BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Nov 2025 | About YouThe Hungarian Competition Authority (GVH) found that About You used misleading discount pricing and pressured consumers with countdown timers and scarcity messages. The company was ordered to pay HUF 505 million to the Hungarian central budget and to provide compensation to affected Hungarian customers. | HU | Gazdasági Versenyhivatal | Omnibus | €1,323,000 | ↗ |
| 21 May 2025 | Autostrade per l'Italia SpaThe Italian data protection authority fined Autostrade per l'Italia Spa EUR 420,000 for unlawfully processing an employee's personal data. The company used content from her Facebook profile and private Messenger and WhatsApp chats to support disciplinary proceedings and justify her dismissal. | IT | Garante per la protezione dei dati personali | GDPR | €420,000 | ↗ |
| 27 Feb 2020 | Tim S.p.A.The Italian data protection authority imposed a EUR 27.8 million fine on Tim S.p.A. The case concerned privacy violations in marketing and telemarketing activities, including issues with obtaining valid consent. | IT | Garante per la protezione dei dati personali | GDPR | €27,800,000 | ↗ |
| 04 Aug 2025 | Azienda Ospedaliero-UniversitariaThe Italian data protection authority fined Azienda Ospedaliero-Universitaria EUR 80,000 for improperly configuring its health dossier. It found that staff could access patients’ clinical histories without proper profiling, alerts, or access logging, and that patients were not adequately informed or able to consent or object. | IT | Garante per la protezione dei dati personali | GDPR | €80,000 | ↗ |
| — | Enel Energia SpAEnel Energia SpA was fined EUR 79.1 million by the Italian data protection authority, Garante. The case concerned misuse of personal data and was a major GDPR enforcement action. | IT | Garante per la protezione dei dati personali | GDPR | €79,100,000 | ↗ |
| 20 Dec 2024 | OpenAIThe Italian data protection authority fined OpenAI EUR 15 million for GDPR noncompliance related to ChatGPT. The 20 December 2024 decision cites issues with the legal basis for training data processing, transparency obligations, age verification, breach notification, and the security and accuracy of outputs. | IT | Garante per la protezione dei dati personali | GDPR | €15,000,000 | ↗ |
| 04 Jun 2025 | Noi Compriamo Auto.it S.r.l.On 4 June 2025, the Italian Data Protection Authority fined Noi Compriamo Auto.it S.r.l. for GDPR breaches in email marketing. The authority found that the company sent promotional emails without consent, failed to properly govern its processors, and did not adequately support data subject rights. | IT | Garante per la protezione dei dati personali | GDPR | €27,800,000 | ↗ |
| 03 Jun 2025 | Regione LombardiaThe Italian Data Protection Authority, Garante per la protezione dei dati personali, imposed a EUR 50,000 fine on Regione Lombardia. The case concerned unlawful retention of employees' email metadata, excessive retention of web browsing logs, and prolonged storage of helpdesk ticket data. | IT | Garante per la protezione dei dati personali | GDPR | €50,000 | ↗ |
| 30 Apr 2026 | Intesa SanpaoloItaly’s data protection authority, Garante, fined Intesa Sanpaolo EUR 31.8 million. The sanction concerned serious failures in security and access management for personal data. | IT | Garante per la protezione dei dati personali | GDPR | €31,800,000 | ↗ |
| 01 Jan 2025 | RaiItaly’s data protection authority fined Rai EUR 150,000 over a Report broadcast on 8 December 2024 that disclosed a private conversation. The case concerns unlawful processing of personal data in a television report. | IT | Garante per la protezione dei dati personali | GDPR | €150,000 | ↗ |
| 10 Apr 2025 | Luka Inc.The Italian data protection authority fined Luka Inc., the US company behind the Replika chatbot, EUR 5,000,000. The 2025-04-10 decision concerned inadequate age verification, an unlawful processing basis, and missing privacy notice information required under the GDPR. | IT | Garante per la protezione dei dati personali | GDPR | €5,000,000 | ↗ |
| 10 Oct 2023 | ComuneThe Italian data protection authority fined a municipality EUR 12,000 for unlawfully publishing personal data online in access request registers. Documents in the transparency section of the municipal website exposed names, protocol numbers, and other sensitive details of hundreds of citizens. | IT | Garante per la protezione dei dati personali | GDPR | €12,000 | ↗ |
| 28 Mar 2023 | Sky Italia S.r.l.The Italian Data Protection Authority fined Sky Italia S.r.l. EUR 842,062 for violations related to telemarketing and commercial communications. The company failed to properly verify consent, relied on outdated consents, and did not check the Public Register of Oppositions before campaigns. | IT | Garante per la protezione dei dati personali | GDPR | €842,000 | ↗ |
| 29 Apr 2025 | Ordine professionale degli psicologi della LombardiaOn 2025-04-29, the Italian Data Protection Authority fined the Ordine professionale degli psicologi della Lombardia EUR 30,000. The sanction concerned breaches of Articles 5(1)(f) and 32 GDPR following a data breach and the failure to implement adequate security measures. | IT | Garante per la protezione dei dati personali | GDPR | €30,000 | ↗ |
| 02 Nov 2024 | Intesa SanpaoloThe Italian Data Protection Authority fined Intesa Sanpaolo €31.8 million for a data breach involving unauthorized access to banking information of more than 3,500 clients. The authority also found that the bank detected the activity late and filed an incomplete and delayed breach notification. | IT | Garante per la protezione dei dati personali | GDPR | €31,800 | ↗ |
| 21 May 2026 | The European House – Ambrosetti spaThe Italian data protection authority fined The European House – Ambrosetti spa EUR 85,000 for security shortcomings following a data breach affecting 61,670 people. The company notified affected individuals too late, only after intervention by the authority. | IT | Garante per la protezione dei dati personali | GDPR | €85,000 | ↗ |
| 14 Nov 2024 | Comune di MaddaloniThe Garante fined Comune di Maddaloni EUR 2,000 for failing to communicate the Data Protection Officer’s contact details to the Authority. This constituted a breach of Article 37(7) GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 13 May 2015 | Iperal S.p.A.Iperal S.p.A. was fined EUR 40,000 by the Garante for activating 11 phone cards in the names of 5 individuals without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 27 Oct 2016 | Studio Medico Odontoiatrico Associato Gimmelli B. & G.Studio Medico Odontoiatrico Associato Gimmelli B. & G. was fined by the Garante for unlawfully processing personal data by disclosing it to Ina Assitalia s.p.a. without obtaining the required informed consent from the data subject. The case reflects a breach of core lawful-processing requirements. | IT | Garante | GDPR | €6,400 | ↗ |
| 25 Mar 2021 | Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules. | IT | Garante | GDPR | €50,000 | ↗ |