BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Sept 2021 | Azienda sanitaria provinciale di CosenzaAzienda sanitaria provinciale di Cosenza was fined by the Garante for unlawfully publishing health data on its institutional website. The case involved breaches of data protection principles and required security measures for sensitive data. | IT | Garante | GDPR | €18,000 | ↗ |
| 06 Sept 2012 | Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined 34,000 EUR by the Garante. The authority found a breach of notification obligations under data protection rules. | IT | Garante | GDPR | €34,000 | ↗ |
| 14 Jan 2021 | Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined by the Garante €30,000 for unlawfully processing employees’ biometric data to monitor attendance. The conduct breached GDPR requirements on lawful processing and data minimisation. | IT | Garante | GDPR | €30,000 | ↗ |
| 13 Nov 2024 | Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 8,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data. The decision indicates non-compliance with core rules on lawful and proper processing. | IT | Garante | GDPR | €8,000 | ↗ |
| 27 Nov 2024 | Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 20,000 EUR for publishing employees’ personal data without a legal basis. The disclosure included details on additional payments, sickness absences, and union rights, breaching the GDPR and the national privacy code. | IT | Garante | GDPR | €20,000 | ↗ |
| 11 Oct 2012 | Azienda sanitaria provinciale di Vibo ValentiaAzienda sanitaria provinciale di Vibo Valentia was fined by the Garante EUR 15,000 for failing to adopt the required minimum security measures. The authority found that the Security Programmatic Document (DPS) was not updated by the deadline required under the Italian Privacy Code. | IT | Garante | GDPR | €15,000 | ↗ |
| 13 Dec 2012 | Azienda sanitaria regionale MoliseThe Regional Health Company of Molise was fined for failing to designate data processing officers for each employee. The authority also found that minimum security measures for electronic processing were not implemented, including weak password policies and insufficient protection against unauthorized external access. | IT | Garante | GDPR | €15,000 | ↗ |
| 26 Sept 2024 | Azienda Sanitaria Territoriale di Ascoli PicenoThe Garante fined Azienda Sanitaria Territoriale di Ascoli Piceno EUR 17,000 for failing to implement procedures that would prevent unauthorized linkage between individuals and health departments. The issue could reveal information about a person's health status. | IT | Garante | GDPR | €17,000 | ↗ |
| 27 Mar 2025 | Azienda sanitaria territoriale di MacerataAzienda sanitaria territoriale di Macerata was fined 5,000 EUR by the Garante for failing to comply with data access requests and for breaches of data protection rules. The case concerned the processing of health data and inadequate security measures. | IT | Garante | GDPR | €5,000 | ↗ |
| 23 Mar 2017 | Azienda Sanitaria ULSS 6 di VicenzaAzienda Sanitaria ULSS 6 di Vicenza was fined by the Garante 10,000 EUR for unlawfully communicating an individual's health data to the Comune di Arcugnano without proper authorization. The case involved a breach of lawful processing rules and safeguards for special-category data. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Jan 2022 | Azienda sanitaria unica regionale MarcheAzienda sanitaria unica regionale Marche was fined EUR 14,000 by the Garante for inadequate data protection measures. The breach involved health data and was linked to QR code generation; improved security measures were later implemented. | IT | Garante | GDPR | €14,000 | ↗ |
| 26 May 2022 | Azienda sanitaria universitaria Friuli OccidentaleAzienda sanitaria universitaria Friuli Occidentale was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the electronic health dossier. The authority found non-compliance with GDPR requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 24 Jun 2020 | Azienda Sanitaria Universitaria Giuliano IsontinaAzienda Sanitaria Universitaria Giuliano Isontina was fined by the Garante for unlawfully communicating health data without an adequate legal basis. The conduct breached Article 20 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jun 2018 | Azienda Semplice s.r.l.Azienda Semplice s.r.l. was fined by the Garante 16,000 EUR for unlawful processing of personal data used to place promotional calls to a private residential phone number without consent. The case concerns a lack of a lawful basis for marketing contact and a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 21 Dec 2023 | Azienda socio-sanitaria localeThe Garante imposed a fine on a local health authority for violations related to the handling of sensitive personal data. The case concerned improper processing of special-category data, which breached data protection rules. | IT | Garante | GDPR | €18,000 | ↗ |
| 18 Jul 2023 | Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest MilaneseThe Garante fined Azienda Socio Sanitaria Territoriale (A.S.S.T.) Ovest Milanese 12,000 EUR for a data breach. Personal data was accessed without negative consequences for the data subjects. The organization took measures to prevent similar violations in the future. | IT | Garante | GDPR | €12,000 | ↗ |
| 12 May 2022 | Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante €7,000 for violations related to the processing of health data. The authority also found insufficient data security measures. | IT | Garante | GDPR | €7,000 | ↗ |
| 29 Apr 2021 | Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante in the amount of 4,000 EUR for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization because personal data remained accessible online for an extended period. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Apr 2021 | Azienda socio sanitaria territoriale Melegnano e della MartesanaAzienda socio sanitaria territoriale Melegnano e della Martesana was fined by the Garante €6,000 for a data breach involving the loss of health data. The case concerned special-category personal data and indicates insufficient organizational or technical safeguards. | IT | Garante | GDPR | €6,000 | ↗ |
| 27 Jan 2022 | Azienda socio sanitaria territoriale Nord di MilanoAzienda socio sanitaria territoriale Nord di Milano was fined by the Garante 20,000 EUR for failing to implement adequate security measures to protect personal data. The authority found a breach of GDPR provisions on data protection and security. | IT | Garante | GDPR | €20,000 | ↗ |