection principles, including lawfulness, fairness, and transparency. The authority found that personal data had been improperly disseminated through journalistic outlets. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 May 2024 | Azienda USL della RomagnaThe Garante imposed a fine of EUR 8,400 on Azienda USL della Romagna for violations related to data processing operations. The processes were largely manual and dependent on operator diligence, which led to a data breach. | IT | Garante | GDPR | €8,400 | ↗ |
| 16 Jun 2022 | Federazione Italiana NuotoFederazione Italiana Nuoto was fined EUR 2,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 of the GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 14 Nov 2019 | ASL n. 2 SavoneseASL n. 2 Savonese was fined EUR 8,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data, including failures to comply with lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €8,000 | ↗ |
| 02 Jul 2020 | Comune di Greve in ChiantiComune di Greve in Chianti was fined by the Garante for unlawfully disclosing personal data relating to criminal convictions and proceedings. The conduct breached the principles of lawfulness, fairness, and transparency in data processing. | IT | Garante | GDPR | €4,000 | ↗ |
| 30 Oct 2013 | Comune di BolzanoComune di Bolzano was fined 10,000 EUR by the Garante for publishing sensitive health-related information about an employee’s absence on its institutional website. The authority found a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Nov 2017 | A.M.A.CO. s.p.a.A.M.A.CO. s.p.a. was fined by the Garante for installing non-compliant video surveillance and geolocation systems on its vehicles. The authority found that these measures breached data protection rules. | IT | Garante | GDPR | €22,400 | ↗ |
| 24 Nov 2016 | Provincia di VercelliProvincia di Vercelli was fined EUR 10,000 by the Garante for unlawfully publishing personal data on its institutional website. The disclosed information included photocopies of identity cards and bank account numbers, without an appropriate legal basis. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Mar 2008 | Frareg s.r.l.Frareg s.r.l. was fined by the Garante for sending advertising material by fax without providing prior and adequate information to recipients. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 10 Jun 2021 | Aeroporto Guglielmo Marconi di Bologna S.p.a.Aeroporto Guglielmo Marconi di Bologna S.p.a. was fined by the Garante EUR 40,000 for violations related to the protection of whistleblower identities. The case indicates insufficient personal data safeguards in the handling of reports. | IT | Garante | GDPR | €40,000 | ↗ |
| 05 Jul 2018 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 800,000 by the Garante for making unsolicited promotional phone calls and sending SMS messages without proper consent. The authority found that these practices breached data protection rules. | IT | Garante | GDPR | €800,000 | ↗ |
| 08 Feb 2007 | Asl OristanoAsl Oristano was fined EUR 10,000 by the Garante for failing to notify the processing of personal data concerning health and sexual life. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Dec 2022 | Eurosanità S.P.A.Eurosanità S.P.A. was fined by the Garante in the amount of 30,000 EUR for violations related to the processing of health data. The authority cited inadequate personal data protection measures. | IT | Garante | GDPR | €30,000 | ↗ |
| 30 Oct 2013 | Ye BiYe Bi was fined by the Garante EUR 2,400 for operating a video surveillance system at Bar Millennium without the required signage. The authority found a breach of privacy regulations. | IT | Garante | GDPR | €2,400 | ↗ |
| 05 Feb 2015 | Comune di MontagnarealeThe Garante fined Comune di Montagnareale 10,000 EUR for unlawfully publishing personal data revealing health status on its institutional website. The breach involved disclosure of sensitive data without an adequate legal basis or safeguards. | IT | Garante | GDPR | €10,000 | ↗ |