BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 Jan 2019 | Azienda Sanitaria Locale di AlessandriaAzienda Sanitaria Locale di Alessandria was fined by the Garante 16,000 EUR for processing personal data through the health dossier without full compliance with data protection rules. The case concerned improper handling of sensitive data in a medical system. | IT | Garante | GDPR | €16,000 | ↗ |
| 22 Jul 2021 | Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 35,000 by the Garante for failing to adopt minimum security measures. The breach resulted in exposure of health data, creating a significant compliance and privacy risk. | IT | Garante | GDPR | €35,000 | ↗ |
| 02 Mar 2023 | Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 50,000 by the Garante for violations in the processing of personal data. The authority found non-compliance with the principles of data minimization and integrity and confidentiality. | IT | Garante | GDPR | €50,000 | ↗ |
| 28 Jun 2018 | Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined by the Garante €20,000 for sharing access credentials among employees. The authority found this to be a breach of data protection rules and access control requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 11 Jan 2023 | Azienda Sanitaria Locale di BrindisiAzienda Sanitaria Locale di Brindisi was fined by the Garante 2,500 EUR for failing to respond to a data access request. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €2,500 | ↗ |
| 22 Jul 2021 | Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5)Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5) was fined EUR 4,000 by the Garante for violations related to the processing of personal data, including health data, during the COVID-19 pandemic. The case concerned improper handling of sensitive data in the context of pandemic-related activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Mar 2020 | Azienda Sanitaria Locale di Ciriè, Chivasso e Ivrea (ASL TO4)ASL TO4 was fined by the Garante EUR 8,000 for unlawful data processing through video surveillance. The authority found that the required agreements with unions were not in place. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Sept 2007 | Azienda sanitaria locale di Lanciano/VastoAzienda sanitaria locale di Lanciano/Vasto was fined by the Garante 10,000 EUR for improper handling of sensitive personal data. The case involved genetic and biometric data processed without proper authorization. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Apr 2026 | Azienda Sanitaria Locale di MateraAzienda Sanitaria Locale di Matera was fined by the Garante EUR 8,600 after a data breach caused by a ransomware attack. The incident led to the exfiltration of personal data, and the authority found inadequate technical and organizational measures to protect data security. | IT | Garante | GDPR | €8,600 | ↗ |
| 04 Apr 2007 | Azienda sanitaria locale di PescaraAzienda sanitaria locale di Pescara was fined €10,000 by the Garante for breaching data protection rules. The case involved improper handling of sensitive personal data, including genetic and health information, without the required notification to the authority. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale di PiacenzaAzienda sanitaria locale di Piacenza was fined for failing to notify the Garante about processing data relating to health and sexual life. The authority treated this as a breach of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Jan 2022 | Azienda Sanitaria Locale FrosinoneAzienda Sanitaria Locale Frosinone was fined by the Italian supervisory authority, Garante, in the amount of EUR 7,500. The case concerned breaches of transparency and information duties in personal data processing under GDPR Articles 12 and 13. | IT | Garante | GDPR | €7,500 | ↗ |
| 11 Feb 2021 | Azienda Sanitaria Locale n. 2 Lanciano-Vasto-ChietiAzienda Sanitaria Locale n. 2 Lanciano-Vasto-Chieti was fined by the Garante 6,500 EUR for violations related to the processing of health data. The нарушения led to a data breach incident. | IT | Garante | GDPR | €6,500 | ↗ |
| 14 Sept 2006 | Azienda sanitaria locale n. 6 di CirièASL Ciriè was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The breach concerned obligations under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Mar 2018 | Azienda Sanitaria Locale Napoli 2 NordAzienda Sanitaria Locale Napoli 2 Nord was fined by the Garante for allowing personal data of registered users to be accessed and modified by anyone through its institutional website. The case concerned inadequate protection of personal data and non-compliance with data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 May 2022 | Azienda Sanitaria Locale Roma 1The Garante fined Azienda Sanitaria Locale Roma 1 EUR 46,000 for the unauthorized publication of health-related personal data on its institutional website. The case concerned a breach of data protection rules through the disclosure of sensitive information without a lawful basis. | IT | Garante | GDPR | €46,000 | ↗ |
| 21 Mar 2024 | Azienda sanitaria locale Roma 3The Garante fined Azienda sanitaria locale Roma 3 10,000 EUR for failing to adequately protect personal data. The breach led to attempted unauthorized access to user accounts and indicated insufficient cybersecurity controls. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Oct 2023 | Azienda Sanitaria Locale TO3Azienda Sanitaria Locale TO3 was fined by the Garante for a health data breach affecting four individuals. The incident lasted nine days and was deemed negligent. | IT | Garante | GDPR | €6,000 | ↗ |
| 24 Mar 2022 | Azienda sanitaria provinciale di CaltanissettaAzienda sanitaria provinciale di Caltanissetta was fined for failing to update the Data Protection Officer’s contact details on its website and in communications with the Authority. The conduct breached GDPR Article 37. | IT | Garante | GDPR | €6,000 | ↗ |
| 15 Dec 2022 | Azienda Sanitaria provinciale di CataniaAzienda Sanitaria provinciale di Catania was fined 5,000 EUR by the Garante for unlawfully publishing personal data on its website concerning an employee's disciplinary and criminal proceedings. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €5,000 | ↗ |