BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 May 2017 | Unit Contact s.r.l.Unit Contact s.r.l. was fined by the Garante EUR 10,000 for making unsolicited promotional calls to a number listed in the public opt-out register. The conduct breached data protection rules and telephone marketing requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Mar 2017 | Moto One s.r.l.Moto One s.r.l. was fined by the Garante in the amount of 14,400 EUR for violations related to its video surveillance system. The authority found that recorded images were retained longer than permitted and that required informational signage was missing. | IT | Garante | GDPR | €14,400 | ↗ |
| 08 Jul 2015 | FNAC Italia s.r.l.FNAC Italia s.r.l. was fined €2,400 by the Garante. The authority found that the company did not provide data subjects with adequate information about the purpose of processing under its video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 26 Oct 2023 | A.C. Group S.r.l.s.A.C. Group S.r.l.s. was fined by the Garante 10,000 EUR for making an unsolicited marketing call to a number listed in the Public Register of Objections without prior informed consent. The authority also found that the company failed to adequately respond to a data subject rights request. | IT | Garante | GDPR | €10,000 | ↗ |
| 20 Mar 2008 | Cid-Centro informazioni didatticoCid-Centro informazioni didattico was fined 3,000 EUR by the Garante for sending advertising material by fax without providing prior and adequate information to recipients. The conduct breached data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 08 Jul 2015 | Autotrasporti Multipli Arcese SpaAutotrasporti Multipli Arcese Spa was fined 12,000 EUR by the Garante for retaining surveillance footage longer than the period allowed under the authority's guidelines. The case concerns non-compliance with data protection rules on video retention. | IT | Garante | GDPR | €12,000 | ↗ |
| 21 Apr 2016 | Ditta individuale Fang WeiweiDitta individuale Fang Weiwei was fined 2,400 EUR by the Garante. The authority found that the video surveillance system was used without providing the information required under privacy rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 17 Dec 2020 | Miropass S.r.l.Miropass S.r.l. was fined EUR 40,000 by the Italian supervisory authority Garante. The case concerned violations related to data processing activities. | IT | Garante | GDPR | €40,000 | ↗ |
| 26 May 2022 | Kalemci MusaThe sole proprietorship “Turkish City” was fined 2,000 EUR by the Garante. The authority found that its video surveillance system did not meet the information requirements under GDPR Article 13. | IT | Garante | GDPR | €2,000 | ↗ |
| 01 Aug 2012 | Spazio S s.r.l.Spazio S s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial emails. The authority found that the company failed to provide adequate information and did not obtain valid consent from recipients, breaching privacy rules. | IT | Garante | GDPR | €10,400 | ↗ |
| 26 Jun 2008 | Contact point s.r.l.Contact point s.r.l. was fined 3,000 EUR by the Garante for violating data protection rules. The case concerned improper handling of personal data during opinion surveys. | IT | Garante | GDPR | €3,000 | ↗ |
| 11 Jul 2013 | Cowboys' Guest Ranch S.r.l.Cowboys' Guest Ranch S.r.l. was fined EUR 14,400 by the Garante for failing to provide the required privacy notice when collecting personal data through online forms, paper questionnaires, and dance competition registration forms. The breach concerned the obligation to inform data subjects about the processing of their personal data. | IT | Garante | GDPR | €14,400 | ↗ |
| 16 Dec 2009 | Campolongo Hospital s.p.a.Campolongo Hospital s.p.a. was fined by the Garante for collecting personal data through its website without providing users with the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 05 Oct 2017 | Qiu JunjieQiu Junjie was fined EUR 10,000 by the Garante for failing to protect video surveillance recordings with a password. The authority found this breached the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Dec 2019 | Eni Gas e Luce S.p.A.Eni Gas e Luce S.p.A. was fined EUR 8,500,000 by the Garante for making unsolicited telemarketing calls without consent. The conduct also affected individuals who had opted out or were listed in the public opposition register. | IT | Garante | GDPR | €8,500,000 | ↗ |
| 12 Sept 2024 | Sky Italia S.r.l.Sky Italia S.r.l. was fined EUR 842,062 by the Garante for telemarketing violations. The authority found that the company contacted individuals without proper consent and failed to consult the Public Register of Objections before promotional campaigns. | IT | Garante | GDPR | €842,000 | ↗ |
| 02 Nov 2024 | Intesa SanpaoloThe Italian Data Protection Authority fined Intesa Sanpaolo €31.8 million for a data breach involving unauthorized access to banking information of more than 3,500 clients. The authority also found that the bank detected the activity late and filed an incomplete and delayed breach notification. | IT | Garante per la protezione dei dati personali | GDPR | €31,800 | ↗ |
| 15 Dec 2016 | Stireria Rosa di HU XINStireria Rosa di HU XIN was fined 2,400 EUR by the Garante. The authority found that the company failed to inform data subjects about the processing of personal data through a video surveillance system covering public areas. | IT | Garante | GDPR | €2,400 | ↗ |
| 18 Feb 2016 | Europa Investigazioni s.r.lEuropa Investigazioni s.r.l was fined EUR 8,000 by the Garante. The authority found that the company failed to notify the processing of data indicating the geographical position of individuals or objects via an electronic communications network. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Feb 2025 | D.e.c. soc. coop.The Garante imposed a EUR 20,000 fine on D.e.c. soc. coop. for failing to deactivate an ex-employee's email account after the employment ended. The authority found this conduct breached GDPR principles of fair and transparent processing of personal data. | IT | Garante | GDPR | €20,000 | ↗ |