BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Jun 2017 | Azienda Policlinico Umberto IAzienda Policlinico Umberto I was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate data processing officers and provide them with the necessary instructions, breaching minimum security measures under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Jun 2020 | Azienda Pluriservizi Macerata S.p.A.Azienda Pluriservizi Macerata S.p.A. was fined EUR 4,000 by the Garante for processing colleagues’ personal data in a manner that did not comply with data protection principles. The authority cited breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Nov 2022 | Azienda per la tutela della salute - ATS SardegnaATS Sardegna was fined by the Garante for breaching data protection principles in its handling of personal data relating to an employee's vaccination status. The authority found violations of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 14 Oct 2021 | Azienda per la Tutela della Salute (ATS) della SardegnaAzienda per la Tutela della Salute (ATS) della Sardegna was fined EUR 8,000 by the Garante for improper processing of personal data, including health data. The authority found breaches of GDPR Articles 5 and 9. | IT | Garante | GDPR | €8,000 | ↗ |
| 01 Jun 2016 | Azienda per i servizi sanitari n. 2 IsontinaAzienda per i servizi sanitari n. 2 Isontina was fined for unlawfully publishing personal data, including negative performance evaluations, of an individual on its institutional website. The conduct breached data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Jan 2021 | Azienda Ospedaliero Universitaria SeneseAzienda Ospedaliero Universitaria Senese was fined by the Garante in the amount of 10,000 EUR for breaches of data protection rules in the healthcare sector. The case concerned the processing of sensitive personal data in a medical setting. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Apr 2023 | Azienda Ospedaliero Universitaria SeneseThe Garante fined Azienda Ospedaliero Universitaria Senese EUR 13,000 for violations related to the processing of personal data in the health sector. The case concerned data minimization and security measures. | IT | Garante | GDPR | €13,000 | ↗ |
| 08 Jul 2021 | Azienda ospedaliero-universitaria SeneseAzienda ospedaliero-universitaria Senese was fined by the Garante 25,000 EUR for violations related to data breaches involving health data and patient information. The case concerned the handling of sensitive data and required assessment of compliance with data protection obligations. | IT | Garante | GDPR | €25,000 | ↗ |
| 29 Apr 2021 | Azienda Ospedaliero Universitaria PisanaAzienda Ospedaliero Universitaria Pisana was fined by the Garante EUR 4,000 for breaches of the principles of lawfulness, fairness, transparency, integrity, and confidentiality in data processing. The case concerned improper handling of personal data under GDPR requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Jan 2020 | Azienda Ospedaliero Universitaria Integrata di VeronaAzienda Ospedaliero Universitaria Integrata di Verona was fined by the Garante EUR 30,000 for employees' unauthorized access to patient health records. The authority found a breach of GDPR principles on data protection and security measures. | IT | Garante | GDPR | €30,000 | ↗ |
| 27 Jan 2021 | Azienda Ospedaliero Universitaria di ParmaAzienda Ospedaliero Universitaria di Parma was fined by the Garante for violations related to the handling of health data. The violations resulted in a data breach, which led to the 10,000 EUR penalty. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Sept 2021 | Azienda Ospedaliero-Universitaria di ModenaAzienda Ospedaliero-Universitaria di Modena was fined by the Garante for the incorrect handling of sensitive health data, including HIV diagnoses, during the COVID-19 emergency. The case concerned breaches of personal data protection rules and medical confidentiality. | IT | Garante | GDPR | €20,000 | ↗ |
| 25 Sept 2025 | Azienda Ospedaliero Universitaria di FerraraAzienda Ospedaliero Universitaria di Ferrara was fined EUR 20,000 by the Garante for irregularities in the handling of personal data in its health dossier system. The authority found that the organization failed to implement adequate measures to protect data privacy. | IT | Garante | GDPR | €20,000 | ↗ |
| 30 Jan 2025 | Azienda Ospedaliero - Universitaria Città della Salute e della Scienza di TorinoThe Garante fined Azienda Ospedaliero - Universitaria Città della Salute e della Scienza di Torino 6,000 EUR for unlawful processing of personal data, including health data. The authority found that the processing lacked an appropriate legal basis. The case concerned sensitive data handling in the healthcare sector. | IT | Garante | GDPR | €6,000 | ↗ |
| 20 Oct 2022 | Azienda Ospedaliero-Universitaria Careggi di FirenzeAzienda Ospedaliero-Universitaria Careggi di Firenze was fined by the Garante 9,000 EUR for violations involving the processing of sensitive health data. The authority cited inadequate safeguards in the handling of histological examinations. | IT | Garante | GDPR | €9,000 | ↗ |
| 04 Aug 2025 | Azienda Ospedaliero Universitaria CareggiAzienda Ospedaliero Universitaria Careggi was fined by the Garante EUR 20,000 for violations related to the management of electronic health records. The authority found non-compliance with data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 04 Aug 2025 | Azienda Ospedaliero-UniversitariaThe Italian data protection authority fined Azienda Ospedaliero-Universitaria EUR 80,000 for improperly configuring its health dossier. It found that staff could access patients’ clinical histories without proper profiling, alerts, or access logging, and that patients were not adequately informed or able to consent or object. | IT | Garante per la protezione dei dati personali | GDPR | €80,000 | ↗ |
| 29 Jan 2015 | Azienda Ospedaliera Universitaria Policlinico Sant'Orsola-MalpighiAzienda Ospedaliera Universitaria Policlinico Sant'Orsola-Malpighi was fined EUR 2,400 by the Garante. The authority found that personal data collected through the website’s “contact us” form was processed without the required privacy notice, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 10 Apr 2025 | Azienda Ospedaliera Universitaria Integrata VeronaAzienda Ospedaliera Universitaria Integrata Verona was fined by the Garante for failing to adequately protect personal data. After a ransomware attack, 612 GB of data was published on the dark web, indicating serious security shortcomings. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Apr 2023 | Azienda Ospedaliera Universitaria di CagliariAzienda Ospedaliera Universitaria di Cagliari was fined EUR 8,000 by the Garante for unlawfully publishing personal data related to a disciplinary procedure online. The authority found breaches of data minimization and transparency principles. | IT | Garante | GDPR | €8,000 | ↗ |