BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Jul 2015 | Ordinanza ingiunzione - 2 luglio 2015 [4337649]The condominium administrator did not respond to requests for information related to a data protection complaint. Garante imposed a fine of EUR 4,000 for violating data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 11 Jul 2013 | Slots R Us srlSlots R Us srl was fined EUR 6,000 by the Garante for failing to provide the required information notice for its video surveillance system. The case concerned non-compliance with data protection rules on informing individuals subject to CCTV monitoring. | IT | Garante | GDPR | €6,000 | ↗ |
| 21 Jul 2016 | Personal club s.r.l.Personal club s.r.l. was fined by the Garante in the amount of EUR 2,400 for failing to provide simplified information about the use of a video surveillance system. The breach concerned the data protection information duties applicable to such processing. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 Nov 2015 | Capodarco Società Cooperativa Sociale IntegrataCapodarco Società Cooperativa Sociale Integrata was fined EUR 12,000 by the Garante for recording and listening to calls between call center operators and users. The authority found that the required information notice was not provided to worker members, in breach of data protection rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 29 Apr 2026 | Istituto Comprensivo Statale MontelibrettiIstituto Comprensivo Statale Montelibretti was fined EUR 4,000 by the Garante for breaches of data protection rules in the processing of personal data on its institutional website. The authority cited failures to comply with lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Feb 2017 | Sisal S.p.A.Sisal S.p.A. was fined by the Garante in the amount of EUR 20,000 for installing a geolocation system on smartphones provided to employees without proper compliance with data protection rules. The case concerned the processing of location data in an employment context and insufficient legal safeguards. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Apr 2016 | Comune di OttavianoComune di Ottaviano was fined for publishing individuals’ personal data on its website without a legal basis. The authority found this breached Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Sept 2021 | Prefettura - Ufficio Territoriale del Governo di GenovaPrefettura - Ufficio Territoriale del Governo di Genova was fined by the Garante for publishing personal data on its institutional website. The conduct breached GDPR requirements on lawful processing and protection of personal data. | IT | Garante | GDPR | €11,000 | ↗ |
| 01 Jun 2023 | NH Italia S.p.A.NH Italia S.p.A. was fined EUR 200,000 by the Garante for failing to appoint specific data processors responsible for the installation and maintenance of video surveillance systems. The authority found this breached the GDPR principles of lawful, fair, and transparent processing of personal data. | IT | Garante | GDPR | €200,000 | ↗ |
| 14 Sept 2023 | Nimbus s.r.l.Nimbus s.r.l. was fined by the Garante 5,000 EUR for using a fingerprint-based attendance system. The authority found that employees were not properly informed and that the required consent was not obtained. | IT | Garante | GDPR | €5,000 | ↗ |
| 12 Feb 2026 | Anconambiente S.P.A.Anconambiente S.P.A. was fined by the Garante for failing to ensure that personal data processing was lawful, fair, and transparent. The authority also found that the company did not have a proper contract with a data processor, as required by Article 28 GDPR. | IT | Garante | GDPR | €2,500 | ↗ |
| 16 Dec 2021 | 1000 Luci Round a BarThe establishment 1000 Luci Round a Bar was fined EUR 1,000 by the Italian authority Garante. The sanction concerned a video surveillance system that did not meet the information requirements of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |
| 29 Sept 2021 | Comune di FormiaComune di Formia was fined for processing personal data linked to parking subscription services without providing adequate information to data subjects. The authority also found excessive data collection and a failure to clearly define the role of the external data processor. | IT | Garante | GDPR | €30,000 | ↗ |
| 18 May 2016 | Accademia Dante Alighieri s.r.l.Accademia Dante Alighieri s.r.l. was fined by the Garante 2,400 EUR for collecting personal data from users through its websites without providing the required information or obtaining consent. The conduct breached Articles 13 and 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 21 Mar 2018 | Azienda Sanitaria Locale Napoli 2 NordAzienda Sanitaria Locale Napoli 2 Nord was fined by the Garante for allowing personal data of registered users to be accessed and modified by anyone through its institutional website. The case concerned inadequate protection of personal data and non-compliance with data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Mar 2019 | Comune di Porto Sant’ElpidioThe Garante fined Comune di Porto Sant’Elpidio EUR 10,000 for publishing documents on its website that contained personal data revealing the health status of individuals with disabilities. The authority found a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Jun 2025 | Istituto d’Istruzione Superiore “Carlo e Nello Rosselli”The Garante imposed a EUR 4,000 fine on Istituto d’Istruzione Superiore “Carlo e Nello Rosselli” for failing to appoint a Data Protection Officer and for delaying notification of the DPO’s contact details to the authority. The authority also found that transparency obligations toward data subjects were not met. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Apr 2021 | FederpolFederpol was fined 5,000 EUR by the Garante for improperly sharing members’ personal information with other associates. The authority found that this breached data protection rules and required a valid legal basis and appropriate safeguards. | IT | Garante | GDPR | €5,000 | ↗ |
| 30 Jan 2014 | Comune di Reggio Emilia – Comando Polizia municipaleThe Municipality of Reggio Emilia's Police Command was fined EUR 2,400 by the Garante for operating a video surveillance system without simplified information signage. The authority found a breach of Article 13 of the Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 10 Mar 2016 | Ministero della giustizia – Dipartimento dell’amministrazione penitenziariaThe Ministry of Justice's Department of Penitentiary Administration was fined EUR 4,000 by the Garante for unlawful processing of personal data. The breach involved disclosing the names and details of prison police personnel who received overtime compensation. | IT | Garante | GDPR | €4,000 | ↗ |