BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 May 2026 | Azienda ospedaliera dei colli Monaldi-Cotugno-CTO di NapoliAzienda ospedaliera dei colli Monaldi-Cotugno-CTO di Napoli was fined EUR 15,000 by the Garante. The authority found that the entity provided false statements and interrupted the performance of its tasks. The case concerns breaches of data protection rules. | IT | Garante | GDPR | €15,000 | ↗ |
| 07 Apr 2022 | Azienda ospedaliera di PerugiaAzienda ospedaliera di Perugia was fined by the Garante EUR 40,000 for breaches related to the protection of whistleblower identities. The authority found that adequate personal data protection measures were not in place. | IT | Garante | GDPR | €40,000 | ↗ |
| 17 Sept 2020 | Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The Garante imposed an EUR 80,000 fine on Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli” for a data breach involving sensitive health data. The incident occurred during a platform maintenance period, indicating insufficient safeguards around processing. | IT | Garante | GDPR | €80,000 | ↗ |
| 25 Nov 2021 | Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The hospital was fined by the Garante 50,000 EUR for unlawfully publishing on its website the personal data of participants in a competitive procedure, including health data. The authority found a breach of data protection principles. | IT | Garante | GDPR | €50,000 | ↗ |
| 18 Jun 2015 | Azienda Ospedaliera Ospedale di Circolo Fondazione MacchiAzienda Ospedaliera Ospedale di Circolo Fondazione Macchi was fined by the Garante 4,000 EUR for processing sensitive personal data without obtaining written consent. This breached the Italian Data Protection Code. The case highlights the need for a valid legal basis before processing special-category data. | IT | Garante | GDPR | €4,000 | ↗ |
| 14 Jun 2018 | Azienda Ospedaliera Pugliese CiaccioAzienda Ospedaliera Pugliese Ciaccio was fined EUR 16,000 by the Garante. The authority found that patients were not informed about data processing and that consent was not obtained for processing sensitive data, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €16,000 | ↗ |
| 27 Jan 2021 | Azienda ospedaliera regionale “San Carlo” di PotenzaAzienda ospedaliera regionale “San Carlo” di Potenza was fined EUR 70,000 by the Garante for violations related to the processing of personal data. The case concerned the handling of sensitive health data. | IT | Garante | GDPR | €70,000 | ↗ |
| 11 Mar 2021 | Azienda Ospedaliera San Giovanni AddolorataAzienda Ospedaliera San Giovanni Addolorata was fined EUR 20,000 by the Garante for inadequate data protection measures concerning patient health data. The authority found breaches of GDPR Articles 5 and 32. | IT | Garante | GDPR | €20,000 | ↗ |
| 24 Jun 2011 | Azienda ospedaliera San Giuseppe Moscati (AOSGM)Azienda ospedaliera San Giuseppe Moscati was fined EUR 20,000 by the Garante. The authority found that the security program document was not updated and that minimum security measures were not adopted for the processing of health data. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Jan 2021 | Azienda Ospedaliera San Pio di BeneventoAzienda Ospedaliera San Pio di Benevento was fined by the Garante 10,000 EUR for publishing employees’ personal data on its intranet without a proper legal basis. The case concerned unauthorized disclosure of personal data within the organization’s internal environment. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Apr 2018 | Azienda Ospedaliera Sant’Andrea di RomaAzienda Ospedaliera Sant’Andrea di Roma was fined 10,000 EUR by the Garante. The authority found that the organization failed to designate individuals responsible for data processing, in breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Apr 2018 | Azienda Ospedaliera Sant’Andrea di RomaAzienda Ospedaliera Sant’Andrea di Roma was fined 32,000 EUR by the Garante for violations related to the processing of personal data in healthcare services. The case concerned deficiencies in consent handling and patient information forms. | IT | Garante | GDPR | €32,000 | ↗ |
| 16 Jan 2026 | Azienda Ospedaliera S. Pio di BeneventoAzienda Ospedaliera S. Pio di Benevento was fined by the Garante EUR 6,000 for violations related to the processing of personal data. The case concerned special categories of data and disclosure to third parties. | IT | Garante | GDPR | €6,000 | ↗ |
| 13 Apr 2023 | Azienda Ospedaliera Universitaria di CagliariAzienda Ospedaliera Universitaria di Cagliari was fined EUR 8,000 by the Garante for unlawfully publishing personal data related to a disciplinary procedure online. The authority found breaches of data minimization and transparency principles. | IT | Garante | GDPR | €8,000 | ↗ |
| 10 Apr 2025 | Azienda Ospedaliera Universitaria Integrata VeronaAzienda Ospedaliera Universitaria Integrata Verona was fined by the Garante for failing to adequately protect personal data. After a ransomware attack, 612 GB of data was published on the dark web, indicating serious security shortcomings. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Jan 2015 | Azienda Ospedaliera Universitaria Policlinico Sant'Orsola-MalpighiAzienda Ospedaliera Universitaria Policlinico Sant'Orsola-Malpighi was fined EUR 2,400 by the Garante. The authority found that personal data collected through the website’s “contact us” form was processed without the required privacy notice, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Aug 2025 | Azienda Ospedaliero-UniversitariaThe Italian data protection authority fined Azienda Ospedaliero-Universitaria EUR 80,000 for improperly configuring its health dossier. It found that staff could access patients’ clinical histories without proper profiling, alerts, or access logging, and that patients were not adequately informed or able to consent or object. | IT | Garante per la protezione dei dati personali | GDPR | €80,000 | ↗ |
| 04 Aug 2025 | Azienda Ospedaliero Universitaria CareggiAzienda Ospedaliero Universitaria Careggi was fined by the Garante EUR 20,000 for violations related to the management of electronic health records. The authority found non-compliance with data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Oct 2022 | Azienda Ospedaliero-Universitaria Careggi di FirenzeAzienda Ospedaliero-Universitaria Careggi di Firenze was fined by the Garante 9,000 EUR for violations involving the processing of sensitive health data. The authority cited inadequate safeguards in the handling of histological examinations. | IT | Garante | GDPR | €9,000 | ↗ |
| 30 Jan 2025 | Azienda Ospedaliero - Universitaria Città della Salute e della Scienza di TorinoThe Garante fined Azienda Ospedaliero - Universitaria Città della Salute e della Scienza di Torino 6,000 EUR for unlawful processing of personal data, including health data. The authority found that the processing lacked an appropriate legal basis. The case concerned sensitive data handling in the healthcare sector. | IT | Garante | GDPR | €6,000 | ↗ |